No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs Plixer Scrutinizer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Ranking in Network Monitoring Software
33rd
Ranking in Network Traffic Analysis (NTA)
3rd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
63
Ranking in other categories
Network Detection and Response (NDR) (5th), Cisco Security Portfolio (7th)
Plixer Scrutinizer
Ranking in Network Monitoring Software
74th
Ranking in Network Traffic Analysis (NTA)
12th
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Network Traffic Analysis (NTA) category, the mindshare of Cisco Secure Network Analytics is 9.0%, down from 14.2% compared to the previous year. The mindshare of Plixer Scrutinizer is 3.8%, up from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Traffic Analysis (NTA) Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics9.0%
Plixer Scrutinizer3.8%
Other87.2%
Network Traffic Analysis (NTA)
 

Featured Reviews

Akash Das Barman - PeerSpot reviewer
Cyber Security Trainee at DataSpace Academy
Network analytics has reduced investigation time and provides deeper visibility into lateral movement
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries. In practice, many teams do not rely on it heavily because SIEM tools or GRC platforms already handle reporting better. Built-in threat intelligence feeds represent another area where expectations do not always match usage. The platform includes threat intelligence-based detection and classifications. Initially, teams expect to depend on this heavily, but later SOC teams often prefer their own threat intelligence feeds or correlate intelligence inside SIEM instead. The built-in feeds are used but not as a primary detection source. Automated incident summaries and guided investigation views are designed to simplify triage by automatically grouping related activity into incidents. However, teams often move away from them due to various factors affecting adoption.
Ira Mulyanti - PeerSpot reviewer
Sales Director at ARGA SOLUSI
An affordable product with great integration capabilities
Plixer Core Platform is a valuable feature and a good software. Plixer Scrutinizer uses NetFlow analysis to monitor whatever is there in a network. Price-wise, Plixer Scrutinizer is not an expensive product. Basically, Plixer Scrutinizer is an affordable product. Plixer Scrutinizer is a tool that allows for customization, especially in scenarios where customers need new product features. Plixer Scrutinizer is a tool that can integrate with any other brand or product in the market, so it is not an area of concern.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Another notable feature of Cisco Secure Network Analytics is its Layer 7 visibility, which allows us to monitor and analyze network communications at the application layer."
"Great network monitoring, looking at anomaly detection and evaluation."
"Cisco Stealthwatch has reduced the amount of time to detect an immediate threat."
"Visibility. The ability to look East and West. To see what is passing through your circuits, where it is coming from, and how big it is."
"It has improved our internal knowledge of what's going on with the network, and that's helpful."
"It has definitely helped us improve our mean time to resolution on network issues."
"The fact that it can identify down to an IP address of a system that is causing problems, or potentially causing problems, is very valuable."
"Provides easily identifiable anomalies that you can't see with signature detections."
"We didn't experience any bugs."
"It shows us the saturation of the network of devices. It gives us a clear view of the flows in the network to understand, for instance, planning upgrades in the network to get an idea of what's going on the network on traffic flows. It gives us insight, for instance, on what's going on on our VPN Client. There are a lot of things where it provides very helpful information. It also gives us our security reports with quite detailed information on what's going on in the network, and whether there are data exfiltrations and so on."
"The reporting and generating troubleshooting reports would be the best feature; our host-to-host conversation reporting."
"There are other tools out there that will do what Scrutinizer does. But what I have found with Scrutinizer is that it does it very quickly. I've taken 25 million individual data fragments from the different sensors, and it has graphed that and mapped it and presented a picture within 30 seconds. It has a very efficient database algorithm that I am really impressed with."
"As a network engineer, the ability to identify what traffic on the link is consuming all the bandwidth at any given time, and provide immediate feedback to the business, is the most valuable feature."
"Plixer Scrutinizer is an affordable product. Plixer Scrutinizer is a tool that allows for customization, especially in scenarios where customers need new product features."
"I honestly don't think there are many areas where Scrutinizer could be improved; it's a pretty robust, out-of-the-box solution."
"The most valuable features of the solution are the ability to track what a device is doing and to go back historically. It is also able to go down to, and identify, very low levels of traffic."
 

