No more typing reviews! Try our Samantha, our new voice AI agent.

Arbor DDoS vs NetWitness Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
79
Ranking in other categories
CDN (1st), WAN Optimization (4th), Web Application Firewall (WAF) (9th), Distributed Denial-of-Service (DDoS) Protection (2nd), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (14th)
Arbor DDoS
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (3rd)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (37th), Security Information and Event Management (SIEM) (36th)
 

Mindshare comparison

Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Arbor DDoS6.1%
Cloudflare12.4%
Imperva Application Security Platform8.0%
Other73.5%
Distributed Denial-of-Service (DDoS) Protection
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.1%
Splunk Enterprise Security7.0%
IBM Security QRadar4.5%
Other87.4%
Log Management
 

Featured Reviews

M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution has improved the security of our organization."
"Stability is great; I love their mechanisms, I love their GUI, I love their front end, I love their behind the scenes, algorithms and everything, it all makes sense."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"Cloudflare's DNS services deliver the best performance in terms of speed and reliability."
"I didn’t have to pay anything for better website security and reduced server load."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"The solution is stable, and the DNS servers are simple to use."
"Arbor DDoS is easy to use, provides effective blocking of DDoS attacks, and can be used for DNS, web, and main servers. Additionally, this solution is far easier to operate than others solutions, such as Fortinet DDoS."
"The solution looks into volumetric attacks and gets them resolved."
"The Arbor Networks SP device provided great visualization of the network traffic."
"The feature I find most valuable is the packet capture, which beautifully shows the communication between the client and the server, identifying potential malicious activity."
"We use it not only for DDoS detection and protection, but we also use it for traffic analysis and capacity planning as well. We've also been able to extend the use of it to other security measures within our company, the front-line defense, not only for DDoS, but for any kind of scanning malware that may be picked up. It's also used for outbound attacks, which has helped us mitigate those and lower our bandwidth costs..."
"The solution is easy to use."
"Its scalability is big. It is for large deployments of big organizations and service providers."
"I have a lot of experience with the technical support for multiple vendors (HPE, Cisco, Palo Alto Networks, Imperva, etc.) and the Arbor support is really good; usually, they respond with the workaround for your issue."
"The most valuable features are the integration and ease of use."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"Overall, this is a good solution with suitable features and it very well fits our needs."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"The most valuable features are its ingestion of logs and raising of alerts based on those logs."
"Technically speaking, this is a good product."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
 

Cons

"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"With CDN loads, sometimes we get an error that the host server is unavailable when the connection between CloudFlare and the server timed out."
"Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"The reporting can definitely be improved to offer a lot more explanation on something that may have happened or has actually happened."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Yes, there were a few times when some of their CDN nodes would fail, creating serious speed issues with the site without any warning or notification from their side."
"There is always room for improvement for any product or service. If we can bring in more agility when deploying services, that is definitely a scope which we can work towards. Nowadays, everything is being offered as a service model. It is not that we have to deploy the physical hardware, many things move up to the cloud, or even can be delivered in the VNS form in the customer's environment as well. So, in that space, if we can add more features to make it more seamless for customers to use and make it available through some marketplace, not only at the hyperscalers, but also for any on-prem deployment, that definitely would be a big plus."
"New versions are sometimes released before the bugs are worked out."
"The solution's IT support needs improvement."
"They also have limited sizes of the boxes. Different sizes are needed because some customers are very small while others are very big, such as ISPs, so this categorization should be available."
"The prices for Arbor DDoS are expensive. The licensing is subscription-based."
"There should be an automatic way to configure it to monitor traffic and decide which is an attack and which is not. In Arbor, you need to tweak and set all parameters manually, whereas in Check Point DDoS Protector, you can select the lowest parameters, and over the weeks, Check Point DDoS Protector will learn the traffic and you can then tighten some of the parameters to decide which traffic is regular and which is malicious."
"The support got worse after NETSCOUT acquired Arbor."
"On the application layer, they could have a better distributed traffic flow. They could improve that a bit. For network data it is very effective, but the application layer can be improved."
"I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need."
"The tool's integration capability isn't so great."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"The user interface is a little bit difficult for new users and it needs to be improved."
"The initial setup is complex. It requires some knowledge in order to set it up."
"Security needs improvement. We would still like to know how the traffic is entering the organization."
"It is overly complicated. It has taken years to implement and the return on investment just isn't there."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
 

Pricing and Cost Advice

"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"We are using the free tier of the solution."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"That is one of the great features. I was able to access the majority of the features and services for free."
"There are no additional costs beyond the standard licensing fees."
"A free version of the solution is available."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"The pricing of the solution is cheap."
"The price of Arbor DDoS depends on many parameters. It depends on the physical capacity of the environment, and it is not a straight-line price. It's fairly competitive in the market on the price."
"The solution is a bit costly if you're a small organization, but I think it's worth the price that they are charging."
"I'm a technical guy. But I know it's expensive compared to its competitors. After you have the on-premise solution, for your solution to be effective you have to subscribe to an "upper level," so there's another cost. There is also a subscription to cloud services, which is another cost."
"Arbor's products are very expensive. Their competitors are cheap when compared with Arbor."
"There is room for improvement with the pricing. It is an expensive solution. The issue with the pricing is more the way it is built. Right now we're paying per router, and there's a limitation there. I would like to see bundle-pricing where there is an overall solution cost."
"Arbor DDoS is quite expensive, but all these solutions are expensive because they deal with confidential information."
"Regarding pricing, I would rate it as average. Arbor DDoS offers good value for money with our DDoS filter device. For higher protection needs, Arbor’s CloudMeter’s DDoS mitigation or hardware devices might be more expensive, but customers who need them are usually prepared for the cost and the additional resources required."
"Our license is for one year."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The product price was reasonable for my region and the market."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Computer Software Company
8%
Financial Services Firm
15%
Comms Service Provider
14%
Outsourcing Company
7%
Computer Software Company
7%
Construction Company
13%
Financial Services Firm
11%
Comms Service Provider
9%
Outsourcing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise11
Large Enterprise26
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What is your experience regarding pricing and costs for Cloudflare DNS?
The pricing, setup cost, and licensing for Cloudflare are a bit on the higher side overall.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other soluti...
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with ...
 

Also Known As

Cloudflare DNS
Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
RSA Security Analytics
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Xtel Communications
Los Angeles World Airports, Reply
Find out what your peers are saying about Radware, Cloudflare, NETSCOUT and others in Distributed Denial-of-Service (DDoS) Protection. Updated: August 2026.
908,834 professionals have used our research since 2012.