No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.7
Cisco Secure Network Analytics improves visibility and detection, aiding IT collaboration; value varies by environment and enhances security posture.
Sentiment score
7.0
Trellix NDR boosts ROI by improving security, reducing response times, and enabling efficient threat management and cost savings.
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
Security Engineer at Digitaltrack
 

Customer Service

Sentiment score
6.1
Cisco Secure Network Analytics receives praise for its knowledgeable international support, despite occasional challenges with local expertise.
Sentiment score
7.2
Trellix Network Detection and Response support is praised for knowledgeable service, though response times need improvement during severe incidents.
There is a lack of adequate local support from the Indian side.
Group Head at Stpi
For technical support of Cisco, the support they provide depends on how the client procures it, and so far, it's understandable.
CEO at BRIGHT-i SYSTEMS LIMITED
The support team was responsive and knowledgeable.
Business development executive at Digitaltrack solution Pvt Ltd
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Scalability Issues

Sentiment score
6.3
Cisco Secure Network Analytics scales well for enterprises, though high costs and outdated hardware can limit effectiveness.
Sentiment score
8.0
Trellix Network Detection and Response is scalable and reliable, efficiently handling complex configurations and high bandwidth in large networks.
The scope of the load balancing work was a team effort where we used three tools for load balancing.
Senior Developer at Atlas Laboratory
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Cyber Security Engineer at a retailer with 51-200 employees
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
Business development executive at Digitaltrack solution Pvt Ltd
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
8.3
Cisco Secure Network Analytics is praised for stability, minimal downtime, and reliability despite initial setup challenges and infrastructure complexity.
Sentiment score
8.0
Trellix Network Detection and Response is highly stable and reliable, with minimal downtime and consistently praised by users.
Cisco products are incredibly stable, boasting a 200% stability.
Group Head at Stpi
Once resolved, the system works well, and overall I think it's good.
CEO at BRIGHT-i SYSTEMS LIMITED
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
Business development executive at Digitaltrack solution Pvt Ltd
I encounter no issues with health or reliability when the recommended specifications are met.
CyberSecurity Architect at a comms service provider with 51-200 employees
 

Room For Improvement

Cisco Secure Network Analytics needs better integration, user interface, AI features, and simplified setup with improved training and database management.
Trellix needs improved customization, integration, and usability in its detection, reporting, and policy management for enhanced user experience.
The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers.
Group Head at Stpi
Proper management of the database is also important; it should be centralized for easier data collection from a single database.
CEO at BRIGHT-i SYSTEMS LIMITED
Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries.
Cyber Security Trainee at DataSpace Academy
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Network & Security Lead at Net-International
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Presales Manager
 

Setup Cost

Cisco Secure Network Analytics is costly with complex licensing, though valued for features; pricing strategy adjustments are suggested.
Trellix's pricing is considered competitive but expensive, with straightforward licensing and efficient setup, potentially deterring smaller businesses.
Cisco solutions are considered to be very expensive.
Group Head at Stpi
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions.
CEO at BRIGHT-i SYSTEMS LIMITED
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
Business development executive at Digitaltrack solution Pvt Ltd
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
CyberSecurity Architect at a comms service provider with 51-200 employees
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
Network & Security Lead at Net-International
 

Valuable Features

Cisco Secure Network Analytics offers comprehensive visibility and enhanced threat detection, improving security and reducing investigation times effectively.
Trellix Network Detection and Response enhances security with real-time detection, automation, and integration, reducing manual monitoring by 50%.
The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level.
Group Head at Stpi
Every solution is gradually integrated with AI, and Cisco has already implemented AI building features in their solution.
CEO at BRIGHT-i SYSTEMS LIMITED
The best feature of Cisco Secure Network Analytics is its reliability, which I find to be the one that gets used the most.
Senior Developer at Atlas Laboratory
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Network & Security Lead at Net-International
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
Presales Manager
 

Categories and Ranking

Cisco Secure Network Analytics
Ranking in Network Detection and Response (NDR)
5th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
63
Ranking in other categories
Network Monitoring Software (33rd), Network Traffic Analysis (NTA) (3rd), Cisco Security Portfolio (7th)
Trellix Network Detection a...
Ranking in Network Detection and Response (NDR)
7th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
54
Ranking in other categories
Advanced Threat Protection (ATP) (10th)
 

Mindshare comparison

As of June 2026, in the Network Detection and Response (NDR) category, the mindshare of Cisco Secure Network Analytics is 5.8%, down from 7.2% compared to the previous year. The mindshare of Trellix Network Detection and Response is 3.0%, up from 2.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics5.8%
Trellix Network Detection and Response3.0%
Other91.2%
Network Detection and Response (NDR)
 

Featured Reviews

Akash Das Barman - PeerSpot reviewer
Cyber Security Trainee at DataSpace Academy
Network analytics has reduced investigation time and provides deeper visibility into lateral movement
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries. In practice, many teams do not rely on it heavily because SIEM tools or GRC platforms already handle reporting better. Built-in threat intelligence feeds represent another area where expectations do not always match usage. The platform includes threat intelligence-based detection and classifications. Initially, teams expect to depend on this heavily, but later SOC teams often prefer their own threat intelligence feeds or correlate intelligence inside SIEM instead. The built-in feeds are used but not as a primary detection source. Automated incident summaries and guided investigation views are designed to simplify triage by automatically grouping related activity into incidents. However, teams often move away from them due to various factors affecting adoption.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Continuous network insight has improved early threat detection and streamlined investigations
Overall, we have a positive experience with Trellix Network Detection and Response, but like any enterprise security solution, there are areas where it can continue to improve. One area would be user interface and dashboard customization. While the platform provides a lot of valuable information, new users can sometimes face a learning curve when navigating and investigating and creating customized views. More intuitive dashboards would simplify workflows and help analysts access critical information even faster. Another area for improvement is reporting and analytics. The existing reporting capabilities are useful, but more flexibility and customizable reporting options would make it easier to generate executive-level summaries, compliance reports, and operational metrics for different audiences.
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Government
8%
Construction Company
8%
Manufacturing Company
16%
Financial Services Firm
13%
Comms Service Provider
9%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business35
Midsize Enterprise11
Large Enterprise23
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is positive, as the setup process was straightforward, licensing was flexible, and the value deliver...
What needs improvement with FireEye Network Security?
Based on my experience with the solution, I do not see any improvements needed for Trellix Network Detection and Response at present; it might be required in the future, but there is no space to im...
What is your primary use case for FireEye Network Security?
Our main use case for Trellix Network Detection and Response is to maintain oversight of our network traffic and catch any threats or unusual activity as early as possible. Trellix Network Detectio...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Cisco Secure Network Analytics vs. Trellix Network Detection and Response and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.