We compared Cisco Secure Network Analytics and ExtraHop Reveal(x) across 5 parameters based on our user reviews. After reading the collected data, you can find our conclusion below:
Cisco Secure Network Analytics users highly value its advanced threat detection capabilities, extensive visibility and control over network traffic, and proactive alerting system. They appreciate the commendable customer service and support provided by Cisco Secure Network Analytics. ExtraHop Reveal(x) also offers robust network visibility and real-time threat detection.
Initial Setup and Support: Cisco Secure Network Analytics has a relatively quick and simple setup process that typically takes one to two weeks for deployment. ExtraHop Reveal(x) setup can be more complex and time-consuming, often taking about a week to complete due to the involvement of network taps and packet brokers. Cisco Secure Network Analytics provides a range of management options and support services, including workshops for a better understanding of solutions. They also experience stability issues in new versions. ExtraHop Reveal(x) excels in efficiency and troubleshooting capabilities of their support team, although there are occasional sporadic support feedback.
Valuable Features: Cisco Secure Network Analytics is praised for its advanced threat detection capabilities, proactive alerting system, and effective security incident response. ExtraHop Reveal(x) stands out for its robust network visibility, comprehensive analytics capabilities, and data-driven decision-making features.
Room For Improvement: Cisco Secure Network Analytics could benefit from improvements in data processing speed, better visualization features, and advanced threat detection capabilities. ExtraHop Reveal(x) needs enhancements in user interface, accuracy, responsiveness, documentation, and customer support.
Setup Cost: Cisco Secure Network Analytics has been considered reasonable and competitive, yet with a potentially higher initial setup cost. ExtraHop Reveal(x) is praised for its relatively low setup cost, making implementation easy and cost-effective.
ROI: The ROI from Cisco Secure Network Analytics has been significant, providing improved network security, reduced risks, advanced analytics capabilities, and reliable support. ExtraHop Reveal(x) excels in network visibility, anomaly detection, and user-friendly interface.
The summary above is based on interviews we conducted recently with Cisco Secure Network Analytics and ExtraHop Reveal(x) users. To access the review's full transcripts, download our report.
"There are already many functionalities, so I don't think there is anything to improve."
"The ability to send data flow from other places and have them all in one place is very valuable for us."
"It provides good visibility to the customers. People are still evaluating it, but it provides visibility and helps them to take action to remediate and mitigate the issues that are highlighted on the dashboard. It has good integration with the Cisco switching platform."
"Stability is the most valuable feature we have seen in this solution."
"Most valuable features are the network maps and server and network response time."
"The most valuable feature is anomaly detection, where it finds things that are not allowed internally."
"It works efficiently for encrypted traffic analysis."
"The most valuable feature about this solution is that it gives me insight of my network."
"ExtraHop Reveal(x) is one of the tools that works out of the box when it comes to threat hunting."
"When there are performance issues with an HTTP app, ExtraHop enables us to identify the causes within a few minutes. We can see what transactions are being impacted by something that may be happening within the server environment."
"The solution's initial setup process is easy."
"It's a wire analytics tool. We use it for isolating and determining issues on our network or applications. It does a lot for crediting the network as opposed to discrediting the network. A lot of people come along and say that it's a network issue. It's always considered to be a network issue, but by using ExtraHop, we can quickly tell them that it's not a networking issue. It's something to do with your application or something at the other end. It could be a database issue. This tool gives us the ability to pinpoint with great accuracy the comings and goings on our network."
"Reveal X integrates seamlessly with CrowdStrike. If you see something sketchy on the network, you can quarantine devices through ExtraHop and it'll push to the CrowdStrike server."
"The solution works well for sending sensors."
"The most valuable features of ExtraHop Reveal(x) are the detection and alerting of network behavior and anomalies."
"We had useful information within the hour of deployment. The ability to trace back for historical analysis, as well as the behavioral analysis done with the security information, puts the user in a position to make an informed decision to mitigate the performance or security incidents. Regarding the security incidents, Reveal (x) is able to create incident cards that guide your teams through the incidents and gives you the option to delve into the transaction detail to potentially view payloads as well."
"The initial setup was straightforward but required a lot of data entry, to begin with building out the server types and network types."
"There could be better integration on the programming side, which uses Python. StealthWatch could provide a template for Python to manage the switches. For example, it would be nice if StealthWatch bounced a port automatically it detected something anomalous."
"The initial setup was complex."
"Many of these tools require extensive on-premises hardware to run."
"There's a lot of traffic on our network that we don't see sometimes."
"One thing I would like to see improved is if it could automatically be tied through ISE, instead of you having to manually get notifications and disable it yourself."
"We would like the solution to make more advances in the way that Extreme Networks has been doing."
"We need to be able to filter out internal IPs as non-threats."
"Agent management could certainly use some focus. It should also be a little bit easier to work with collections. We should be able to nest collections within collections. There should be better nesting."
"They used to have the ability to decode Citrix sign-on, setup, and tear down. Unfortunately, Citrix has stopped sharing that knowledge. Citrix has continued to change its model of processing, making it harder and harder to troubleshoot."
"The solution's reporting part and GUI are areas with certain shortcomings where improvements are required."
"It needs integration with more security vendors."
"ExtraHop Reveal(x) could improve by allowing a longer look back in the feature. Right now you have a limit of 30 days to look back on your activity. I've used Darktrace before, and they allow you the ability to play back events. This would be a good feature to have in ExtraHop Reveal(x)."
"The solution’s pricing could be improved."
"I would like to see more cloud capability."
"The solution should include more support protocols."
More Cisco Secure Network Analytics Pricing and Cost Advice →
Cisco Secure Network Analytics is ranked 4th in Network Traffic Analysis (NTA) with 58 reviews while ExtraHop Reveal(x) is ranked 5th in Network Traffic Analysis (NTA) with 12 reviews. Cisco Secure Network Analytics is rated 8.2, while ExtraHop Reveal(x) is rated 8.6. The top reviewer of Cisco Secure Network Analytics writes "Increased the visibility of what is happening in our network". On the other hand, the top reviewer of ExtraHop Reveal(x) writes "It helps you visualize how data moves across your network". Cisco Secure Network Analytics is most compared with Darktrace, Cisco Secure Cloud Analytics, ThousandEyes, Vectra AI and Cisco Cognitive Threat Analytics, whereas ExtraHop Reveal(x) is most compared with Darktrace, Vectra AI, Corelight, Arista NDR and ExtraHop Reveal(x) 360. See our Cisco Secure Network Analytics vs. ExtraHop Reveal(x) report.
See our list of best Network Traffic Analysis (NTA) vendors and best Network Detection and Response (NDR) vendors.
We monitor all Network Traffic Analysis (NTA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.