RSA NetWitness Logs and Packets (RSA SIEM) Room for Improvement

Maor Hojberg
Team Leader & Head of MSSP at We Ankor
The solution would be greatly improved by unifying the management to one configuration option. One of the problems the system had is that you always have to choose the managed host. For example, if you want to write a rule, you have to duplicate it across your managed hosts. It should have centralized management. If you want to make a change then it should be configured automatically, so that you don't need to go one by one, changing it. That is really annoying. Another problem is that the EPL (Event Processing Language) is not properly explained, and the expert could not even use it when they came to our site. It was causing the system to crash, so they should really consider using something else. The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together. I think that it could be better integrated, and it would be great for new customers or even existing customers. View full review »
Elias Lefate Tebele
ACD - Level 3 Analyst at a tech services company with 10,001+ employees
Advance monitoring and alerting feature is not stable (Event Stream Analysis). Does not allow certain use cases running parallel. The reporting module: If only their dashboards resembled anything you would see on any BI reporting tools. View full review »
Allan Vargas
IT security specialist at a comms service provider with 201-500 employees
I would like for them to incorporate IPS. Only the monitoring detects abnormal behavior so we'd like to see IPS. I would like to see a dashboard include PAM so that it's a one-stop shop. View full review »
SrManagee3c6
Sr Manager InfoSecurity at a healthcare company with 10,001+ employees
I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex. View full review »
Allan Vargas
IT security specialist at a comms service provider with 201-500 employees
The implementation needs assistance. View full review »

Sign Up with Email