TrustRadius: an HG Insights company

Juniper Secure Analytics

Score9 out of 10

1 Reviews and Ratings

What is Juniper Secure Analytics?

Juniper Secure Analytics is a security information and event management (SIEM) system designed to consolidate and analyze event data from various devices, endpoints, and applications in near real time. According to the vendor, this solution is suitable for organizations of all sizes and caters to the needs of IT security professionals, network administrators, security operations centers (SOCs), managed security service providers (MSSPs), and enterprise organizations across industries such as finance, healthcare, retail, government, and telecommunications.

Key Features

JSA Virtual Appliance: The JSA Virtual Appliance is a virtual SIEM that collects, analyzes, and consolidates security data from networked devices to detect and remediate security incidents.

99.9% Security Effectiveness: According to the vendor, Juniper Secure Analytics demonstrates a 99.9% exploit block rate with zero false positives, as evidenced by its "AAA" rating in CyberRatings' 2023 Enterprise Network Firewall Report.

RAM: The JSA Virtual Appliance is equipped with 24 GB of RAM, which the vendor claims ensures smooth performance and efficient processing of security events and logs.

Canned Reports: Juniper Secure Analytics offers 1300 pre-built reports that cover various aspects of security monitoring and analysis, including threat detection, compliance management, and incident response.

Maximum Flows per Minute: The JSA Virtual Appliance supports a maximum of 600,000 flows per minute, enabling comprehensive monitoring and analysis of network traffic in real time.

Top Performing Features

  • Event and log normalization/management

    Ability to normalize event syntax so that logs can be compared and are machine-understandable

    Category average: 8.5

  • Integration with Identity and Access Management Tools

    Integration with access control tools like Active Directory and LDAP

    Category average: 8.4

  • Data integration/API management

    Ease and quality of data integrations between SIEM and other systems

    Category average: 8

Areas for Improvement

  • Custom dashboards and workspaces

    dashboards that can be customized to meet the needs of specific groups

    Category average: 8.6

  • Host and network-based intrusion detection

    Ability to detect both endpoint intrusion and network ingress detection

    Category average: 8

  • Rules-based and algorithmic detection thresholds

    Effectiveness of manually-established rules and algorithmically-determined detection thresholds

    Category average: 8

Juniper... What is it NOT good for?

Use Cases and Deployment Scope

We currently use this capability to analyze all of our security incidents on the network devices with the support of Splunk as well. It is not our main SIEM tool, but it is in the top 3 for the organization. We use this from an Enterprise perspective for over 100k assets.

Pros

  • Analytics.
  • Network monitoring/behavior.
  • Security issue detection.

Cons

  • User training.
  • Capability for other products.

Most Important Features

  • Data analytics.

Return on Investment

  • Found issues before our other tools.

Alternatives Considered

FortiSIEM

Other Software Used

Splunk IT Essentials, PowerConnect for Splunk, Splunk Log Observer