The RSA Netwitness packet plays a major role in identifying cyber attacks from different sources. We integrated in a very large environment, deploying it in a container corporation in India. The company has around 86 locations across the country. Another use case of RSA is for running full scans and the third use case is for blocking malware and viruses. Nowadays, people hide behind encaptured networks and use proxies to look through the door. Then they'll try to come in.
Cyber security Lead at a manufacturing company with 1,001-5,000 employees
Great wireless feature, provides many automatic rules that are very helpful
Pros and Cons
- "Offers a good wireless feature."
- "Technically speaking, this is a good product."
- "Technical support could be improved."
- "I believe they could improve their support, there are often delays."
What is our primary use case?
What is most valuable?
The wireless feature is good, it tells you when to check a spot, which file it has used to encrypt, whether it is spreading and how many hosts have been infected. It's about data analysis. Looking at the network logs, it's difficult to figure out where the problem is coming from and where it's going, but those kinds of features help me a lot. The solution provides lots of automatic rules which is helpful. Technically speaking, this is a good product.
What needs improvement?
I believe they could improve their support, there are often delays. The price of the solution could be reduced, it's very costly.
What do I think about the stability of the solution?
This is a stable product.
Buyer's Guide
NetWitness Platform
March 2026
Learn what your peers think about NetWitness Platform. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,286 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We're using the solution extensively in our shipping business so it is scalable. We probably have seven or eight users and the solution is in use 24/7.
How are customer service and support?
Getting technical support takes time, they get a lot of calls and we generally only get a response the following day. Cisco is better with technical support.
How was the initial setup?
The initial setup is not straightforward because of all the integrations required. It needs the aggregate data, data concentrator, defense, correlation roots, and more.
What's my experience with pricing, setup cost, and licensing?
It would help if they could provide the malware analytics in the core package as that would make the cost more reasonable. Licensing is paid annually and I believe the cost is somewhere between 12,000 - 15,000 Pounds per year. It's very high.
What other advice do I have?
I would recommend this solution.
I rate this solution a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Computer Security Consultant at SECURE SOFT
Deployment flexibility and robust integration enhance reporting and analytics capabilities in financial industry
Pros and Cons
- "NetWitness Platform offers flexibility for deployment and robust integration capabilities."
What is our primary use case?
I use NetWitness Platform in the financial industry as a good product with excellent capabilities and integration with various devices.
What is most valuable?
NetWitness Platform offers flexibility for deployment and robust integration capabilities. It excels in research events, analytics data, and reporting. It is particularly beneficial for reporting purposes, offering efficient solutions.
What needs improvement?
There is currently no need for improvement in the SIEM, though there could be potential enhancements by integrating with AI.
How are customer service and support?
The support is good, and I would rate it nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup was not complex. On a scale of zero to ten, where ten is the easiest, I would rate it seven or eight.
What was our ROI?
The solution is efficient, though I do not provide specific ROI details.
What's my experience with pricing, setup cost, and licensing?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
Which other solutions did I evaluate?
What other advice do I have?
I would rate the SIEM eight out of ten.
Which deployment model are you using for this solution?
I am using the on-premises deployment model.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
NetWitness Platform
March 2026
Learn what your peers think about NetWitness Platform. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,286 professionals have used our research since 2012.
Associate Manager Human Resources at a financial services firm with 1,001-5,000 employees
Good packet inspection and automated incident response, but it needs to be more customizable
Pros and Cons
- "The most valuable features are the packet inspection and the automated incident response."
- "The most valuable features are the packet inspection and the automated incident response."
- "More customizability is required, which is something that they need to improve on."
- "More customizability is required, which is something that they need to improve on."
What is our primary use case?
We are using this solution for security.
What is most valuable?
The most valuable features are the packet inspection and the automated incident response.
What needs improvement?
More customizability is required, which is something that they need to improve on.
When it comes to starting a log event, there are not many options available. It is very limited.
The log and event correlation need improvement.
The threat detection capability should be enhanced.
For how long have I used the solution?
I have been using this solution for one month.
What do I think about the stability of the solution?
We are using it on a daily basis and, so far, it has been stable.
What do I think about the scalability of the solution?
We have approximately 6000 employees, which means that we have 6000 endpoints that this product is working with. It is easy to scale it up to production.
How are customer service and technical support?
We have not had to contact technical support.
Which solution did I use previously and why did I switch?
In this company, they did not use a similar solution prior to this one. Personally, I used Splunk in my previous organization. Definitely, I prefer to use Splunk because there is more functionality, visibility, and options. You can do whatever you want with Splunk.
How was the initial setup?
The initial setup is not complex, and more on the simple side. Our deployment took almost five months in total.
What about the implementation team?
We had assistance from an integrator and the vendor for our deployment.
