No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs Symantec Advanced Threat Protection comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
63
Ranking in other categories
Network Monitoring Software (33rd), Network Traffic Analysis (NTA) (3rd), Network Detection and Response (NDR) (5th), Cisco Security Portfolio (7th)
Symantec Advanced Threat Pr...
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (22nd)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Cisco Secure Network Analytics is designed for Network Monitoring Software and holds a mindshare of 0.9%, down 1.2% compared to last year.
Symantec Advanced Threat Protection, on the other hand, focuses on Advanced Threat Protection (ATP), holds 2.1% mindshare, up 1.6% since last year.
Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics0.9%
Zabbix3.9%
SolarWinds NPM3.6%
Other91.6%
Network Monitoring Software
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Symantec Advanced Threat Protection2.1%
Palo Alto Networks WildFire7.3%
Microsoft Defender for Office 3656.5%
Other84.1%
Advanced Threat Protection (ATP)
 

Featured Reviews

Akash Das Barman - PeerSpot reviewer
Cyber Security Trainee at DataSpace Academy
Network analytics has reduced investigation time and provides deeper visibility into lateral movement
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries. In practice, many teams do not rely on it heavily because SIEM tools or GRC platforms already handle reporting better. Built-in threat intelligence feeds represent another area where expectations do not always match usage. The platform includes threat intelligence-based detection and classifications. Initially, teams expect to depend on this heavily, but later SOC teams often prefer their own threat intelligence feeds or correlate intelligence inside SIEM instead. The built-in feeds are used but not as a primary detection source. Automated incident summaries and guided investigation views are designed to simplify triage by automatically grouping related activity into incidents. However, teams often move away from them due to various factors affecting adoption.
TapabrataSamanta - PeerSpot reviewer
Lead Architect at Zones
Reliable platform with effective integration capabilities
Our primary use case for the product is to provide advanced threat protection to our clients, primarily in the banking and financial sectors Symantec ATP has been beneficial in ensuring robust security for our clients. Its effectiveness in detecting and mitigating threats has improved customer…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has improved our internal knowledge of what's going on with the network, and that's helpful."
"Provides easily identifiable anomalies that you can't see with signature detections."
"Being able to look at the Layer 7 application and get information about intrusion attempts is the most valuable feature for us."
"Time to value is very good for Stealthwatch."
"It has been pretty stable since we deployed it, and everything seems to be working fine."
"Great network monitoring, looking at anomaly detection and evaluation."
"This solution has improved my organization because when I have users who are having issues with patching slowness it gives me the ability to be able to proactively troubleshoot and determine what the issue is."
"The most valuable feature of the solution is that it helps you gain visibility for your application."
"Endpoint to network is a good feature, it can protect the line."
"Overall, the product supports everything already feature-wise, because it has email protection, monitoring detection, network intrusion detection, and advanced threat protection."
"The technical support services are excellent."
"The most valuable feature is NetFlow threat protection."
"Technical support has been helpful and responsive."
"This is a good solution, and whatever our requirement is, all of the features are there."
"Symantec Endpoint Protection provides end-to-end protection. Along with antivirus protection, it has a lot of key areas, including intrusive prevention, firewall features, and application and device control."
"The great advantage in using this product is it creates multiple services."
 

Cons

"One of the things which bugs me about Lancope is the licensing."
"The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers."
"This is an expensive solution and the license is expensive."
"One area that could be improved in SNA is the integration with Cisco ISE for user and session details, which currently requires additional setup."
"There could be better integration on the programming side, which uses Python."
"Complexity on integration is not so straightforward and you really need an expert to help build it out."
"We had some trouble with the installation as we migrated from our previous solution."
"We've run into some issues with the configuration."
"It also needs network-based threat protection for shared folders and files."
"The security features need to be improved."
"It's a strange situation where the infrastructure of the consumer or customer is behind some kind of firewall and they have always used some kind of customized proxy. In this situation, the ATP has a very tough time to pass the information to the cloud and back. To fix, it requires a more elaborate and complex configuration for that particular case."
"There are limits with respect to blocking files by hash value or blocking IP addresses, and these limits should be removed."
"The cloud platform needs to have improvement in terms of the user interface and the different capabilities it has available. It needs to match the other leading next-gen EDR products that are available in the market. That's the reason why we are stepping away from Symantec. Their cloud environment is just generally lacking in comparison to others."
"Symantec appliances need improvement. The whole appliance environment is a robust system and it needs a massive amount of storage space. If you have to increase or speed up the background storage it's a pretty complicated process. The scalability and sizing is critical, and if you do it wrong you run into issues pretty quickly."
"The endpoint protection looks old."
"The support has dropped down to a five out of ten."
 

Pricing and Cost Advice

"Licensing is done by flows per second, not including outside>in traffic."
"There are additional licenses needed for the number of so-called network flows. It's hard to plan the number of flows you need in the network, this is a problem. The price of the Cisco Stealthwatch is relatively inexpensive"
"The pricing for this solution is good."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"Pricing is much higher compared to other solutions."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"We pay for support costs on a yearly basis."
"The yearly licensing cost is about $50,000."
"The price is quite expensive."
"Symantec Advanced Threat Protection's pricing is comparable."
"Pricing is good. It is nice to have a great product at a fair price."
"The pricing of this solution is inexpensive and affordable."
"Symantec Endpoint Protection has an average price."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Government
8%
Construction Company
8%
Manufacturing Company
12%
Financial Services Firm
12%
Marketing Services Firm
10%
University
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise13
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
What is your experience regarding pricing and costs for Symantec Advanced Threat Protection?
The price is quite expensive because a different entity has taken over the company.
What needs improvement with Symantec Advanced Threat Protection?
One area for improvement could be the pricing model. Future releases could further enhance integration capabilities with other platforms and simplify the licensing model to compete more with Micros...
What is your primary use case for Symantec Advanced Threat Protection?
Our primary use case for the product is to provide advanced threat protection to our clients, primarily in the banking and financial sectors.
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
ECI
Find out what your peers are saying about Zabbix, SolarWinds, Auvik and others in Network Monitoring Software. Updated: May 2026.
900,747 professionals have used our research since 2012.