Cisco Stealthwatch is a network behavior analysis product based on technology acquired by Cisco with its Lancope acquisition in 2015.
N/A
ExtraHop Performance Platform
Score 8.4 out of 10
N/A
ExtraHop in Seattle, Washington offers an IT operations analytics platform via the ExtraHop Performance Platform, providing a dynamic, real-time view of all transactions in the IT environment, every team from NetOps to SecOps can spot and solve problems fast.
Cisco Secure Network Analytics is a compulsion to any organization looking to secure their network in silence with a complete record and analysis of the threats. All the critical information of the client is also preserved for instance and assistance for future needs. Cyber-attacks can’t even think to roam about your network in any case.
ExtraHop is going to replace our packet capture and storage technology since it not only detects network security breaches but can also have sensors installed throughout our network to look at historical packet captures for analysis. ExtraHop is well suited for threat mitigation, network segmentation, and threat analysis of the network.
It's really good at mapping out like what applications are, like who's talking to what. To see if someone thinks that a particular application is only being used a certain way and we can validate what's talking to that system with the tool.
Extrahop can perform health monitoring end to end if you have multiple probes deployed in your network, the intelligence engine can easily help you to compare and data collected from different hops and help you to narrow down the issue to a specific part of your end to end network.
Extrahop is not just analyzing and monitoring the health of the network, actually, its deep-dive analysis engine can perform an analysis from the network layer up to the application layer. It's easy to identify the root cause whether it's a network issue or something wrong in the application, save the time to have the issue go around again and again between network team and application team to blame each other.
Extrahop provides good programming functionalities allowing the user to do their specific programing to meet the requirement of how they design to better operate the service.
Cisco Secure Network Analytics is a fantastic tool, but does require some setup and upkeep which may turn off smaller IT Security teams. However, once all the flows are set up and the product is functioning with the proper rules, the insight into your network is fantastic. For us, the product has a significant ROI and will be a product we keep up on.
Strong and complete tool which gives comprehensive methods to discover cyber security incidents and prevent data leakage. In case of common use of Cisco StealthWatch and Cisco ISE, you will receive [the] ability [to] not just discover cyber security incidents but also dynamically respond to them. This makes StealthWatch one of most valuable products through[out] [the] whole Cisco Security product portfolio.
We haven't had too many issues with the uptime and availability of CSNA, but the application does have a lot of dependancies and we have seen issues after an upgrade that caused an outage for several hours.
Overall winner because it exceeds our expectations by answering all our requirements and at the same time empowers our operations thru other built-in capabilities it has. Visibility is a key to security operations and Cisco StealthWatch really gives us a magnifying glass to check all logs in the network for threat intelligence and threat hunting.
Implementation of the product can be tedious, especially fine tuning its rules to customize it to your environment. However, after that is done, CSNA is a very useful and flexible product that would enhance the security posture of any corporate network.
While other platforms such as Nagios and Solarwinds NTA provide visibility of the traffic, it either (*) does not provide API/programmatic way to pull the data to other platforms or (*) does not interface with secondary security systems to report on malicious traffic activity. Ultimately, these platforms accomplish the visibility, but do little else in the overall IT/security ecosystem of product, making them "dead end" data flow products where data goes in but does not share elsewhere.
A new and very useful ability of ExtraHop [Performance Platform] is the single tool for cloud forensics. Cloud incidents can easily be determined with the ability to implement responses along with assessments to easy the burden of reports. In comparison to Netscout, ExtraHop's user interface is more fluent and easier to maneuver.
Once tuned and baselines established, it is far easier to identify issues on a network
Management is able to look at the dashboard and fairly quickly get an update on the status of how the network is performing and what threats may be out there
Reports can be scheduled to send on a regular basis to all involved with management of the infrastructure and the security team