Cisco Stealthwatch is a network behavior analysis product based on technology acquired by Cisco with its Lancope acquisition in 2015.
N/A
Intermapper
Score 8.4 out of 10
N/A
Intermapper is a network monitoring and mapping software for hybrid environments. Intermapper provides real-time performance alerts and bandwidth monitoring with cross-platform functionality.
N/A
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.3 out of 10
N/A
SolarWinds Netflow Traffic Analyzer is a network monitoring tool within the broader SolarWinds ecosystem. It includes core traffic monitoring features, as well as customizable traffic reports and alerts.
N/A
Pricing
Cisco Secure Network Analytics
Intermapper
SolarWinds NetFlow Traffic Analyzer (NTA)
Editions & Modules
No answers on this topic
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco Secure Network Analytics
Intermapper
SolarWinds NetFlow Traffic Analyzer (NTA)
Free Trial
No
Yes
Yes
Free/Freemium Version
No
Yes
No
Premium Consulting/Integration Services
No
Yes
No
Entry-level Setup Fee
No setup fee
Optional
Optional
Additional Details
—
Intermapper pricing is based on number of devices monitored. Intermapper is free for 5 devices or less. Subscription pricing starts at $303 for 25 devices. Device-based pricing starts at $765 for 25 devices.
Cisco Secure Network Analytics is in a class of its own and some of these products come close but are not in the same class. The other products I tested take a lot more of them to get the same results you would from the Enterprise class of Cisco products. I have been very happy …
While other platforms such as Nagios and Solarwinds NTA provide visibility of the traffic, it either (*) does not provide API/programmatic way to pull the data to other platforms or (*) does not interface with secondary security systems to report on malicious traffic activity. …
Few products operate off the Netflow or RAP/SPAN traffic versus the endpoint. Of those products, many operate from the aggregate traffic of uplinks/downlinks, whereas Secure Network Analytics focuses on viewing all traffic to give per-endpoint comprehensive data analytics. SNA is a great product for network visibility and detection, and to preserve that focus, other options such as remediation or quarantined are deferred to other products in the security ecosystem. SNA uses Machine Learning models to determine traffic behavioral compliance, which is a double-edged sword. On one hand, it mitigates zero day attacks changing traffic patterns, but conversely, it requires training to know acceptable traffic patterns. Unfortunately, many adopters of SNA do not spend the time giving it the user input and so the ML models never gets the correct weights and parameters to work from.
Intermapper is a light weight, quick and easy to use monitoring application. It will get you up and monitoring key infrastructure devices with a simple management interface and effective alert system that doesn't generate a lot of noise. It provides mobile device access through a web interface and is relatively inexpensive.
We use and depend on it for status state of our network gear, switches and routers. It does an excellent job of getting you the details you need to confirm all devices and products are working at the level needed. At times, it does tend to flag network switch ports and/or switches themselves as exceeding their rated capacity when frequently it was a quick blip of high traffic due to downloads, or uploads causing the max'ing of the device. Again, you can adjust the settings but then you adjust it too high and miss real activity. It can become nuisance alerting when you tend to then ignore
The best thing about Intermapper is that it is map-based. You start by building your map, which is done completely automatically. I've used many different monitoring software packages, Solarwinds, Nagios, Opmanager, and it is a royal PITA to create live maps with those.
Another great feature is that it shows you, visually, the bandwidth utilization of your network by using "ants" and color codes. Incredibly useful.
Alarms are very easy to setup, again much easier than the packages mentioned above.
The level of customization possible with Network Bandwidth Analyzer is very valuable. Rather than being stuck with a "one-size-fits-all" presentation, an administrator can easily create customized views, reports, and alerts so that users can have a more tailored view of the data provided by Network Bandwidth Analyzer. This has the effect of making the tool more attractive to the end user.
The NetFlow Traffic Analyzer piece of Network Bandwidth Analyzer provides the details on bandwidth usage on the network. More than knowing how much bandwidth is being used, one is provided with detailed information on how that bandwidth is being used. This provides invaluable information for capacity planning and even certain forensic tasks faced by the network engineer.
The ability to produce network maps provides an easy way to create an attractive and functional NOC/SOC view of the entire network. Both technician and the occasional passerby can quickly determine if there are issues to be addressed. The ability to customize a map with background images and custom icons and stencils can make these maps really pop.
