

Trellix Network Detection and Response and Cisco Secure Network Analytics are competing in the network security solutions category. Each product has distinct strengths; Trellix offers cutting-edge threat detection capabilities, while Cisco stands out for exceptional network visibility and traffic analytics.
Features: Trellix Network Detection and Response excels at detecting zero-day attacks with a robust malware analysis tool and real-time response capability with an integrated network view. Cisco Secure Network Analytics provides unmatched network visibility with layer-wise insights and strong traffic analytics, enhanced by integration with Cisco's security suite for comprehensive network analysis.
Room for Improvement: Trellix Network Detection and Response could improve user-friendliness, reduce false positives, and enhance cloud and machine learning integrations. Cisco Secure Network Analytics needs more advanced reporting, better integration with other Cisco products, and simplified user configuration processes. Both could enhance their machine learning and analytics capabilities.
Ease of Deployment and Customer Service: Trellix Network Detection and Response offers flexible deployment options like on-premises and hybrid cloud solutions with highly rated customer support globally. Cisco Secure Network Analytics focuses on on-premises deployment, providing reliable customer and technical support, yet needing improvement in integration with select products.
Pricing and ROI: Trellix Network Detection and Response is considered expensive with a restrictive pricing model, yet provides good ROI by preventing breaches and reducing response time. Cisco Secure Network Analytics is also costly, with a complex licensing structure based on network flows, but offers strong ROI by preventing network threats and enhancing productivity.
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
The time was reduced because of the automated detections.
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
There is a lack of adequate local support from the Indian side.
For technical support of Cisco, the support they provide depends on how the client procures it, and so far, it's understandable.
The support team was responsive and knowledgeable.
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
The scope of the load balancing work was a team effort where we used three tools for load balancing.
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Cisco products are incredibly stable, boasting a 200% stability.
Once resolved, the system works well, and overall I think it's good.
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
I encounter no issues with health or reliability when the recommended specifications are met.
The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers.
Proper management of the database is also important; it should be centralized for easier data collection from a single database.
Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Cisco solutions are considered to be very expensive.
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions.
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level.
Every solution is gradually integrated with AI, and Cisco has already implemented AI building features in their solution.
The best feature of Cisco Secure Network Analytics is its reliability, which I find to be the one that gets used the most.
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
| Product | Mindshare (%) |
|---|---|
| Cisco Secure Network Analytics | 5.8% |
| Trellix Network Detection and Response | 3.0% |
| Other | 91.2% |


| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 7 |
| Large Enterprise | 52 |
| Company Size | Count |
|---|---|
| Small Business | 35 |
| Midsize Enterprise | 11 |
| Large Enterprise | 23 |
Cisco Secure Network Analytics enhances network security through integrated threat detection and detailed traffic visibility, optimizing performance with AI analytics and strong platform integrations.
Cisco Secure Network Analytics offers deep visibility into network traffic, with tools like network maps and server response times. Its AI-driven analytics help detect threats, focusing on east-west traffic. Integration with platforms such as pxGrid and ISE complements its capabilities. Reporting and telemetry help in identifying bandwidth issues, yet improvements are desired in AI for better data organization. Installation complexity and false positives present challenges, and managing network loads effectively is a recognized need.
What are the key features of Cisco Secure Network Analytics?Industries such as banking, defense, and police rely on Cisco Secure Network Analytics for securing networks against threats. Its capability to provide insights into encrypted traffic and facilitate device auditing makes it a sought-after choice for those requiring extensive network visibility. Users appreciate its application for threat prevention and response in demanding sectors.
Trellix Network Detection and Response provides robust threat protection with advanced detection of zero-day attacks and APTs. Its user-friendly dashboard and real-time response capabilities enhance security and visibility across networks.
Trellix Network Detection and Response stands out with its MVX engine, leveraging virtual machines for comprehensive behavioral analysis. The solution supports detection of advanced cyber threats through features like sandboxing and application filtering, offering real-time response and packet capture for detailed contextual insights. Companies benefit from seamless integration with other platforms, enhancing usability and overall protection. User-friendly interfaces improve network visibility, while stability and ease of configuration safeguard against both signature-based and signature-less threats.
What key features does Trellix offer?Companies in sectors like finance, healthcare, and enterprise security utilize Trellix Network Detection and Response for tasks such as network intrusion detection, endpoint protection, and securing data transmission paths. It aids in threat investigations, pre-sales demos, and network forensics, reducing risks by protecting against cyber threats like phishing.
We monitor all Network Detection and Response (NDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.