Try our new research platform with insights from 80,000+ expert users

NetMon vs Vectra AI comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetMon
Ranking in Identity Threat Detection and Response (ITDR)
16th
Average Rating
7.6
Reviews Sentiment
6.1
Number of Reviews
12
Ranking in other categories
Network Monitoring Software (51st)
Vectra AI
Ranking in Identity Threat Detection and Response (ITDR)
11th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
47
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (5th), Network Detection and Response (NDR) (2nd), Extended Detection and Response (XDR) (16th), AI-Powered Cybersecurity Platforms (6th)
 

Mindshare comparison

As of January 2026, in the Identity Threat Detection and Response (ITDR) category, the mindshare of NetMon is 1.0%. The mindshare of Vectra AI is 2.7%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity Threat Detection and Response (ITDR) Market Share Distribution
ProductMarket Share (%)
Vectra AI2.7%
NetMon1.0%
Other96.3%
Identity Threat Detection and Response (ITDR)
 

Featured Reviews

SR
Pan India IT Infrastructure Management / End-user Services at Tata Group
Has supported real-time event detection and reporting accuracy while database integration has required extra effort
Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time. However, currently, it is not giving many challenges.It is difficult to integrate NetMon with other databases. We can customize NetMon's monitoring views, but it is done by the team who handles it, as it is outsourced.
RR
Consultant at a retailer with 5,001-10,000 employees
Threat detection has improved and malicious emails are now identified quickly
Vectra AI offers artificial intelligence capabilities with visibility that can be integrated into our day-to-day operations and other tools, including malware detection tools and cyber threat tools. Vectra AI has positively impacted my organization. Last year while using it, we received many malicious email threats and virus incidents, including a trojan virus that had reportedly been deployed by someone. Our company used Vectra AI to detect the malicious threats and viruses before they could cause more damage, and we successfully stopped the threats. Using Vectra AI, I notice that server downtime has decreased significantly. We now experience only two to three hours of downtime, whereas without Vectra AI and other tools, our downtime would exceed 48 to 72 hours.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Visibility is a valuable feature, the ability to see even if the traffic is not going into the firewall"
"The protocols with which you see the traffic for a particular website that a client has in their environment, for example, are valuable. We can monitor whether the traffic is up to the mark or whether they need to add more bandwidth. Also, we can see if we're able to get real-time environment data as well. The customization dashboard is really good. LogRhythm NetMon has its own in-built dashboards which are helpful in guiding customization."
"NetMon's best feature is traffic analysis."
"LogRhythm NetMon's most impressive feature is that it's a bundled package, so you're not just relying on monthly data; you get a six-month view for more comprehensive indicators of compromise. This dual approach is precious. We implement LogRhythm NetMon in our cybersecurity strategy mainly for compliance and correlation of network, user, and decision activities, particularly for network firewalls and access control."
"It has a very strong artificial intelligence engine."
"The initial setup is straightforward because we can deploy an open server."
"The most valuable feature is the log, which can be analyzed by our SIEM solution."
"The analytics feature is the most valuable feature."
"The solution is currently used as a central threat detection and response system."
"We often use the new feature to create PCAP files from the whole data traffic. It makes it much easier to find network problems such as whether the server is responding to a request. It has nothing to do with security, but it helps a lot to find other problems."
"What I like best about Vectra AI is that it alerts you about suspicious activities."
"The packet-capturing feature is very useful."
"The core product provides excellent visibility, but my favorite feature is Vectra Recall."
"Our company used Vectra AI to detect the malicious threats and viruses before they could cause more damage, and we successfully stopped the threats."
"It's easy to manage, and I love the UX. It's very well designed. When we are looking for something, it's quite easy to find it."
"One of the things that we didn't expect to happen was that our network team also jumped on it faster than we thought. In most cases, if it's a security tool that's working on the network part, they can also use it to find out certain flaws that have been in the system. Certain flaws, related to some legacy stuff, were already there for quite a few years, which they couldn't explain at first, but we could explain them based on the timing of certain things."
 

