We provide NetWitness along with Archer, and multiple sites. We are managing their security operations using this other station and Archer. A collector can work in two different ways. It can collect the logs, and it can aggregate the traffic tools from different net flow logs. When I saying "logs," I mean a log collector and when I say "packet," that means the packet or log connector.
Information Technology Security Consultant at Sify Technologies
The setup is straightforward and there are multiple connectors to help you integrate
Pros and Cons
- "Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
- "Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
What is our primary use case?
What do I think about the stability of the solution?
The stability all depends upon how well the site is set up. All these solutions are good, but the CPU and OS are the major portion of undoing the correlations. If you have a poor correlation, then you need to have less than 70 percent utilization. Then that may not be good performance.
What do I think about the scalability of the solution?
NetWitness is scalable. You can scale, but you cannot assume that if you are deploying it today, you could use the same hardware setup as before. You only have two or three connectors. It is not at all possible. However, 20 percent scalability is always there with Odyssey.
How are customer service and support?
Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10.
Buyer's Guide
NetWitness Platform
June 2026
Learn what your peers think about NetWitness Platform. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,456 professionals have used our research since 2012.
How was the initial setup?
Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports.
The complexity of the deployment depends on the amount and type of log sources. Are there any custom home-grown log sources for which you need to create the custom parsers? How many different logs or log lines in a home grown application? These factors might make your parser development a bit cumbersome.
What's my experience with pricing, setup cost, and licensing?
The licenses are based on the ETS.
What other advice do I have?
I rate RSA NetWitness Logs and Packets eight out of 10. Aside from ETS, it is the second-most important solution for maintaining compliance and how much data you need in the online logs or the offline archival logs.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Presales Manager at a tech services company with 51-200 employees
Enables incident response team to correlate logs to identify any kind of problem, both for logs and packets
Pros and Cons
- "It gives the capability for the incident response team to correlate logs to identify any kind of problem like malware and incidents in a general sense, both for logs and packets."
- "It gives customers visibility about their most important servers and devices."
- "If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
- "One thing to be improved in NetWitness is the capability to correlate event logs in a general sense."
What is our primary use case?
This solution is deployed on-premise.
What is most valuable?
It gives the capability for the incident response team to correlate logs to identify any kind of problem like malware and incidents in a general sense, both for logs and packets. I think the most important thing was that it gives the customer the capability to discover and respond to an incident. It gives customers visibility about their most important servers and devices.
Regarding the packet model, the most important thing is how easy it is to rebuild the raw data. Through one click, you can see an email that was sent even without accessing the mailbox from the user. It's easy to rebuild the raw data, especially the packet.
What needs improvement?
If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis.
NetWitness has a malware appliance, but in terms of dynamic analysis, we need to integrate with 30 vendors. It would be great to have a sandbox produced by the RSA and the SSL appliance also.
For how long have I used the solution?
I have been working with this solution for six years.
Which solution did I use previously and why did I switch?
I have worked with ArcSight from Micro Focus. One thing to be improved in NetWitness is the capability to correlate event logs in a general sense. We have less resources in the NetWitness correlation engine compared with ArcSight.
What other advice do I have?
I would rate this solution 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
NetWitness Platform
June 2026
Learn what your peers think about NetWitness Platform. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,456 professionals have used our research since 2012.
Security Operations Manager at a computer software company with 1,001-5,000 employees
Reliable, straightforward installation, but lacking multi-tenant capabilities
Pros and Cons
- "The newer 11.5 version that my team is using has found it to have good mapping."
- "The solution is reliable."
- "The multi-tenant capabilities are lagging compared to IBM QRadar."
What is our primary use case?
We have two customers using this solution and one of them is a banking business. We are collecting some of the security log sources. In the main use case, we are correlating rules and we are using the endpoint detection capabilities. We are utilizing RSA NetWitness Logs and Packets, to have more insights on an endpoint level.
What is most valuable?
The newer 11.5 version that my team is using has found it to have good mapping.
What needs improvement?
The multi-tenant capabilities are lagging compared to IBM QRadar.
We want the OEM to support us when we add a partner. They have to come forward and be ready to give a POC to the customer. For example, if we are identifying any customer, and the customer wants to see the POC but at that time we do not have that resource to showcase the POC or the environment. At this time the OEM should come forward and showcase the POC to the customer. Once the customer is satisfied, we will be gaining the business, as a win-win situation.
For how long have I used the solution?
I have been using RSA NetWitness Logs and Packets (RSA SIEM) for approximately two years.
What do I think about the stability of the solution?
The solution is reliable.
What do I think about the scalability of the solution?
I have not tried to expand the solution.
How are customer service and support?
The technical support is responsive. Professional service when it is required is expensive. I wasn't able to compare with other professional services, because we have only one tool we are using at the moment. I am not able to tell you how much other OEM professional services cost. We have heard from the support that it is expensive.
Which solution did I use previously and why did I switch?
I have previously used IBM QRadar.
How was the initial setup?
The installation is somewhat straightforward. For example, if they want a UBA or SOAR type of platform, then I don't have experience in integrating or installing the SOAR or UPA. If that kind of opportunity comes or a customer requests it, then we have to see. As it is now, RSA NetWitness Logs and Packets (RSA SIEM) installation is straightforward.
What's my experience with pricing, setup cost, and licensing?
We are on an annual license for the use of the solution.
What other advice do I have?
I would recommend version 11.5, it looks good. However, we are looking for an alternative solution.
