No more typing reviews! Try our Samantha, our new voice AI agent.

Arbor DDoS vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arbor DDoS
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (3rd)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (36th), Security Information and Event Management (SIEM) (34th)
 

Mindshare comparison

Arbor DDoS and NetWitness Platform aren’t in the same category and serve different purposes. Arbor DDoS is designed for Distributed Denial-of-Service (DDoS) Protection and holds a mindshare of 5.7%, down 11.7% compared to last year.
NetWitness Platform, on the other hand, focuses on Log Management, holds 1.1% mindshare, up 0.4% since last year.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Arbor DDoS5.7%
Cloudflare11.9%
Imperva Application Security Platform7.7%
Other74.7%
Distributed Denial-of-Service (DDoS) Protection
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.1%
Splunk Enterprise Security6.8%
IBM Security QRadar4.5%
Other87.6%
Log Management
 

Featured Reviews

reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The AI capabilities and anomaly detection using machine learning modules like isolation forests and auto-encoders are the most effective in mitigating DDoS attacks."
"The artificial intelligence feature is most appreciated. This solution can lower the throughput and clear the traffic, which is something really important for us. It also provides good protection. It is user-friendly, and its integration has also been really fast. We have many critical applications, and it was easy to integrate Arbor DDoS with our website, mobile application, and web banking."
"Reporting is quite good. There are several pages of reporting on DDoS attacks, and you can find all the details that you need."
"Because this Arbor DDoS product is the best, I do not need to spend time supporting it."
"Arbor DDoS offers security features that automatically detect and prevent DDoS attacks."
"I recommend using Arbor DDoS for those wanting to keep their services online."
"It is fully mitigating the attacks. We've dealt with other ones where we didn't necessarily see that. The detection is very good. It's also very simple to use. Arbor is a single pane of glass, whereas with other solutions you might have a detection pane of glass and then have to go to a separate interface to deal with the mitigation. That single pane of glass makes it much simpler."
"We also use it by serving our customers' cloud signaling services with on-premise APS devices."
"Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients."
"Overall, this is a good solution with suitable features and it very well fits our needs."
"The newer 11.5 version that my team is using has found it to have good mapping."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The product's initial setup phase was not at all difficult."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
"This solution has a very good dashboard with a separate tab for incidents and alerts."
"The most valuable feature is the security that it provides."
 

Cons

"The solution needs to enhance its features to compete with other tools."
"For troubleshooting problems, it's not so intuitive. It's not straightforward. This is the core of their kernel, so they need to improve it a little bit... In F5 I have full control of everything."
"New versions are sometimes released before the bugs are worked out."
"The upgrade process is mildly complex requiring treatment of the custom embedded OS separately from the application. The correlation of the underling OS to the application version can be easily missed."
"An improvement would be to provide information on how pricing is done on different customer levels (e.g. is it done per gig or bandwidth?)."
"I think Arbor DDoS needs improvement in areas where competitors like S5, Redver, or NETSCOUT offer web application firewall functionality or dedicated web application firewall devices. Arbor lacks these features, which is a significant disadvantage. Yes, I would like to see these features introduced in Arbor as well. Regarding real-time detection capabilities, Arbor DDoS works very well. We and our customers are very satisfied with its performance. However, it would benefit from adding Web Application Firewall (WAF) capabilities to reach a larger customer base."
"We need a SaaS model for the solution."
"If we want to see live traffic, we can see do so. But once an attack that lasts for five minutes is done, the data is no longer there. It would be an improvement if we could see recent traffic in the dashboard. We can check and download live traffic, but a past attack, with all the details, such as why it happened and how to mitigate and prevent such future attacks, would be helpful to see."
"It is overly complicated. It has taken years to implement and the return on investment just isn't there."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"I believe they could improve their support, there are often delays."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"More customizability is required, which is something that they need to improve on."
"Cross Platform Integration could be improved."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
 

Pricing and Cost Advice

"The price of this solution is a little high in the African market, it should be lower."
"Arbor's products are very expensive. Their competitors are cheap when compared with Arbor."
"The pricing of the solution is cheap."
"Our customers always complain about the price of the product."
"Start with a small license. Measure your bandwidth requirements."
"The licensing of a complete Arbor solution, including fire-walling and unified site management, can get expensive."
"The solution's pricing is based on a licensing model that is expensive when compared to other tools."
"I believe that the price of Arbor DDoS falls under the bracket of medium to high price."
"The product price was reasonable for my region and the market."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"It is cheap."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"It’s cheaper to run virtual machines in a VMware environment."
"This is a pricey solution; it's not cheap."
"The licenses are good but the cost is very expensive."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Comms Service Provider
12%
Outsourcing Company
11%
Construction Company
6%
Construction Company
13%
Financial Services Firm
11%
Comms Service Provider
11%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss that prices are very high.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
RSA Security Analytics
 

Overview

 

Sample Customers

Xtel Communications
Los Angeles World Airports, Reply
Find out what your peers are saying about Radware, Cloudflare, NETSCOUT and others in Distributed Denial-of-Service (DDoS) Protection. Updated: September 2026.
913,806 professionals have used our research since 2012.