Cons

"The platform's integration features often need to be improved."
"Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time."
"The main concern is that LogRhythm has not improved NetMon but instead introduced a separate product, which many customers, including us, would prefer to be integrated into a single platform for easier management."
"There is an issue with tunneling in relation to how the connectivity is established between the end devices and where NetMon is installed. On the console, I often observe that there's a difference of a few seconds or maybe a minute, and this lag time should not be there."
"The training for this product is not very good and needs to be improved."
"I would like to see better integration with multiple products. Integration is not something that is readily available for most of the products."
"Sometimes it's hard to find the network devices' self-audit logs."
"LogRhythm NetMon's pricing model is an area of concern that should be made a little bit cheaper in comparison to the other players in the market currently."
"In comparison with a lot of systems I used in the past, the false positives are really a burden because they are taking a lot of time at this moment."
"The rules for threats are not always precise and Vectra AI should improve this."
"Vectra AI could be improved by focusing on all threat types, not only malicious threats or virus threats."
"They use a proprietary logging format that is probably 90% similar to Bro Logs. Their biggest area of improvement is finishing out the remaining 10%. That 10% might not be beneficial to their ML engine, but that's fine. The industry standard is Zeek Logs or Bro Logs, or Bro or Zeek, depending on how old you are. While they have 90% of those fields, they're still missing some fields. In very rare instances, some community rules do not have the fields that they need, and we had to modify community rules for our logs. So, their biggest area of improvement would be to just finish their matching of the Zeek standard."
"I would like to see a bit more strategic metrics instead of technical data. Information that I could show to my executive management team or board would be valuable."
"I think Vectra AI's automation, reporting, and integration could be improved."
"Pricing could be improved, as many customers have complained about the pricing model and pricing complexity."
"The solution has not reduced the security analyst workload in our organization because we still need to SIEM. Unfortunately, while Vectra, for us, is a brilliant tool for network investigations, giving wonderful visibility, it doesn't go the whole way to replace our SIEM that is needed for compliance. So, I still have the same amount of alerting and logging that I did before. It gives us more defined ability to see incidents, but it doesn't give us enough information to satisfy a PCI or 27001 audit."
 

Pricing and Cost Advice

"I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships."
"NetMon's licensing costs about $85k per year, with some extra costs for support."
"Pricing is okay. There were some competitors that were extremely expensive and there were some which were really inexpensive but LogRhythm stayed in the middle of them."
"LogRhythm's licensing part is something that depends on the license you want since they offer it on a perpetual and subscription basis."
"The price of this solution is too high, so it should be made more practical and more valuable for the customer."
"The product is expensive for smaller companies."
"At the time of purchase, we found the pricing acceptable. We had an urgency to get something in place because we had a minor breach that occurred at the tail end of 2016 to the beginning of 2017. This indicated we had a lack of ability to detect things on the network. Hence, why we moved quickly to get into the tool in place. We found things like Bitcoin mining and botnets which we closed quickly. In that regard, it was worth the money."
"The pricing is very good. It's less expensive than many of the tools out there."
"The solution's pricing was 50 percent lower than the other vendors shortlisted."
"Its cost is too much. It's an investment that we can afford. It's a lot, but it's worth it."
"Vectra AI is not a cheap solution."
"The pricing and licensing are quite straightforward because they're based on the IP licenses. As a result, they are easy to count."
"It's relatively on the pricier side, but when compared to other solutions. It's not the most budget-friendly option, but it can be considered somewhat more cost-effective in comparison to other alternatives."
"Their licensing model is antiquated. I'm not a fan of their licensing model. We have to pay for licensing based on four different things. You have to pay based on the number of unique IPs, the number of logs that we send through Recall and Stream, and the size of our environment. They need to simplify their licensing down to just one thing. It should be based on the amount of data, the number of devices, or something else, but there should be just one thing for everything. That's what they need to base their licensing on. Cost-wise, they're not cheap. They were definitely the most expensive option, but you get what you pay for. They're not the cheapest option."
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Transportation Company
19%
Performing Arts
13%
Financial Services Firm
11%
Comms Service Provider
7%
Financial Services Firm
10%
Computer Software Company
9%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise7
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise10
Large Enterprise29
 

Questions from the Community

What do you like most about LogRhythm NetMon?
It has a very strong artificial intelligence engine.
What is your experience regarding pricing and costs for LogRhythm NetMon?
I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships.
What needs improvement with LogRhythm NetMon?
Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time. However, currently, it is not giving many challenges.It is difficult to i...
What is the biggest difference between Corelight and Vectra AI?
The two platforms take a fundamentally different approach to NDR. Corelight is limited to use cases that require the eventual forwarding of events and parsed data logs to a security team’s SIEM or ...
What do you like most about Vectra AI?
The solution is currently used as a central threat detection and response system.
What is your experience regarding pricing and costs for Vectra AI?
It is very acceptable when you compare it with Darktrace, for example.
 

Comparisons

 

Also Known As

LogRhythm Network Monitor
Vectra Networks, Vectra AI NDR
 

Overview

 

Sample Customers

Sera-Brynn
Tribune Media Group, Barry University, Aruba Networks, Good Technology, Riverbed, Santa Clara University, Securities Exchange, Tri-State Generation and Transmission Association
Find out what your peers are saying about NetMon vs. Vectra AI and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.