We have administrators in the company who take care of administration and maintenance. The vendor was only needed for the implementation.
What other advice do I have?
RSA is something that I can recommend.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Analyst at Microland Limited
Easy to set up with good UEBA functionality
Pros and Cons
- "What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
- "Stability has not been an issue with this product."
- "Security needs improvement."
- "Security needs improvement. We would still like to know how the traffic is entering the organization."
What is our primary use case?
The primary use case of this solution is for security.
We use the UEBA tool.
What is most valuable?
What we are mainly using are the RSA Concentrator, RSA Decoder, Archiver, Broker, and Log Decoder.
What needs improvement?
Security needs improvement.
We would still like to know how the traffic is entering the organization. We can find out but it will take time before we know, leaving the organization vulnerable for attack.
There is no SIEM tool in the world that can provide 100% security.
For how long have I used the solution?
I have been using this solution for five months.
What do I think about the stability of the solution?
Stability has not been an issue with this product.
What do I think about the scalability of the solution?
It's a scalable solution.
How was the initial setup?
The initial setup was straightforward, not at all complex.
There are approximately 1,400 devices that are integrated into RSA in my organization. While I was not a part of the integration, from my knowledge, it would take a week.
Which other solutions did I evaluate?
We have looked at similar systems and find that the architecture is somewhat different, yet the functionality is similar.
What other advice do I have?
This is a product that I recommend.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer/Architect at Telecom Italia
Offers good security, integrates well, and they have good technical support
Pros and Cons
- "The most valuable feature is the security that it provides."
- "The most valuable feature is the security that it provides."
- "It is not so easy to customize this product."
- "It is not so easy to customize this product."
What is our primary use case?
We are a solution provider and RSA NetWitness is one of the products that we implement for our clients. We also use it ourselves, They primarily use it for threat protection.
What is most valuable?
The most valuable feature is the security that it provides.
The log-related capabilities are good.
It integrates well with other risk-assessment tools.
What needs improvement?
It is not so easy to customize this product.
This product would be improved with the addition of machine learning functionality.
For how long have I used the solution?
I have been working with this product for perhaps eight years.
What do I think about the stability of the solution?
Stability is not a problem with NetWitness.
What do I think about the scalability of the solution?
We have not heard any complaints about scalability. This is generally for enterprise-level companies.
How are customer service and technical support?
The technical support is good and our customers are satisfied with it.
Which solution did I use previously and why did I switch?
We use McAfee for internal purposes.
How was the initial setup?
The complexity of the initial setup depends on the environment, but overall, I would say that it is quite easy. It isn't the easiest product to install, although it is not difficult, either.
What other advice do I have?
They have just introduced an orchestration tool, although I don't know how it works yet.
Overall, this is a good product and I recommend it. However, I always suggest doing a proof of concept first, to make sure that it meets your needs.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT and Cybersecurity Professional at a financial services firm
Easy to deploy with powerful threat prediction and network forensics capabilities
Pros and Cons
- "The most valuable features are the threat prediction and network forensics."
- "Overall, I feel that the product is very good and my biggest complaint is about their support."
- "Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
- "I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need."
What is our primary use case?
Our primary use case is real-time threat prediction so that we can minimize the person-hours of IT security analysts.
What is most valuable?
The most valuable features are the threat prediction and network forensics. For example, if there is any malware on the network, I am able to see who received it and who clicked on it. I like this functionality the most.
The deployment of the appliance is easy, where even a non-technical person can configure it.
What needs improvement?
The SOAR (security orchestration, automation, and response) component has areas for improvement.
Technical support needs to be improved.
Integration with third-party products for industries such as the banking sector, or telecommunications, presents challenges that require help from the OEM.
Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support.
For how long have I used the solution?
We have been using RSA NetWitness for about 10 years.
What do I think about the stability of the solution?
There are no issues in terms of stability.
What do I think about the scalability of the solution?
This solution is pretty scalable, as I am using the VM infrastructure. It can scale to whatever you need.
How are customer service and technical support?
I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need.
Which solution did I use previously and why did I switch?
I have used RSA enVision and ArcSight in the past. We migrated from RSA enVision because they had declared the product end-of-life and upgraded to the NetWitness platform.
The Logs component is similar to what other competitors, such as IBM, ArcSight, and LogRhythm have. What distinguishes this solution is the Packets component. It is critical and something that people should make use of.
How was the initial setup?
It is easy to deploy the appliance. Anyone can mount and configure it. There is a simple, pre-built OS that they just need to mount in the VM infrastructure, and that is clearly mentioned in the documentation. It will take two or three days to deploy, at most.
The challenge comes with trying to integrate with third-party application servers.
What about the implementation team?
We deployed this solution with our in-house team.
