Cisco Stealthwatch Room for Improvement

Consulta004b
Consultant at a healthcare company with 1,001-5,000 employees
In the last year or two, we have been working with our Cisco NAS engineers to improve our security posturing. It is more our being proactive rather than reactive. While Stealthwatch and Lancope have this ability to look inside and give you visibility (a great feature), follow-up is the rule. We would like filters that you can put into place to tap onto certain types of behaviors, alerts out, and/or hopefully a block. This is sort of what we are looking for. I might be speaking too early, because we are not down this path yet. We know the feature set is there, we just do not know yet how to achieve it. That is proactive rather than more reactive. For Lancope Stealthwatch, we would like to see it more on the ASA Firewall platform. While this might already be available, this is more a failing of Cisco to inform us if it is there. For example: * Are we on the right or wrong version of the code? * What does the code look like? * Are we are really looking at firewalls? Or is it more about the foundation and route switches that we are seeing? It is about visibility. View full review »
Travis Bugh
Senior Director of Architecture and Engineering at Trace3
I don't have a specific feature request, but my big push with Cisco has always been to make it easier for the administrators to use it. If you look at other products that they've been really successful within software space like Meraki, it's because a customer can jump right in and use it on day one and feel like they're accomplishing something with it. They don't have to have a Ph.D. Anything that we can do to make the customer experience better makes it easier for them to use it, which is what we want, and it also makes it easier for us to sell it. Obviously usability, but given the space that it plays in, any way that we can continue to increase the security vector coverage is always going to be a net gain for a product like that. View full review »
Technicab71a
Technical Consultant at a tech services company with 501-1,000 employees
I would like this product to have better integration with Cisco Firepower. That is the easiest way to pair. Eliminating Java from the SMC would improve this solution. It would be better to let people know, upfront, that is doesn't give you nice, clear information, as seen in the demos, without Cisco ISE installed. Most of my customers are ISE-based so it doesn't matter, but I have to break the news to the ones who are not. View full review »
Find out what your peers are saying about Cisco, Darktrace, Vectra AI and others in Intrusion Detection and Prevention Software. Updated: October 2019.
372,906 professionals have used our research since 2012.
NetworkAcb23
Network Administrator at a mining and metals company with 1,001-5,000 employees
One thing I would like to see improved is if it could automatically be tied through ISE, instead of you having to manually get notifications and disable it yourself. I am the only network admin at my facility, and when I'm on vacation for a week and there is an attack, I'm the only individual that gets alerts. Essentially there's a push button that you click to implement the policy through ISE to block that host or some other network essentially segregated from your internal network. I would like to see an automatic block function. I haven't noticed any downfall as far as CPU usage or any congestion, but it is still too early to say. Once I get a better understanding of it and get past the baselining, I can probably answer better and in more depth, because I don't know everything about it. I just understand the fundamental idea of it and what I can do from the dashboard. View full review »
NetworkE7689
Network Engineer at a government with 1,001-5,000 employees
We don't use Cisco Stealthwatch for threat detection. We use it more for information gathering. We use better options for threat detection, i.e. Palo Alto firewalls for our security. I would like the search page available with Cisco Stealthwatch to be more intuitive. The previous release was better than the current one for the UI. We moved to the latest UI a couple of months ago, maybe like six months ago. I'm not a fan. I wish the search options were easier. View full review »
Robert Ufer
Network Architect at Henry Ford health system
Cisco Stealthwatch needs more integration with device discovery. We have to do a lot of hard work to figure out what things are. Better service integration is required. View full review »
Directorb5e9
Director Network Services at a consultancy with 1,001-5,000 employees
I would like to see more expansion in artificial intelligence and machine learning features. There does not seem to be much available in terms of training for the product. We use several training institutions, and this solution is not on any of their lists. View full review »
LeadNetwd213
Lead Network Engineer at a retailer with 1,001-5,000 employees
I think the interface is a little lacking. The interface seems like it just needs to be modernized. It's been the same interface now, ever since I've seen it probably four years ago. View full review »
Director9b3e
Director of Networking and Telecom at a healthcare company with 1,001-5,000 employees
The GUI could use some improvement. Being able to find features more easily would be a great improvement if it was simplified. View full review »
Dale Keehan
Network Engineer at UC San Diego Health System
We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too. View full review »
Ken Poteate
Security Analysist at Amwins Group
I would like to see more and cleaner reporting. For example, if I pull up Steven and I want to look and maybe compare him to what you've done in the past week, and compare that to the past six months, the point would be to see what the difference in activity looks like over this time. I don't see that capability in reporting to date. You see that trend but you don't really see a straightforward comparison. That right there is key to what we want to see about the normal activity. View full review »
NetworkSddc6
