NetWitness Platform Other Advice

MR
Senior Assistant Vice President at a financial services firm with 1,001-5,000 employees

There are lots of opportunities to expand this functionality, and it is a wonderful solution. It can compete with Splunk and LogRhythm.

I would recommend RSA NetWitness and rate it at five on a scale from one to ten.

View full review »
MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited

I rate the solution as a six out of ten.

View full review »
MdZaman - PeerSpot reviewer
IT manager at a agriculture with 10,001+ employees

I would definitely recommend this solution to others, but not to small-sized customers. The solution is one of the best for enterprise customers exceeding 10,000 or 2,000 EPS. 

I rate RSA NetWitness Logs and Packets (RSA SIEM) as a nine out of ten. 

View full review »
Buyer's Guide
NetWitness Platform
April 2024
Learn what your peers think about NetWitness Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,292 professionals have used our research since 2012.
SS
Security Analyst at HeiTech Padu Berhad

For small to medium-sized organizations, NetWitness Platform will be a suitable option. Most enterprises or larger organizations will likely choose a different platform because NetWitness Platform is no longer listed in Gartner. Additionally, the pricing is too high and is not competitive with Splunk and other products. It is relevant, but they need to set up or hire someone to help them compete with similar products like Slack, QRadar, or Palo Alto. Overall, I rate it a seven out of ten.

View full review »
RR
Senior consultant Cybersecurity

I've been using Sentinel and IBM QRadar. They are far better than RSA SIEM from a graphic user point of view and in terms of log integration. Everything is enhanced in these solutions compared to that in RSA.

RSA NetWitness Logs and Packets is far behind the competition. Initially, RSA was the only company focusing on decentralization and automation, but now, Microsoft and Google are also in the picture and are investing a lot of money to make their product user friendly and good for the customers from a cybersecurity point of view.

Overall, I would rate RSA NetWitness Logs and Packets (RSA SIEM) at six on a scale from one to ten.

View full review »
RP
Cyber security Lead at a manufacturing company with 1,001-5,000 employees

I would recommend this solution. 

I rate this solution a nine out of 10. 

View full review »
AR
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees

NetWitness is a part of the cybersecurity solutions we use today, but it's not the only one. We use many different solutions, such as Splunk and QRadar. The product is an SIEM solution, and we use SIEM solutions from different vendors for different needs on different sites.

We don't have all the features we thought were a part of the solution. We need to do many things manually to customize the solution for the customer's needs. By the book, we don't have enough to connect the product to all the systems with some inputs based on machine learning or all the new algorithms like artificial intelligence. The customer must know all these before installing this product. We need community knowledge for new products that tell us what has to be added after a few installations. The setup, then, can be very fast, and all the knowledge for integration with other components and the company's infrastructure can also be very fast because the solution is best-of-breed and third-party. It's not proprietary for special companies and corporations. In the context of product implementation, everything is very slow and must be done manually and not integrated automatically into the product. We need to know what we will do, how we will monitor the overall system, what kind of events we want to collect from the system, and what type of layout we want to provide through the system to alert about incidents or some type of situation. The customer manually processes all this. It's not like we deploy the product and get all this information and all these capabilities in one coverage of the solution.

Before choosing the NetWitness Platform, find the best integrators with professional experience implementing and deploying this product in other companies. The product has many features and coverage but needs professional integration and implementation.

I would rate NetWitness Platform an eight, but since it depends on the installation, I rate the solution a seven out of ten.

View full review »
Francesco Ritrovato - PeerSpot reviewer
Security Analyst at Sogei

I give the solution a nine out of ten.

I recommend the solution to others.

View full review »
ST
Manager at a comms service provider with 10,001+ employees

When comparing the cloud security solutions, RSA feels outdated. I would advise others before choosing RSA NetWitness Logs and Packets, to do a POC process and later they can do the purchase if it fits their needs.

I rate RSA NetWitness Logs and Packets an eight out of ten.

View full review »
Sandeep Sehrawat - PeerSpot reviewer
Information Technology Security Consultant at Sify Technologies

I rate RSA NetWitness Logs and Packets eight out of 10. Aside from ETS, it is the second-most important solution for maintaining compliance and how much data you need in the online logs or the offline archival logs.