The number of people required for maintenance depends on your use case. If you are only using it to maintain the infrastructure then two staff is sufficient. However, if you want to implement a full-fledged SOC then you will need at least four or five people.
What other advice do I have?
My advice for anybody who is implementing this solution is to look at both their endpoints and circuit paths. The two components, Logs and Packets, should definitely both be considered. Even if there is an on-premises SIEM log, they can integrate it.
Overall, I feel that the product is very good and my biggest complaint is about their support.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Securuty Analyst at a tech services company with 11-50 employees
Good performance, reporting, and log archiving capability
Pros and Cons
- "Performance and reporting are very good."
- "Once it is deployed and you are used to it, you can do whatever you want."
- "The user interface is a little bit difficult for new users and it needs to be improved."
- "The user interface is a little bit difficult for new users and it needs to be improved."
What is our primary use case?
I am currently working in a security operations center and RSA NetWitness Log and Packets is part of our security solution. We use it for log management and anomaly identification. It is used for compliance as well because it has a log archiving capability that will span at least a couple of years.
We are also using it to facilitate monitoring and research.
What is most valuable?
Performance and reporting are very good.
What needs improvement?
The user interface is a little bit difficult for new users and it needs to be improved.
It takes a lot of time to register when compared to other solutions.
For how long have I used the solution?
I have been using this solution for about one year, although it has been in the company for a couple of years.
What do I think about the stability of the solution?
We did have some issues before our upgrade from version 10.6., although they were not major. Since the upgrade, I have noticed that some of these things have gotten better.
I would say that this is a stable solution, although there are some minor issues that need to be settled. Currently, they are being investigated.
What do I think about the scalability of the solution?
We have never had issues with scalability. We can reduce the usage as per our requirement and we increased our capacity in 2019. We are planning to further increase, either this year or next year. Scalability overall is quite easy.
How are customer service and technical support?
When we started finding problems, we got in touch with technical support and opened tickets. They worked with us to resolve them. I would rate them good, although not great. At times, I felt that they were being really short with me.
How was the initial setup?
I was not part of the initial setup but my understanding is that there were no issues and everything was good. I was part of the upgrade from version 10.6 to 11.3 and it was smooth, with no major issues.
What about the implementation team?
The deployment was done by my manager a couple of years ago.
What other advice do I have?
My advice to anybody who is considering this solution is that it is a relatively good program, but you want to take some time to get used to it. Once it is deployed and you are used to it, you can do whatever you want. Orchestration is another element that is there.
I would recommend this solution for large organizations that need to be compliant with these types of things. My main complaint is about the user interface.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
RSA Specialist at a computer software company with 1,001-5,000 employees
A user-friendly solution that integrates well with our system
Pros and Cons
- "The most valuable features are the integration and ease of use."
- "Overall, this is a good solution with suitable features and it very well fits our needs."
- "The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
- "The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
What is our primary use case?
Our customers are enterprise-level businesses.
What is most valuable?
The most valuable features are the integration and ease of use. It is a pretty simple platform that can integrate very well with our system.
What needs improvement?
The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly. I may see it differently than other people.
I would like to see a little question mark beside each button that you can click and find out what that button is for. It would make it much easier for people who are new to the solution. Like a pop-up appearing when hovering over the question mark, attached to each main action and split into branches.
For how long have I used the solution?
We began using RSA NetWitness Logs and Packets not long ago.
What do I think about the stability of the solution?
This is a very stable product.
How are customer service and technical support?
I have not been in contact with technical support.
I would say that RSA University is fair and square. It is a bit tricky because they have changed the learning platform and I had trouble enrolling in courses. I needed to contact Dell EMC support, which is the same support for RSA, and they assigned the courses to me in one or two hours. In the end, I was very satisfied. It is a bit expensive but the companies are paying for it.
How was the initial setup?
The initial setup is straightforward. I am also coding so it is easy for me to adapt.
What other advice do I have?
I have also worked with RSA SecurID and I can say that from the moment I touched it, it has been very easy for me to use.
The company is very active on the market and it is improving continuously. EMC/RSA are trying to approach a build such that it can meet every user's needs, but you can't satisfy everyone.
I recommend RSA NetWitness alongside other products, although I would suggest this first because of the user-friendly interface and easy-to-manipulate options. The only issue I have is with the documentation.
Overall, this is a good solution with suitable features and it very well fits our needs.
I would rate this solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free NetWitness Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Popular Comparisons
Splunk Enterprise Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Security Onion
LogRhythm SIEM
Rapid7 InsightIDR
Elastic Stack
Amazon OpenSearch Service
Fortinet FortiSIEM
Gigamon Deep Observability Pipeline
Buyer's Guide
Download our free NetWitness Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?