Some of the jobs can be difficult to setup until you know how they were designed
Unless coupled with other Cisco products, you may not get all of the information you would like to have
If you have a network that already has many issues it may take a lot of time to see the value in the product; it would take time to weed everything which this product will detect for you to use it to find that needle in the haystack
The ability to intuitively and quickly serve up specified information up to a dashboard for general “public” consumption, that cycles through several pages of information.
The ability to intuitively set up alerting on bandwidth levels, instead of having to dig through all types of alerts available to find the one needed.
Provide a pricing model based on different support levels: if I want only available update installations, don’t make me pay the same amount as those wanting full support.
Cisco Secure Network Analytics is a fantastic tool, but does require some setup and upkeep which may turn off smaller IT Security teams. However, once all the flows are set up and the product is functioning with the proper rules, the insight into your network is fantastic. For us, the product has a significant ROI and will be a product we keep up on.
Strong and complete tool which gives comprehensive methods to discover cyber security incidents and prevent data leakage. In case of common use of Cisco StealthWatch and Cisco ISE, you will receive [the] ability [to] not just discover cyber security incidents but also dynamically respond to them. This makes StealthWatch one of most valuable products through[out] [the] whole Cisco Security product portfolio.
As far as rating for usability is concerned I would give 10/10 as NTA is very easy to use. All you need to do is install that module and ask network Team to configure the Netflow towards Server IP. [The] rest is pre-configured and reports are pre-built. Moment you receive the flows from Network all you will have is information about traffic.
I would rate Cisco Secure Network Analytics’ availability as 8 out of 10. The platform is highly stable and reliable, with users reporting minimal downtime and consistent performance once the system is properly deployed and configured.
Overall winner because it exceeds our expectations by answering all our requirements and at the same time empowers our operations thru other built-in capabilities it has. Visibility is a key to security operations and Cisco StealthWatch really gives us a magnifying glass to check all logs in the network for threat intelligence and threat hunting.
The product works well and is very easy to maintain. As such, we haven't had many occasions to use support. When we have called them they were easy to contact and responsive to our questions. We have had the product for years and it may have been a year or better since the last time we contacted them.
I know we could probably pay for it, but it would be nice if we could get to a tier 2 technician faster. Spending a couple of hours on the phone with the level 1 technician, when we have already tried the troubleshooting they are walking us through, is just a waste of time.
The training offered by SolarWinds is some of the best out there. They have several different videos that go into great detail from initial setup to advanced configurations. In addition to the view at your own pace video, they also have live training for customers that focus on a single product and you can ask questions with the folks who develop the software. I have had good success with their live sessions and getting questions answered.
Implementation of the product can be tedious, especially fine tuning its rules to customize it to your environment. However, after that is done, CSNA is a very useful and flexible product that would enhance the security posture of any corporate network.
I wasn't involved in the decision-making when it happened. It was a couple of years ago, but I can't think of the vendor's name. They used to be here at Cisco Live. But it was another NetFlow vendor, but they were strictly NetFlow and all they did was just a net flow and the Secure Network Analytics has like some of the security anomaly detection stuff built into it. And that was kind of a deciding factor of wanting more of the security focus of the net flow. The net flow was a bonus, but the security stuff was what we were looking for.
Intermapper is a cross between WhatsUp Gold and Nagios. WhatsUp Gold being for a less technical end-user and Nagios doing more than just SNMP scans and up down monitoring.
SolarWinds NetFlow Traffic Analyzer compared to Wireshark and PRTG Network Monitor beats it by just the simple interface. Though all are manual setup, NTA takes it a step further with graphs and reports that analyze the data for you. In comparing to Extrahop from a bandwidth comparison, Extrahop wins but Extrahop is a lot more than just a bandwidth monitoring and cost.
It is a little pricey - in my organization, with budget cuts, I eventually had to replace it with an open source product (NTOP). While it works well for visibility, it simply isn't the same. If you can afford it, don't bother looking anywhere else - just get it.
Being able to detect, pivot out, and remmediate from one console was awesome.
Downtime costs money. Every minute we can get ahead of an outage is time that a plant is not sitting there waiting. We don't need to wait for a call from a plant, we know they are down immediately and we can begin troubleshooting.
Be prepared to answer lots of questions. When people see the data in NTA they are going to want to know why App A is talking to App B. Be ready to explain!
Hand the keys to the NTA kingdom to the network team. They will thank you. Everyone wants to have friends on the network team, right?
Be prepared to invest in some significant compute and storage performance to keep up with your NTA monitoring
Running the latest firmware for your network gear is (often) required to take advantage of all the flow-monitoring. You upgrade regularly, right??