View full review »
Rafał Popielski - PeerSpot reviewer
Solution Architect at NASK

NetWitness can be highly beneficial for incident detection and response. RSA has incorporated Extended Detection and Response (XDR) functionality through collaborations and licensing agreements with other companies.

It integrates well with other tools, boasting over 600 integrations on its website. The list is continuously updated and readily accessible.

Security improvements will vary depending on the combination of integrations. It's essential to carefully assess both the list of available integrations and each customer's specific needs.

I rate it a ten out of ten.

View full review »
SM
Information Technology Security and Infrastructure Expert at a government with 201-500 employees

My company has had many benefits from the use of the product in the last eight years.

The tool has streamlined our company's incident response process since it serves as a log repository, which allows us to correlate events and access different technology stacks. In our company, we were able to actually find some potential attacks, so it has been very helpful.

The tool's integration capability isn't so great. In my company, we managed to integrate it with our Microsoft Azure Subscription, after which we managed to integrate it with other tools. You will face a lot of difficulties if you want to integrate it with your database monitoring tool, PAM solutions, or IAM products.

The product has done well overall for my company's teams to deal with their workflow efficiency.

I would not recommend the product to others.

I rate the tool a seven out of ten.

View full review »
LB
Presales Manager at a tech services company with 51-200 employees

I would rate this solution 8 out of 10.

View full review »
MS
Program Manager at EGYANAM TECH

I'm on the latest version of the solution. I tend to work on updated versions.

We are systems integrators. We have a partnership with RSA.

If a company decides to try out this product, they need to do the homework properly due to the fact that sometimes on the hardware side or on the software side, you may face some issues. It is better to study thoroughly the troubleshooting part and prepare properly. Only then you can go for implementation.

I'd rate the solution at an eight out of ten.

View full review »
Salah Sabouni - PeerSpot reviewer
Director at ST

I would advise taking your time to understand the architecture of the solution, including how the modules communicate with each other and the role of each module. It is recommended to start slowly after gaining this understanding.

I would rate NetWitness Platform an eight out of ten.

View full review »
GD
Security Operations Manager at a computer software company with 1,001-5,000 employees

I would recommend version 11.5, it looks good. However, we are looking for an alternative solution.

I rate RSA NetWitness Logs and Packets (RSA SIEM) version 11.4 a seven out of ten.

View full review »
MA
IT and Cybersecurity Professional at a financial services firm

My advice for anybody who is implementing this solution is to look at both their endpoints and circuit paths. The two components, Logs and Packets, should definitely both be considered. Even if there is an on-premises SIEM log, they can integrate it.

Overall, I feel that the product is very good and my biggest complaint is about their support.

I would rate this solution an eight out of ten.

View full review »
NB
Delivery Partner APAC and MEA at Tata Consultancy

I would rate NetWitness Logs and Packets as eight out of ten.

View full review »
MT
Security Engineer/Architect at Telecom Italia

They have just introduced an orchestration tool, although I don't know how it works yet.

Overall, this is a good product and I recommend it. However, I always suggest doing a proof of concept first, to make sure that it meets your needs.

I would rate this solution an eight out of ten.

View full review »
HL
Information Technology Security Architect at a financial services firm with 5,001-10,000 employees

If it's possible, ask for help from primary support to help you implement at the very beginning with the fundamental alert or detection rules. This is my best advice for a customer regardless of the size and scope of the implementation. Use the support to help you with the implementation process.

I would rate it an eight out of ten. 

View full review »
RD
Senior Cyber Security Specialist at a tech vendor with 10,001+ employees

My advice to anybody who is researching this solution is to consider the differences between the hardware and the virtual solution. The hardware is okay, but if you have any issues and need to restart then it is easy to do this with the VM. My preference is using the VM, where they can easily increase the size of storage if necessary.

It is important to remember that ESA takes all of the main memory. The minimum requirement is 96 GB of RAM, and this is very easy to implement on a virtual machine. My advice is to implement ESA using the maximum eligibility criteria. Consider what the hardware requires are in terms of RAM and storage, and use the maximum available for ESA.

This solution has a very good dashboard with a separate tab for incidents and alerts. There is a ticketing tool as well. If the problems with the dashboard are corrected then we will not need to have any other tools. The dashboard is a very important feature for clients.

