We performed a comparison between NetWitness XDR and SolarWinds NetFlow Traffic Analyzer based on real PeerSpot user reviews.
Find out what your peers are saying about CrowdStrike, SentinelOne, Wazuh and others in Extended Detection and Response (XDR)."The 'Incidents and Alerts' tab is a valuable feature where we can find triggered alerts."
"Defender XDR has a feature called the timeline that lets you track all activities. It helps a lot with investigations."
"The attack simulation is excellent; initially, this feature wasn't very robust, but Microsoft improved what we could achieve with it. We can now customize our practice phishing emails and include our company logo, for example. Attack simulation also helps integrate with third-party solutions where applicable and provides an overview of our security architecture through testing. The summary includes areas for improvement in our protection and what steps we need to take to get there."
"The visibility into threats is also very impressive because Microsoft helps you predict things and provides analytics to help you really improve your security. And all of this technology works across the domain, so it is pretty helpful in terms of threat analytics."
"It's a very scalable tool that can be used in a very small environment or in a very large environment. Everything can be managed from a simple dashboard and can be scaled up or down depending on the customer's environment."
"The threat intelligence is excellent."
"Microsoft XDR's system of analysis and investigation is super convenient for our customers. It integrates with other Microsoft solutions like Defender for 365 to protect email traffic from malicious external web links and phishing."
"The ability to integrate and observe a more cohesive narrative across the products is crucial."
"Ability to isolate the machine when there are malicious files."
"It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users."
"It helps our security team respond more accurately when there are threats, then we get less false positives or negatives."
"The stability of the RSA NetWitness Endpoint is very good."
"It is very easy to use, and its usability is great. The use cases are also very easy. The visualizations of the use cases are magnificent. You cannot find this in any other solution. From my point of view, it is great."
"NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console."
"Technical support is knowledgeable."
"The most valuable feature is the way it captures the traffic, and it contains every detail of the communication."
"The bandwidth monitoring functionality is one of the most important features for our customers. When the customer notices that their bandwidth usage is too high for some reason, they will use the traffic analysis within SolarWinds NTA to identify which protocols (e.g. HTTPS) or applications are using up the bandwidth."
"It helps us know when a branch is down because it has a graphic presentation of all the locations a node represents."
"With SolarWinds, we are now able to accurately gauge bandwidth consumption."
"For managing the traffic, it provides you a response about whether the traffic is down, up, or heavy, which is a very powerful feature. It has a good response time. We have been using this solution for many years, and we don't have any problem with this solution."
"The initial setup was straightforward."
"They have instructional videos and other information available on the site to assist you with learning it."
"The monitoring is perfect, showing you the details for the utilization of resources and network bandwidth."
"The program is scalable enough for our usage."
"Automated playbooks and automated dashboards would be preferable to the way the data is currently being presented."
"The dashboard should be easier to use. There is also improvement needed in the reporting when it comes to exporting or scheduling reports."
"Defender also lacks automated detection and response. You need to resolve issues manually. You can manage multiple Microsoft security products from a single portal, and all your security recommendations are in one place. It's easy to understand and manage. However, I wouldn't say Defender is a single pane of glass. You still need to switch between all of the available Microsoft tools. You can see all the alerts in one panel, but you can't automate remediation."
"We should be able to use the product on devices like Apple, Linux, etc."
"The licensing is a nightmare and has room for improvement."
"The capability to not only thwart attacks but also to adapt to evolving threats is crucial."
"The Defender agent itself is more compatible with Windows 10 and Windows 11. Other than these two lines, there are so many compatibility issues. Security is not only about Microsoft. The core technical aspects of it are quite good, but it would be good if they can better support non-Microsoft solutions in terms of putting the agents directly into VMware and other virtualization solutions. There should be more emphasis on RHEL and other operating systems that we use, other than Windows, in the server category."
"Support is hit or miss. Microsoft wants you to buy premium support contracts. Though they call themselves professional support, it's almost like throwing questions into a black hole. You get an answer, but it's never helpful."
"Threat detection could be better."
"The contamination feature could be improved."
"When analyzing something, you have to click several times. It requires a lot of effort to find something."
"The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features."
"Its price could be improved. It is an expensive product. Its training is also too expensive. It would be great if they can have a better pricing scheme for the training."
"This solution needs an upgrade in reporting. I have heard from RSA that they are working on this, but as of yet it is not available."
"The threat intelligence could improve in RSA NetWitness Endpoint."
"RSA NetWitness Network could improve on integration with non-native application integration."
"The solution needs better log management and log coordination with tools."
"It can be complex to set up and configure."
"An area for improvement in SolarWinds NetFlow Traffic Analyzer is the dashboarding. The user interface also has room for improvement because it's currently clunky."
"The price of the solution is a bit high for our clients. They should consider adjusting their price model."
"An area for improvement in SolarWinds NetFlow Traffic Analyzer is application visibility because some applications aren't being recognized correctly. You can see applications such as Facebook and YouTube, but SolarWinds NetFlow Traffic Analyzer needs to have more visibility into more applications. Currently, SolarWinds fails to detect more powerful applications, such as Zoom and Teams. If SolarWinds NetFlow Traffic Analyzer can recognize every application and be able to report on each in terms of bandwidth, then that would be good. This is what I'd like to see in the next release of the solution."
"This solution does not do a very good job when I am trying to look deeper into my internal network, in particular with respect to individual ports."
"I would like to see better customization capabilities."
"Technical support needs improvement."
More SolarWinds NetFlow Traffic Analyzer Pricing and Cost Advice →
NetWitness XDR is ranked 17th in Extended Detection and Response (XDR) with 15 reviews while SolarWinds NetFlow Traffic Analyzer is ranked 6th in Network Traffic Analysis (NTA) with 34 reviews. NetWitness XDR is rated 8.0, while SolarWinds NetFlow Traffic Analyzer is rated 7.6. The top reviewer of NetWitness XDR writes "Beneficial single unified dashboard, good native application integration, and high availability". On the other hand, the top reviewer of SolarWinds NetFlow Traffic Analyzer writes "Displays traffic visibility and efficient traffic flows". NetWitness XDR is most compared with Darktrace, ExtraHop Reveal(x), CrowdStrike Falcon, SentinelOne Singularity Complete and Microsoft Defender for Endpoint, whereas SolarWinds NetFlow Traffic Analyzer is most compared with Cisco Secure Network Analytics, Zabbix, ManageEngine NetFlow Analyzer, SolarWinds NPM and Darktrace.
We monitor all Extended Detection and Response (XDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.