No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness NDR vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.0
Implementing NetWitness NDR enhances security, improves network visibility, reduces costs, and boosts efficiency and productivity for businesses.
Sentiment score
7.0
Trellix NDR boosts ROI by improving security, reducing response times, and enabling efficient threat management and cost savings.
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
Security Engineer at Digitaltrack
 

Customer Service

Sentiment score
7.3
NetWitness NDR's customer service is generally efficient and highly regarded, though some users report occasional slow response times.
Sentiment score
7.2
Trellix Network Detection and Response support is praised for knowledgeable service, though response times need improvement during severe incidents.
The support team was responsive and knowledgeable.
Business development executive at Digitaltrack solution Pvt Ltd
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Scalability Issues

Sentiment score
7.0
NetWitness NDR is scalable for large enterprises, though some users report issues with scalability and agent migration.
Sentiment score
8.0
Trellix Network Detection and Response is scalable and reliable, efficiently handling complex configurations and high bandwidth in large networks.
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Cyber Security Engineer at a retailer with 51-200 employees
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
Business development executive at Digitaltrack solution Pvt Ltd
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
7.7
NetWitness NDR is generally reliable, providing real-time data and stability, though minor technical issues are occasionally reported.
Sentiment score
8.0
Trellix Network Detection and Response is highly stable and reliable, with minimal downtime and consistently praised by users.
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
Business development executive at Digitaltrack solution Pvt Ltd
I encounter no issues with health or reliability when the recommended specifications are met.
CyberSecurity Architect at a comms service provider with 51-200 employees
 

Room For Improvement

NetWitness NDR requires improvements in UI, scalability, detectability, integration, session times, pricing, training, and features, making it complex and slow.
Trellix needs improved customization, integration, and usability in its detection, reporting, and policy management for enhanced user experience.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Network & Security Lead at Net-International
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Presales Manager
 

Setup Cost

Trellix's pricing is considered competitive but expensive, with straightforward licensing and efficient setup, potentially deterring smaller businesses.
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
Business development executive at Digitaltrack solution Pvt Ltd
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
CyberSecurity Architect at a comms service provider with 51-200 employees
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
Network & Security Lead at Net-International
 

Valuable Features

NetWitness NDR offers high detection rates, real-time malware response, third-party integration, and a user-friendly, interoperable interface with advanced analytics.
Trellix Network Detection and Response enhances security with real-time detection, automation, and integration, reducing manual monitoring by 50%.
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Network & Security Lead at Net-International
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
Presales Manager
 

Categories and Ranking

NetWitness NDR
Ranking in Network Detection and Response (NDR)
19th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (48th), Threat Intelligence Platforms (TIP) (34th), Endpoint Detection and Response (EDR) (58th), Security Orchestration Automation and Response (SOAR) (23rd), Extended Detection and Response (XDR) (39th)
Trellix Network Detection a...
Ranking in Network Detection and Response (NDR)
7th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
54
Ranking in other categories
Advanced Threat Protection (ATP) (10th)
 

Mindshare comparison

As of June 2026, in the Network Detection and Response (NDR) category, the mindshare of NetWitness NDR is 3.4%, up from 2.2% compared to the previous year. The mindshare of Trellix Network Detection and Response is 3.0%, up from 2.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Trellix Network Detection and Response3.0%
NetWitness NDR3.4%
Other93.6%
Network Detection and Response (NDR)
 

Featured Reviews

reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Continuous network insight has improved early threat detection and streamlined investigations
Overall, we have a positive experience with Trellix Network Detection and Response, but like any enterprise security solution, there are areas where it can continue to improve. One area would be user interface and dashboard customization. While the platform provides a lot of valuable information, new users can sometimes face a learning curve when navigating and investigating and creating customized views. More intuitive dashboards would simplify workflows and help analysts access critical information even faster. Another area for improvement is reporting and analytics. The existing reporting capabilities are useful, but more flexibility and customizable reporting options would make it easier to generate executive-level summaries, compliance reports, and operational metrics for different audiences.
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
9%
Computer Software Company
8%
Comms Service Provider
7%
Manufacturing Company
16%
Financial Services Firm
13%
Comms Service Provider
9%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise6
By reviewers
Company SizeCount
Small Business35
Midsize Enterprise11
Large Enterprise23
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is positive, as the setup process was straightforward, licensing was flexible, and the value deliver...
What needs improvement with FireEye Network Security?
Based on my experience with the solution, I do not see any improvements needed for Trellix Network Detection and Response at present; it might be required in the future, but there is no space to im...
What is your primary use case for FireEye Network Security?
Our main use case for Trellix Network Detection and Response is to maintain oversight of our network traffic and catch any threats or unusual activity as early as possible. Trellix Network Detectio...
 

Also Known As

RSA ECAT, NetWitness Network
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

ADP, Ameritas, Partners Healthcare
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about NetWitness NDR vs. Trellix Network Detection and Response and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.