I would rate this solution a seven out of ten.

View full review »
AM
RSA Specialist at a computer software company with 1,001-5,000 employees

I have also worked with RSA SecurID and I can say that from the moment I touched it, it has been very easy for me to use.

The company is very active on the market and it is improving continuously. EMC/RSA are trying to approach a build such that it can meet every user's needs, but you can't satisfy everyone.

I recommend RSA NetWitness alongside other products, although I would suggest this first because of the user-friendly interface and easy-to-manipulate options. The only issue I have is with the documentation.

Overall, this is a good solution with suitable features and it very well fits our needs.

I would rate this solution a nine out of ten.

View full review »
AR
Associate Manager Human Resources at a financial services firm with 1,001-5,000 employees

RSA is something that I can recommend.

I would rate this solution a six out of ten.

View full review »
VG
IT Security Head with 1,001-5,000 employees

My advice for anybody who is implementing this solution is to make sure that the team handling the deployment is skilled. Without support, they will not be able to do it at all.

Also, if somebody wants to make their own connectors then they will need to have a development team. Without knowledge of scripting, it is not possible to make connectors. So, I would say that at an early point there needs to be somebody specialized in the use of this product.

I would rate this solution a six out of ten.

View full review »
MH
Team Leader & Head of MSSP at We Ankor

This solution has some good features, but it is lacking in usability. This means that I would rate it somewhere in the middle. I would rate this solution a five out of ten.

View full review »
it_user365328 - PeerSpot reviewer
Founder & CEO at a tech services company with 11-50 employees

The only thing I advise others is to spend enough time for fine-tuning and the initial rule development.

You should also develop a plan for the ongoing development and fine-tuning, as found in all the other leading SIEM solutions.

View full review »
PR
Analyst at Microland Limited

This is a product that I recommend.

I would rate this solution an eight out of ten.

View full review »
MA
Information Securuty Analyst at a tech services company with 11-50 employees

My advice to anybody who is considering this solution is that it is a relatively good program, but you want to take some time to get used to it. Once it is deployed and you are used to it, you can do whatever you want. Orchestration is another element that is there.

I would recommend this solution for large organizations that need to be compliant with these types of things. My main complaint is about the user interface.

I would rate this solution an eight out of ten.

View full review »
ET
ACD - Level 3 Analyst at a tech services company with 10,001+ employees

Either operating this solution in-house or reselling. First, outline all your data sources. Give more priority to the assets you want to protect.

Event source type and versions will be key.

Additional useful features:

  • Easy to integrate common data sources.
  • User friendly GUI.
  • Basic SQL rule syntax.

We are using RSA Security analytics version 10.6.3.2 and upgrading to 10.6.4 in mid-September. NetWitness suite v11 is due in October as a major upgrade.

View full review »
IO
Solution Specialist at a tech services company with 11-50 employees

It's a comprehensive SIEM solution. The packet capture feature is one thing that will be very beneficial for all accounts because it gives you that general visibility into what's going on even on your network. It's a great product, and I would rate it at eight on a scale from one to ten. It's way ahead of the others. 

View full review »
EB
Sr Manager InfoSecurity at a healthcare company with 10,001+ employees

It's supposed to help our security program maturity. Has it? I think that's another question.

I rate this product at three out of ten. It is overly complicated. It has taken years to implement and the return on investment just isn't there.

View full review »
it_user619134 - PeerSpot reviewer
Direct Sales Director at a tech services company with 501-1,000 employees
  • Don’t rush. Prepare use cases for packets and logs as it is a very important part of deployment and future use.
  • Use RSA Professional Services or a partner. Don’t deploy alone.
  • A basic administration course is a must for all administrators.
  • System architecture may be very easy or very complex. Do sizing well with external help.
View full review »
AV
IT security specialist at a comms service provider with 201-500 employees

I would recommend this solution to somebody considering it. 

I would rate it a nine out of ten.

View full review »
it_user130770 - PeerSpot reviewer
Managing Architect at a tech company with 10,001+ employees
This purely is an Enterprise Product and one has to have a defined budget and plan; it’s good to fit Business requirements first, and then go for products. View full review »
Buyer's Guide
NetWitness Platform
April 2024
Learn what your peers think about NetWitness Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,292 professionals have used our research since 2012.