Cisco Stealthwatch is a network behavior analysis product based on technology acquired by Cisco with its Lancope acquisition in 2015.
N/A
Flowmon ADS
Score 9.1 out of 10
N/A
Flowmon
Anomaly Detection System (Flowmon ADS) by Kemp is a network security solution that analyzes network
traffic from multiple perspectives to counter malicious behaviour and cyberattacks.
By using a combination of detection methods, including machine learning, adaptive
baselining, heuristics, behaviour patterns, and signatures, context-rich
visualization and…
N/A
Pricing
Cisco Secure Network Analytics
Kemp Flowmon ADS
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco Secure Network Analytics
Flowmon ADS
Free Trial
No
Yes
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
Capacity-based licensing per amount of monitored traffic.
Cisco Secure Network Analytics is a compulsion to any organization looking to secure their network in silence with a complete record and analysis of the threats. All the critical information of the client is also preserved for instance and assistance for future needs. Cyber-attacks can’t even think to roam about your network in any case.
Flowmon ADS is a customizable anomaly detection solution with excellent scalability capabilities and quick integration into the organization environment. Flowmon ADS provides a large set of essential detections out of the box, which allows to quickly acquire an awareness of potential problems in the monitored network. Custom configuration, filters, and false-positive flagging make the system highly customizable for diverse environments. Powerful dashboards make summaries and reporting a breeze. We use the Flowmon Anomaly Detection System daily for event detection and incident handling. It provides high-quality detection methods with low false-positive rates.
It's really good at mapping out like what applications are, like who's talking to what. To see if someone thinks that a particular application is only being used a certain way and we can validate what's talking to that system with the tool.
Kemp Flowmon ADS provides a large set of essential detections out of the box, which allows us to quickly acquire an awareness of potential problems in the monitored network.
Custom configuration, filters, and false-positive flagging make the system highly customizable for diverse environments.
Powerful dashboards make summaries and reporting a breeze.
Cisco Secure Network Analytics is a fantastic tool, but does require some setup and upkeep which may turn off smaller IT Security teams. However, once all the flows are set up and the product is functioning with the proper rules, the insight into your network is fantastic. For us, the product has a significant ROI and will be a product we keep up on.
Strong and complete tool which gives comprehensive methods to discover cyber security incidents and prevent data leakage. In case of common use of Cisco StealthWatch and Cisco ISE, you will receive [the] ability [to] not just discover cyber security incidents but also dynamically respond to them. This makes StealthWatch one of most valuable products through[out] [the] whole Cisco Security product portfolio.
We haven't had too many issues with the uptime and availability of CSNA, but the application does have a lot of dependancies and we have seen issues after an upgrade that caused an outage for several hours.
Overall winner because it exceeds our expectations by answering all our requirements and at the same time empowers our operations thru other built-in capabilities it has. Visibility is a key to security operations and Cisco StealthWatch really gives us a magnifying glass to check all logs in the network for threat intelligence and threat hunting.
Implementation of the product can be tedious, especially fine tuning its rules to customize it to your environment. However, after that is done, CSNA is a very useful and flexible product that would enhance the security posture of any corporate network.
While other platforms such as Nagios and Solarwinds NTA provide visibility of the traffic, it either (*) does not provide API/programmatic way to pull the data to other platforms or (*) does not interface with secondary security systems to report on malicious traffic activity. Ultimately, these platforms accomplish the visibility, but do little else in the overall IT/security ecosystem of product, making them "dead end" data flow products where data goes in but does not share elsewhere.
Once tuned and baselines established, it is far easier to identify issues on a network
Management is able to look at the dashboard and fairly quickly get an update on the status of how the network is performing and what threats may be out there
Reports can be scheduled to send on a regular basis to all involved with management of the infrastructure and the security team