There's nothing like it and a dream to operate, very intuitive. The most valuable feature is NetFlow. The beginning of any security investigation starts with NetFlow data.
Highly motivated Security Engineer incident Response, Vuln Mgmt, Malware Analysis, IDS/IPS, DLP, Network Security +more at a transportation company with 10,001+ employees
NetFlow data is the beginning of any security investigation, very easy to use
Pros and Cons
- "The most valuable feature is NetFlow. The beginning of any security investigation starts with NetFlow data."
- "There's nothing like it and a dream to operate, very intuitive."
- "One update I would like to see is an agent-based client. Currently StealthWatch is network based."
What is most valuable?
How has it helped my organization?
Easily identifiable anomalies that you can't see with signature detections.
What needs improvement?
I am so familiar with the product I would say none. Lancope has always listened to customer input for product enhancements. One update I would like to see is an agent-based client. Currently StealthWatch is network based. A local agent could help manage endpoints.
For how long have I used the solution?
12 years.
Buyer's Guide
Cisco Secure Network Analytics
August 2026
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,834 professionals have used our research since 2012.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and support?
I've known those guys for a long time. They are completely familiar with their product.
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
Very straightforward. They helped in every step of the installation.
What's my experience with pricing, setup cost, and licensing?
Licensing is done by flows per second, not including outside>in traffic.
Which other solutions did I evaluate?
I have tried the Sourcefire solution but StealthWatch wins because of ease of use.
What other advice do I have?
Go for it. Also great for your network segmentation project.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Analyst at a non-profit with 1,001-5,000 employees
Enables me to detect devices talking to suspect IPs.
Pros and Cons
- "I value the feature which enables me to detect devices talking to suspect IPs."
- "We need to be able to filter out internal IPs as non-threats."
What is most valuable?
I value the feature which enables me to detect devices talking to suspect IPs.
How has it helped my organization?
We can now see what is going on in our network.
What needs improvement?
We need to be able to filter out internal IPs as non-threats.
For how long have I used the solution?
We have been using the product since 2008.
What do I think about the stability of the solution?
We did not encounter any issues with stability.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability.
How are customer service and technical support?
The technical support is good.
Which solution did I use previously and why did I switch?
We did not use any other solution previously.
How was the initial setup?
The initial setup was relatively easy, though different devices need different configurations for the flow exports.
What's my experience with pricing, setup cost, and licensing?
It is worth the cost.
Which other solutions did I evaluate?
We evaluated Arbor.
What other advice do I have?
Get it in and see what you can see!
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Network Monitoring Software Network Traffic Analysis (NTA) Network Detection and Response (NDR) Cisco Security PortfolioPopular Comparisons
Cisco Secure Firewall
Cisco Umbrella
SolarWinds NPM
Splunk Observability Cloud
TrendAI Vision One
PRTG Network Monitor
Cisco Identity Services Engine (ISE)
LogicMonitor
WhatsUp Gold
Auvik Network Management (ANM)
ThousandEyes
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- When evaluating Network Performance Monitoring, what aspect do you think is the most important to look for?
- What is the best network monitoring software for large enterprises?
- What Questions Should I Ask Before Buying a Network Monitoring Tool?
- UIM OnPrem - SaaS
- Anyone switching from SolarWinds NPM? What is a good alternative and why?
- What is the best tool for SQL monitoring in a large enterprise?
- What tool do you recommend using for VoIP monitoring for a mid-sized enterprise?
- Should we choose Nagios or PRTG?
- Which is the best network monitoring tool: Zabbix or Solarwinds? Pros and Cons?













