TrustRadius: an HG Insights company

JSA Series Secure Analytics Virtual Appliance

Score9 out of 10

1 Reviews and Ratings

What is JSA Series Secure Analytics Virtual Appliance?

Juniper Secure Analytics is a security information and event management (SIEM) system designed to consolidate and analyze event data from various devices, endpoints, and applications in near real time. According to the vendor, this solution is suitable for organizations of all sizes and caters to the needs of IT security professionals, network administrators, security operations centers (SOCs), managed security service providers (MSSPs), and enterprise organizations across industries such as finance, healthcare, retail, government, and telecommunications.

Read more details.

Top Performing Features

  • Event and log normalization/management

    Ability to normalize event syntax so that logs can be compared and are machine-understandable

    Category average: 8.6

  • Integration with Identity and Access Management Tools

    Integration with access control tools like Active Directory and LDAP

    Category average: 8.2

  • Data integration/API management

    Ease and quality of data integrations between SIEM and other systems

    Category average: 8

Areas for Improvement

  • Custom dashboards and workspaces

    dashboards that can be customized to meet the needs of specific groups

    Category average: 8.4

  • Host and network-based intrusion detection

    Ability to detect both endpoint intrusion and network ingress detection

    Category average: 8.1

  • Rules-based and algorithmic detection thresholds

    Effectiveness of manually-established rules and algorithmically-determined detection thresholds

    Category average: 8.3

Who Buys & Uses JSA Series Secure Analytics Virtual Appliance

Juniper... What is it NOT good for?

Use Cases and Deployment Scope

We currently use this capability to analyze all of our security incidents on the network devices with the support of Splunk as well. It is not our main SIEM tool, but it is in the top 3 for the organization. We use this from an Enterprise perspective for over 100k assets.

Pros

  • Analytics.
  • Network monitoring/behavior.
  • Security issue detection.

Cons

  • User training.
  • Capability for other products.

Most Important Features

  • Data analytics.

Return on Investment

  • Found issues before our other tools.

Alternatives Considered

FortiSIEM

Other Software Used

Splunk IT Essentials, PowerConnect for Splunk, Splunk Log Observer