ExtraHop Reveal(x) Primary Use Case

Jordan Swanson - PeerSpot reviewer
Information Security Assurance Engineer at School District of Lee County

Initially, we deployed Reveal as a standalone solution for network detection and response. It provided us with data and analytics on server-to-server enterprise networking. We used it to gain visibility into the amount of traffic and where it's going. For example, it will say that 28 gigs of data went to Google and break that down based on all the sites that have been visited. 

It also tells you about the authentication data and helps you visualize how data moves across your network. Based on that, you can adjust the routing tables to make things work a little more evenly. It will also help you identify specific types of malware and how it moves across devices, what protocols and ports it uses, etc.

Unlike Crowdstrike, Reveal(x) doesn't require you to deploy sensors. CrowdStrike puts a sensor on the computer, so I know exactly how many devices are going through it. It's roughly 50,000. Those aren't people using it. Those are just devices that exist in the world. ExtraHop just looks at traffic, so each device connected to the network goes through it, and that's around 230,000 devices, and it's monitoring all the traffic to and from the internet.

View full review »
Henry-Steinhauer - PeerSpot reviewer
Systems Engineer at LifePoint Health

We are a healthcare organization with more than 80 facilities, but I'm the only one who uses ExtraHop. When there are performance issues with an HTTP app, ExtraHop enables us to identify the causes within a few minutes. We can see what transactions are being impacted by something that may be happening within the server environment.

We set up a number of traffic sources that are typically either ERSPANs or TAPs and place ExtraHop appliances at critical places within the network. That traffic is typically fed into a packet. We have four small devices designed to go into small data centers. We're continually rotating those around to different facilities to help identify issues. They have helped us to understand what's going on.

The ExtraHop appliance enables you to do what an expert using Wireshark can do. However, it's all in the firmware, so you can do real-time analysis without the need to boil terabytes worth of data to find out what's happening.

View full review »
John Boake - PeerSpot reviewer
Senior monitoring engineer at a financial services firm with 10,001+ employees

It's used by application owners and network engineers for troubleshooting application performance issues or network performance issues.

It's a hybrid solution. We have on-prem sensors and trace appliances and a cloud control appliance.

View full review »
Buyer's Guide
ExtraHop Reveal(x)
April 2024
Learn what your peers think about ExtraHop Reveal(x). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,246 professionals have used our research since 2012.
CC
Cyber Security Engineer II at a healthcare company with 10,001+ employees

I'm on the cybersecurity team. I do a lot of the blue threat-hunting and incident response. The things I deal with have nothing to do with network performance, but I handle the detections and things that ExtraHop Reveal(x) can pick up.

View full review »
Serena Bryson - PeerSpot reviewer
Information Security Program Manager at a non-profit with 11-50 employees

We are using ExtraHop Reveal(x) for lateral movement and for behavioral analytics.

View full review »
SS
Business Development Manager at Westcon-Comstor

Our company uses the solution to send sensors to the Reveal 360 cloud for customers. We have about 500 customers using the solution. 

View full review »
NH
Cyber security specialist officer at a financial services firm with 5,001-10,000 employees

It can detect new attacks or expired certificates. It's especially effective in identifying Netria attacks or any other online threats that may occur.

View full review »
Amer_Alkhawaldeh - PeerSpot reviewer
Account Manager at a tech services company with 11-50 employees

I use ExtraHop Reveal(x) since it helps provide notifications related to the network traffic in my company so that the necessary action can be taken.

View full review »
DV
Sales Engineer | Technical Sales | Pre-Sales at SUSE

We have implemented the ExtraHop Reveal(x) solution at multiple clients. They range from government, retail to financial. We collect north-south and east-west traffic via a visibility layer (packet brokers, taps, spans) and then feed that traffic to the ExtraHop Reveal (x) solution. The volume ranges from 1 GB solutions up to 40 GB solutions with 100 GB in the pipeline. Initially, we approached them for application performance analysis, but we now use it to assist the security teams as well. The behavioral analytics and ability to go back in history is proving extremely valuable.

View full review »
Ryan Barker - PeerSpot reviewer
Technical Account Manager at a security firm with 501-1,000 employees

We primarily use the solution for three main aspects: security, visibility, and application performance.

View full review »
OD
Presales Consultant at a tech services company with 201-500 employees

We use the solution for an advanced layer of security. It provides us with network visibility to identify types of attacks.

View full review »
Buyer's Guide
ExtraHop Reveal(x)
April 2024
Learn what your peers think about ExtraHop Reveal(x). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,246 professionals have used our research since 2012.