Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs NetMon comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon
Ranking in Identity Threat Detection and Response (ITDR)
1st
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
138
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Endpoint Protection Platform (EPP) (1st), Threat Intelligence Platforms (TIP) (1st), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), Attack Surface Management (ASM) (1st), AI-Powered Cybersecurity Platforms (1st)
NetMon
Ranking in Identity Threat Detection and Response (ITDR)
14th
Average Rating
7.6
Reviews Sentiment
6.1
Number of Reviews
12
Ranking in other categories
Network Monitoring Software (51st)
 

Mindshare comparison

As of March 2026, in the Identity Threat Detection and Response (ITDR) category, the mindshare of CrowdStrike Falcon is 14.0%, down from 15.4% compared to the previous year. The mindshare of NetMon is 1.4%. It is calculated based on PeerSpot user engagement data.
Identity Threat Detection and Response (ITDR) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon14.0%
NetMon1.4%
Other84.6%
Identity Threat Detection and Response (ITDR)
 

Featured Reviews

Waleed Omar - PeerSpot reviewer
Information Security Specialist at Arab Open University
Provides effective real-time threat detection with potential for cost optimization
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
SR
Pan India IT Infrastructure Management / End-user Services at Tata Group
Has supported real-time event detection and reporting accuracy while database integration has required extra effort
Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time. However, currently, it is not giving many challenges.It is difficult to integrate NetMon with other databases. We can customize NetMon's monitoring views, but it is done by the team who handles it, as it is outsourced.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Enables us to understand what processes are running on the system, what registry keys have been enabled."
"CrowdStrike Falcon is a very light solution. It does not use too much processor or RAM."
"The biggest advantage of this solution for my customers is that it is a single solution that fulfills most of their security concerns while being easy to manage."
"There's almost no maintenance required. It's very low if there's any at all."
"Overall, what I found most valuable in CrowdStrike Falcon is its good mechanism. It also has a good reporting feature. CrowdStrike Falcon is an invaluable tool because, through it, you can take quick action, for example, when an OS is missing specific patches."
"One of the most valuable features of CrowdStrike Falcon is when there are upgrades there are no additional fees."
"Because it is security product and acts like an AIML smart product, not merely based on daily/weekly updates and signatures."
"I like the Overwatch feature the most."
"It has a very strong artificial intelligence engine."
"NetMon's best feature is traffic analysis."
"LogRhythm NetMon's most impressive feature is that it's a bundled package, so you're not just relying on monthly data; you get a six-month view for more comprehensive indicators of compromise. This dual approach is precious. We implement LogRhythm NetMon in our cybersecurity strategy mainly for compliance and correlation of network, user, and decision activities, particularly for network firewalls and access control."
"Visibility is a valuable feature, the ability to see even if the traffic is not going into the firewall"
"The most valuable feature is the log, which can be analyzed by our SIEM solution."
"The protocols with which you see the traffic for a particular website that a client has in their environment, for example, are valuable. We can monitor whether the traffic is up to the mark or whether they need to add more bandwidth. Also, we can see if we're able to get real-time environment data as well. The customization dashboard is really good. LogRhythm NetMon has its own in-built dashboards which are helpful in guiding customization."
"The initial setup is straightforward because we can deploy an open server."
"It is a stable solution...It is a scalable solution."
 

Cons

"The management of the solution could improve."
"If CrowdStrike can further expand its support for XDR compatibility, that would give it an edge over all the other competing new products."
"The detection time has room for improvement."
"We encounter occasional issues, such as when disabling network access for a host that uses CrowdStrike."
"The biggest issue with Falcon as a standalone product is it doesn't have very much reporting."
"Unfortunately, native applications are not supported."
"Basically, they don't cover legacy OS or applications. That's the only issue we're concerned about"
"I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does."
"LogRhythm NetMon's pricing model is an area of concern that should be made a little bit cheaper in comparison to the other players in the market currently."
"The training for this product is not very good and needs to be improved."
"The platform's integration features often need to be improved."
"Sometimes it's hard to find the network devices' self-audit logs."
"I would like to see better integration with multiple products. Integration is not something that is readily available for most of the products."
"Some of the automated tasks we can perform on QRadar cannot be performed on LogRhythm because the solution has limitations."
"There is an issue with tunneling in relation to how the connectivity is established between the end devices and where NetMon is installed. On the console, I often observe that there's a difference of a few seconds or maybe a minute, and this lag time should not be there."
"The main concern is that LogRhythm has not improved NetMon but instead introduced a separate product, which many customers, including us, would prefer to be integrated into a single platform for easier management."
 

Pricing and Cost Advice

"The tool is a little bit expensive compared to other products, but I think it's okay owing to its quality."
"The solution's pricing is great for us."
"I would like them to further reduce the price, because it is quite pricey at the moment."
"We pay between $30-50 per user for a yearly license, which is more expensive than SentinelOne or Bitdefender. However, CrowdStrike gives better value for money."
"Years ago, when we bought CrowdStrike, you got everything it had. I was a little concerned when they broke this out into a la carte modules where you can buy EDR, Spotlight, etc., picking and choosing off the menu. I was a little worried that the solution would get watered down. However, I realized in my previous organization when we had the full suite that there were a bunch of features in it that we didn't have time to operationalize. So, I warmed up to it. I get the whole, "Look, you can pick and choose. Okay, everybody buys a steak, but do you want mashed potatoes, or do you want lobster mac and cheese?" So, you can pick the sides that you want, so you can buy the solution that you want and operationalize versus paying a lot of money and getting a bunch of things, but not using 60 percent of the tools in the box."
"The price of CrowdStrike Falcon is expensive."
"The pricing on CrowdStrike is per license. It was about $42 per seat yearly."
"There are approximately a hundred different modules you have to purchase, depending on what you want to do. I have most of the modules. How it works is you buy the portfolio, you have to decide all the components you want in it, and then they price out a bundle for you. I have almost all of the package features in my bundle. You only need to pay for the modules you want."
"I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships."
"NetMon's licensing costs about $85k per year, with some extra costs for support."
"LogRhythm's licensing part is something that depends on the license you want since they offer it on a perpetual and subscription basis."
"Pricing is okay. There were some competitors that were extremely expensive and there were some which were really inexpensive but LogRhythm stayed in the middle of them."
"The price of this solution is too high, so it should be made more practical and more valuable for the customer."
"The product is expensive for smaller companies."
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
884,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
10%
Government
6%
Transportation Company
16%
Performing Arts
11%
Financial Services Firm
10%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business50
Midsize Enterprise33
Large Enterprise62
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise7
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
What do you like most about LogRhythm NetMon?
It has a very strong artificial intelligence engine.
What is your experience regarding pricing and costs for LogRhythm NetMon?
I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships.
What needs improvement with LogRhythm NetMon?
Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time. However, currently, it is not giving many challenges.It is difficult to i...
 

Also Known As

CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
LogRhythm Network Monitor
 

Overview

 

Sample Customers

Information Not Available
Sera-Brynn
Find out what your peers are saying about CrowdStrike Falcon vs. NetMon and other solutions. Updated: February 2026.
884,873 professionals have used our research since 2012.