Network Section Chief at a government with 1,001-5,000 employees
We're still gathering numbers about our increased threat detection rate. Anything we can improve with security patches to the network greatly improves the product. There's a lot of traffic on our network that we don't see sometimes. View full review »
Forensic60e5
Forensic Analyst at a pharma/biotech company with 1,001-5,000 employees
I have nothing negative to say about the product. I've become very familiar with it, it is intuitive and easy to learn. I'm happy that the deployment worked well. If there was one improvement I’d suggest it would be that it detect traffic through an intranet. The product requires that traffic flow through a managed network device. The product is designed mostly for enterprise environments and not smaller environments or businesses. View full review »
Joaquin Quinata
Network Manager Administrator at a financial services firm with 501-1,000 employees
At my company, we might not be using it enough with other applications that we have that can integrate with it. We need integration between ISE and Stealthwatch. I know my company is trying to get it to work. I don't know if they actually got it yet. View full review »
NetworkM6238
Network Manager at a financial services firm with 1,001-5,000 employees
The overall visibility into the actual device itself would be helpful. I don't just want support-specific data, but also to be able to see information such as CPU and other internal components or usage of the devices. View full review »
NetworkEd59a
Network Engineer at a tech services company
Considering all the data on the network, I believe that the analytics of Cisco Stealthwatch are pretty decent. I would like to see it better organized when I'm looking at it. If I hand it to another NOC engineer, they may not know what they're looking at, so I would prefer it to be more clean and structured, making it easier to use. View full review »
Rob Hartstone
Network Operations Manager at Philips Electronics
Complexity on integration is not so straightforward and you really need an expert to help build it out. View full review »
Mark Green
Network Operations Manager at a tech company with 10,001+ employees
There is room for this solution to mature because there are still things that we want to see. The reporting of day-to-day metrics still has room for improvement. View full review »
Finn Kristensen
Architect at Atea A/S
Some of our customers find this solution to be a little bit tough because they don't understand how to configure and use it. It may have to do with a need for more education when installing the product. Speed is an issue because the faster you have visibility, the better the solution. View full review »
Brian Grainer
Manager of Digital Communications at Memorial Hermann Healthcare System
The ability to be natively integrated into Port Aggregator would be beneficial because it would reduce just one more component that's needed in order to have that type of view. View full review »
Director7b47
Director of Operations at a manufacturing company with 1,001-5,000 employees
It is time-consuming to set it up and understand how the tool works. View full review »
James Stout
Network Engineer at Oracle Corporation
We had some trouble with the installation as we migrated from our previous solution. View full review »
Douglas Bentley
Assistant Director of IT at University of Rochester Medical Center
The initial setup is complex, as there is a lot to configure. View full review »
NetworkMed21
Network Manager at a healthcare company with 1,001-5,000 employees
I would like to see better filters. You should be able to filter the data out to more rapidly find what you're looking for. View full review »
SeniorCoeaa2
Senior Consultant at a manufacturing company with 10,001+ employees
I would like to see a hybrid solution that can work without being connected directly to the internet for those destinations. A business case would be manufacturing floors that are not, or still not, connected to the internet permanently. In terms of the user interface, navigating through the drill down windows needs to be improved. View full review »
SrNetworbb7a
Sr Network Engineer at a insurance company with 5,001-10,000 employees
They should include Citrix VDIs in the next release. View full review »
JosephSullivan
Manager at Indiana University Health
I would like to see some improvement when it comes to reporting. View full review »
Associat85b7
Associate Director Network Services at a pharma/biotech company with 10,001+ employees
It's too complicated to install when starting out. Also, we have actually seen an increase in false positives with Stealthwatch. A few of the false positives were too early to detect. Availability is another issue. You need a couple of days to get it to work. View full review »
NetworkAe7fe
Network Administrator at a retailer with 1,001-5,000 employees
We're trying to upgrade to the newest release. We're running a version that's three versions behind. View full review »
Bill Guilford
Senior Information Security Engineer at a transportation company with 10,001+ employees
One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints. View full review »
reviewer1151310
Chief Consultant at a tech services company with 11-50 employees
The usability of this solution needs to be improved. The initial setup of this solution can be simplified. View full review »
SrNetworab58
Sr. Network Engineer at a tech services company with 10,001+ employees
I don't really think we really save time while using this solution. View full review »
Toufeik Choukri
PIC for Cyber Security at a university with 51-200 employees
There are already many functionalities, so I don't think there is anything to improve. Its the best one on the market I have seen. View full review »
Rafael-Garcia
Infosec Manager at a energy/utilities company with 1,001-5,000 employees
Stealthwatch needs improvement when it comes to speed. View full review »
Find out what your peers are saying about Cisco, Darktrace, Vectra AI and others in Intrusion Detection and Prevention Software. Updated: October 2019.
372,906 professionals have used our research since 2012.
Sign Up with Email