

Cisco Secure Network Analytics and Corelight Open NDR compete in the network security analytics category. Cisco Secure Network Analytics seems to have the upper hand due to its comprehensive integration capabilities and expansive feature set, bolstered by user feedback on robust analytics and threat protection.
Features: Cisco Secure Network Analytics provides extensive network maps, server and network response time monitoring, and excellent visibility via NetFlow data. The integration within Cisco's ecosystem offers unparalleled network visibility. Corelight Open NDR excels in threat detection using Suricata and integrates seamlessly with open-source tools like Zeek, offering detailed insights crucial for cybersecurity.
Room for Improvement: Cisco Secure Network Analytics could enhance its user interface and streamline reporting. Users desire better filtration and fewer false positives. Corelight Open NDR requires a more interactive interface, improved service catalogs, and a simpler architecture. There's also a need for advanced features and improved AI capabilities.
Ease of Deployment and Customer Service: Both solutions offer on-premises deployment; however, Corelight additionally provides hybrid cloud deployment. Cisco's technical support is generally well-regarded, yet some users cite inconsistencies in expertise. Corelight users report satisfaction with knowledgeable support addressing their concerns effectively.
Pricing and ROI: Cisco Secure Network Analytics is perceived as expensive with flow-based licensing contributing to costs, but users find it justifiable due to enhanced network visibility and reduced threat response times. Corelight Open NDR is more affordable due to its open-source nature, yet it's seen as costly compared to similar products. It offers solid ROI, particularly in initial cybersecurity investments, through efficient threat detection.
| Product | Mindshare (%) |
|---|---|
| Corelight Open NDR | 4.9% |
| Cisco Secure Network Analytics | 6.0% |
| Other | 89.1% |

| Company Size | Count |
|---|---|
| Small Business | 11 |
| Midsize Enterprise | 7 |
| Large Enterprise | 52 |
| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 2 |
| Large Enterprise | 1 |
Cisco Secure Network Analytics enhances network security through integrated threat detection and detailed traffic visibility, optimizing performance with AI analytics and strong platform integrations.
Cisco Secure Network Analytics offers deep visibility into network traffic, with tools like network maps and server response times. Its AI-driven analytics help detect threats, focusing on east-west traffic. Integration with platforms such as pxGrid and ISE complements its capabilities. Reporting and telemetry help in identifying bandwidth issues, yet improvements are desired in AI for better data organization. Installation complexity and false positives present challenges, and managing network loads effectively is a recognized need.
What are the key features of Cisco Secure Network Analytics?Industries such as banking, defense, and police rely on Cisco Secure Network Analytics for securing networks against threats. Its capability to provide insights into encrypted traffic and facilitate device auditing makes it a sought-after choice for those requiring extensive network visibility. Users appreciate its application for threat prevention and response in demanding sectors.
Corelight Open NDR delivers rapid deployment, essential insight, and data for cybersecurity. Known for ease of use, cost-effectiveness, and open-source Zeek code, it enhances security by streamlining traffic monitoring and integrating with threat feeds.
Corelight Open NDR offers organizations enhanced network security and visibility, utilizing physical sensors in addition to cloud, virtual, and software variants. It supports incident response with packet capture sampling, monitoring internet, data center, and LAN traffic while facilitating east-west traffic identification. Despite its complexity, users suggest architectural simplifications and a graphical interface to boost usability and reduce costs. Features like Smart PCAP and service catalogs contribute positively, but an interactive interface with more seamless feature access is desired.
What Are Corelight Open NDR's Key Features?Primarily utilized by organizations to bolster network security, Corelight Open NDR is deployed in various sectors to increase visibility and streamline incident response. Its deployment spans physical, cloud, virtual, and software models, focusing on comprehensive packet capture sampling for effective traffic monitoring. Across industries, it serves managed services by identifying lateral network traffic, optimizing internet, data center, and LAN performance.
We monitor all Network Detection and Response (NDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.