We performed a comparison between NetWitness Platform and Trellix Advanced Threat Defense based on real PeerSpot user reviews.
Find out what your peers are saying about Splunk, Wazuh, Datadog and others in Log Management."Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"The most valuable feature is the hunting ability to work in a CERT."
"Incident management is its most valuable feature."
"The product's initial setup phase was not at all difficult."
"The most valuable feature is the correlation. It can report in real-time and monitor the management."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"It is stable and reliable."
"Provides good exfiltration, and is an all-in-one product."
"It stops in excess of twenty-five malware events per month, all of which could be critical to the business."
"It is very scalable."
"I recommend this solution because of its ease of use."
"Its greatest strength is the DXL client which can rapidly disseminate attack information to all clients via the McAfee Agent instead of going through the ePO server."
"The most valuable features are the administration console and its detection and response module."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"The solution should have more integration capabilities with different platforms."
"An area for improvement would be better automation and more inbuilt use cases."
"The log system is a bit complex and has room for improvement."
"If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
"Lacks remote capabilities not dependent on the internet."
"This solution needs to be made "cloud ready"."
"Make the ATD system a part of the whole product and take the whole thing onto the cloud. While it is there already, it is not to the same level as the on-premise version."
"We'd like them to be better at dealing with script threats."
"There could be a tool that automatically updates all-new Microsoft IPs, which are available for free to connect to the client."
"The initial setup was industry standard complex. It takes awhile and has a lot of planning involved. It could be simplified with product redesign."
"I would like to see future versions of the solution incorporate artificial intelligence technology."
More Trellix Advanced Threat Defense Pricing and Cost Advice →
NetWitness Platform is ranked 18th in Log Management with 36 reviews while Trellix Advanced Threat Defense is ranked 22nd in Advanced Threat Protection (ATP) with 8 reviews. NetWitness Platform is rated 7.4, while Trellix Advanced Threat Defense is rated 7.8. The top reviewer of NetWitness Platform writes "Can find out if there is lateral movement, but integration and workflow need improvement". On the other hand, the top reviewer of Trellix Advanced Threat Defense writes "Easy to set up and use with a nice interface". NetWitness Platform is most compared with Splunk Enterprise Security, RSA enVision, IBM Security QRadar, Cisco Secure Network Analytics and Microsoft Sentinel, whereas Trellix Advanced Threat Defense is most compared with Fortinet FortiSandbox, Microsoft Defender for Office 365, Microsoft Defender for Identity and Palo Alto Networks WildFire.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.