Cons

"Its granularity for RBAC roles-based access control needs improvement."
"Cisco Stealthwatch has increased the administrative time required just to get everything up and running smoothly."
"It hasn't really improved our direct detection rate but it has definitely reduced our incident response time as we wouldn't have been able to detect threats or immediate risks without this solution."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"Some of our customers find this solution to be a little bit tough because they don't understand how to configure and use it."
"I don't really think we really save time while using this solution."
"We need to be able to filter out internal IPs as non-threats."
"The ability to be natively integrated into Port Aggregator would be beneficial because it would reduce just one more component that's needed in order to have that type of view."
"From what I understand it is that the solution is not very scalable in a high volume traffic environment with a large number of flows."
"We couldn't get it set up properly."
"Data retention needs improvement. Data retention is a thing where we are looking for a better way to collect flow data for a longer time to do forensic research on security incidents. By default, data retention is quite low. We need detailed data in safe storage for a longer time, e.g., for a couple of months. An improvement would be a way to export data into a secure long-term storage."
"We were trying to set up some configuration, but it just wasn't quite working properly; we couldn't get it set up properly."
"It would be useful if there was a way to back up the configuration information. E.g., if you wanted to deploy a new instance or disaster recovery, you could quite easily deploy and restore the config, as opposed to having to restore all the NetFlow data. If there was just a button that said "backup config information", that would be good."
"They're working on the security areas, so it can provide more insight. What they have is still pretty much IP-concentric. If they were to make it IP and URL, they'd be a little bit ahead on that."
"The solution creates a visual map of a particular location and how the network flows. You need to spend time to generate all those maps. If they could figure out a way to reduce the time needed to generate the maps, that would be great."
"Knowing that they're coming out with a new user interface, that is an area where there is room for improvement. There are so many variables. They should limit the variables in the user interface and create some classes, like "simple," "novice," and "expert" to narrow down the variables within it."
 

Pricing and Cost Advice

"Licensing is on a yearly basis."
"The pricing for this solution is good."
"Licensing is done by flows per second, not including outside>in traffic."
"​Licensing is done by flows per second, not including outside (in traffic)."
"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"The licensing costs are outrageous."
"NetFlow is very expensive."
"It's about €10,000 a year for initial license and yearly maintenance costs. In addition, the hardware costs are about €10,000 once every five years."
"We recently bought a license upgrade, so we will integrate more exporters. We upgraded from a 25 exporter license to a 50 exporter license. Therefore, there will be more flows, and this will be an extension. I don't know when we will purchase a faster server, because the server that we have is quite new."
"We just renewed. The pricing is 5,000 euro per year. This is the final price. All tax (20 percent) is included."
"There are no extra costs. It's about $8,000 a year. The bang for the buck (cost) is definitely a plus."
"We pay our one-off cost for the licenses, per device, in blocks of 50. And then we pay an annual maintenance fee of about $15,000 Australian, which is, at this point in time, about $9,000 US, for those 250 devices. The upfront costs for the 250-license use, were about $50,000 Australian, which is about $32,000 US."
"The license is per device. We have 50 devices."
"The licensing cost for Plixer Scrutinizer is in the middle. It's not the cheapest, but it's not the most expensive. Its licensing model is based on how many exporters, how many devices export information to the system. Plixer Scrutinizer has different modules you could add such as the security module which would cost extra."
"There is a recurring maintenance fee after the initial purchase or if we want the license upgrade."
report
Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Government
8%
Construction Company
8%
Financial Services Firm
11%
Manufacturing Company
9%
Construction Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise8
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
Ask a question
Earn 20 points
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Oxford Networks, Squaw Valley Ski Holdings, UltiSat, Wipro, West Aurora School District 129, SUNY Geneseo College, Bloomington Public Schools, First National Bank of Pennsylvania, Kitsap Credit Union, Metropolitan Transit Authority of Harris County Houston Texas, Carilion Clinic, Banner Health, IDEXX Laboratories, Phibro Animal Health Corporation, Goodwill Industries, Parmalat, Armstrong Coal Company, Flybe, James Walker
Find out what your peers are saying about Cisco Secure Network Analytics vs. Plixer Scrutinizer and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.