Anomali ThreatStream vs. NetWitness Cloud SIEM

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Anomali ThreatStream
Score 7.0 out of 10
N/A
ThreatStream from Anomali in Redwood City speeds detection of threats by uniting security solutions under one platform and providing tools to operationalize threat intelligence. ThreatStream also automates many of the tasks typically assigned to security professionals, freeing analysts to quickly handle threats. ThreatStream collects threat intelligence data from hundreds of third party sources.N/A
NetWitness Cloud SIEM
Score 6.1 out of 10
N/A
NetWitness Cloud SIEM delivers log management, retention, and analytics services in a simplified cloud form. It aims t o eliminate traditional deployment and administration requirements with a simple throughput-based licensing model, to make high-quality SIEM quick and easy to acquire without sacrificing capability or power.N/A
Pricing
Anomali ThreatStreamNetWitness Cloud SIEM
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Anomali ThreatStreamNetWitness Cloud SIEM
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details——
More Pricing Information
Community Pulse
Anomali ThreatStreamNetWitness Cloud SIEM
Top Pros
Top Cons
Features
Anomali ThreatStreamNetWitness Cloud SIEM
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Anomali ThreatStream
-
Ratings
NetWitness Cloud SIEM
7.6
1 Ratings
3% below category average
Centralized event and log data collection00 Ratings8.01 Ratings
Correlation00 Ratings10.01 Ratings
Event and log normalization/management00 Ratings8.01 Ratings
Deployment flexibility00 Ratings10.01 Ratings
Integration with Identity and Access Management Tools00 Ratings7.01 Ratings
Custom dashboards and workspaces00 Ratings6.01 Ratings
Host and network-based intrusion detection00 Ratings4.01 Ratings
Best Alternatives
Anomali ThreatStreamNetWitness Cloud SIEM
Small Businesses
AlienVault USM
AlienVault USM
Score 8.0 out of 10
AlienVault USM
AlienVault USM
Score 8.0 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Splunk Enterprise
Splunk Enterprise
Score 8.4 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
InsightIDR
InsightIDR
Score 8.6 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Anomali ThreatStreamNetWitness Cloud SIEM
Likelihood to Recommend
8.9
(3 ratings)
7.0
(1 ratings)
User Testimonials
Anomali ThreatStreamNetWitness Cloud SIEM
Likelihood to Recommend
Anomali
Anomali ThreatStream is excellent in scenarios where we deliver Managed Security Services to customers. It offers exhaustive volumes of information in the form of threat bulletins, IOCs, Threat Actor profiling, and details related to campaigns in the wild which can be used to a great extent by MSSPs. For an enterprise SOC, I believe it is a little less suited purely because of the pricing aspect as it is slightly towards the expensive side of the spectrum.
Read full review
RSA Security
It is really a robust platform that can be heavily customized to suit requirements. Good for advanced hunting and forensics. Robust automation features.
Read full review
Pros
Anomali
  • Indicators of Compromise
  • Signatures
  • Community Sharing
Read full review
RSA Security
  • Log collection and parsing.
  • Packet collection and parsing.
  • Enhanched analytics and alerting.
  • Robust integration.
Read full review
Cons
Anomali
  • The user interface, perhaps there is some room for improvement although it is good already.
  • Confidence assigning process for IOCs needs to be more robust and transparent.
  • While integration with SIEM solutions is a cakewalk, there is definitely added value if SIGMA rule conversion and YARA rule creation are provided from the platform.
Read full review
RSA Security
  • Lacking out of the box best practice templates etc. It relies heavily on customization.
  • Lack of up to date threat feeds.
  • Difficult to learn and use initially.
Read full review
Alternatives Considered
Anomali
Many of the products that can be used to be ingested into a security event management software can be cumbersome with threat streamThere are many opportunities to continue fine-tuning the environment and providing great context in regards to threat research. When compared to other products threat stream stands out from usability and features.
Read full review
RSA Security
Best in Class for us, and was a good choice since we already are using a lot of other RSA products(DLP, Archer etc.)
Read full review
Return on Investment
Anomali
  • After the Initial startup cost, it has overall had a positive impact by increasing efficiency of the team and freeing up analysts to do manual threat hunting
Read full review
RSA Security
  • Hard to calculate ROI since it is not revenue based.
  • It is a expensive solution, bit very capable.
Read full review
ScreenShots