Skip to main content
TrustRadius
NetWitness Cloud SIEM

NetWitness Cloud SIEM

Overview

What is NetWitness Cloud SIEM?

NetWitness Cloud SIEM delivers log management, retention, and analytics services in a simplified cloud form. It aims t o eliminate traditional deployment and administration requirements with a simple throughput-based licensing model, to make high-quality SIEM quick and easy to acquire…

Read more
Recent Reviews
Read all reviews
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is NetWitness Cloud SIEM?

NetWitness Cloud SIEM delivers log management, retention, and analytics services in a simplified cloud form. It aims t o eliminate traditional deployment and administration requirements with a simple throughput-based licensing model, to make high-quality SIEM quick and easy to acquire without…

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

5 people also want pricing

Alternatives Pricing

What is Microsoft Sentinel?

Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.

What is AlienVault USM?

AlienVault® Unified Security Management® (USM) delivers threat detection, incident response, and compliance management in one unified platform. It is designed to combine all the essential security capabilities needed for effective security monitoring across cloud and on-premises environments,…

Return to navigation

Product Details

What is NetWitness Cloud SIEM?

The NetWitness Platform is presented as an evolved SIEM and threat detection and response solution that functions as a single, unified platform for security data. It features an analyst workbench for triaging alerts and incidents, and it orchestrates security operations programs end to end.

The NetWitness Platform for XDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a single interface.

NetWitness Cloud SIEM Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(3)

Reviews

(1-1 of 1)
Companies can't remove reviews or game the system. Here's why
Score 7 out of 10
Vetted Review
Verified User
Incentivized
We are using it as RSA Security Analytics (NetWitness) for our SIEM. We do log and packet collection and analysis and generate alerts and incidents that flow into RSA Archer Security Operations module. It is a major part of our information security program, and [we] depend on it for managing DLP incidents, Windows event logging and alerting. Our goal is automation, so we automate as much as we can, since we have limited resources, and do not have a 24/7 SOC.
  • Log collection and parsing.
  • Packet collection and parsing.
  • Enhanched analytics and alerting.
  • Robust integration.
  • Lacking out of the box best practice templates etc. It relies heavily on customization.
  • Lack of up to date threat feeds.
  • Difficult to learn and use initially.
It is really a robust platform that can be heavily customized to suit requirements. Good for advanced hunting and forensics. Robust automation features.
Security Information and Event Management (SIEM) (7)
75.71428571428571%
7.6
Centralized event and log data collection
80%
8.0
Correlation
100%
10.0
Event and log normalization/management
80%
8.0
Deployment flexibility
100%
10.0
Integration with Identity and Access Management Tools
70%
7.0
Custom dashboards and workspaces
60%
6.0
Host and network-based intrusion detection
40%
4.0
  • Hard to calculate ROI since it is not revenue based.
  • It is a expensive solution, bit very capable.
Best in Class for us, and was a good choice since we already are using a lot of other RSA products(DLP, Archer etc.)
Return to navigation