I rate RSA NetWitness Logs and Packets (RSA SIEM) version 11.4 a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT manager at a agriculture with 10,001+ employees
Really scalable for enterprise customers
Pros and Cons
- "The solution is really scalable for the high-end power, enterprise customer."
- "Integration is exceedingly minimal, since its project development is much easier than that of LogRythm or IBM."
- "The solution should have more integration capabilities with different platforms."
What is our primary use case?
Generally, we use the solution for network forensics. It allows us to do visual data detection and prevention.
What needs improvement?
The solution should have more integration capabilities with different platforms. The API is nearly open and scalable, so the solution can integrate with many platforms. The solution has more than 200 log sources in the scalability to support, but this is its limit.
Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.
For how long have I used the solution?
I have been using RSA NetWitness Logs and Packets (RSA SIEM) for two years.
What do I think about the scalability of the solution?
The solution is really scalable for the high-end power, enterprise customer, but not for the small one.
How are customer service and support?
Mostly, the support is provided remotely and has proven to be good. It was good at the time when we made use of it. I have no idea whether they improved their support over the course of the last year. Previously, our country did not have certified resources, although the first-level of support was available through their local partners, as well as paying-level support, which was handled remotely through India or Singapore.
How was the initial setup?
Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.
If one goes the intelligent route, installation should take at least four to five hours.
What about the implementation team?
There were at least two people involved in the deployment and maintenance. From an operational perspective, there is a need for at least three people, since type one, two and three analysts are involved. Two people are sufficient for the installation, though.
What's my experience with pricing, setup cost, and licensing?
There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual.
Which other solutions did I evaluate?
Integration is exceedingly minimal, since its project development is much easier than that of LogRythm or IBM. This means that the solution is significantly more flexible for the customer and requires less training.
What other advice do I have?
I would definitely recommend this solution to others, but not to small-sized customers. The solution is one of the best for enterprise customers exceeding 10,000 or 2,000 EPS.
I rate RSA NetWitness Logs and Packets (RSA SIEM) as a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Program Manager at EGYANAM TECH
Economical with good technical support and is easily scalable
Pros and Cons
- "It's quite economical compared to other solutions in the market."
- "Technical support is very good; they try to resolve issues with the proper SLAs which are defined by them and they understand the client's requirements as well as the client's infrastructure in a better manner."
- "The initial setup is complex. There are other solutions that are easier to implement."
- "The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
What is our primary use case?
I'm primarily using the solution on my client's site.
This is a log event management tool. We are integrating this solution for the clients where it is required. Mostly we work with OEMs such as IBM, RSA, Splunk, and Micro Focus.
With the help of these tools, you can identify any attacks or phishing activity in your network. Most of the time you are able to identify these types of attacks or activity on your firewall. When the firewall will notify the SIEM tools, it will identify which needs to be acted on immediately - unlike when you are using automation tools. With the help of automated tools, you can block those suspicious IPS or you can hand it over back to your security analyst or analyst team to take action ASAP.
What is most valuable?
We have not evaluated this tool. It is evaluated by the client's company directly. That said, I have found it has good threat intel insights, comparatively speaking.
From the client-side, there are economical kinds of features. It's quite economical compared to other solutions in the market.
The solution is scalable.
The technical support is very good.
What needs improvement?
We are designing reports and automated rules and processes. We are defining them in relation to this product. With the help of automated rules and processes, this product will help the team when they go to production to do operations smoothly, as, most of the time, what happens when you put manual interference into such systems, it may be delayed. This can lead to vulnerabilities. Sometimes, if a hacker enters the system, he might only have a limited time where there is a window of access, however, in that time, he'll take what he can, and even if the vulnerability only lasted for a few minutes, in that time, items can get stolen.
Therefore, there needs to be more proactively to avoid any downtime. We're adding automating tools to help RSA Netwitness so that if anything happens, RSA can immediately shut anything down. We're in the process of configuring them and adding them in.
The initial setup is complex. There are solutions that are easier to implement.
For how long have I used the solution?
I've been using the solution for two and a half years.
What do I think about the stability of the solution?
The solution is reliable. I won't say great, due to the fact that, naturally, if you compare it to other products it is not that great. That said, for the operations, it is good as long as you do not violate your license. The moment you violate your license, this will cause a quite delayed reaction, at least, that is what I've seen compared to Splunk and QRadar.
What do I think about the scalability of the solution?
While the solution isn't necessarily for small organizations, it is good for medium and large organizations.
The solution scales easily.
How are customer service and technical support?
Technical support is very good. They try to resolve issues with the proper SLAs which are defined by them and they understand the client's requirements as well as the client's infrastructure in a better manner. I'm happy with the support.
How was the initial setup?
The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk. They are much easier to set up. It also depends on the client's infrastructure. It just needs some time and understanding to be deployed.
Once it is deployed it requires maintenance. Whenever you work on such products, if you do not take the support or support services, it might take some time to work through some things. For some things, the documentation is not the best. Support is always recommended. If you do not buy support, it can be a disaster.
What's my experience with pricing, setup cost, and licensing?
It's my understanding that the pricing of the product is pretty good. Compared to other options on the market, it's reasonable.
I would say it's economical, as the licensing part is always a different ball game in the SIEM tools business, as everyone is running their business in a different manner. If you go to IBM, they will charge you in a different way, for example. RSA will charge you in a different way as well, and Splunk has its own unique licensing policies. I would say it's economical. I won't say it's cheap. It is in between.
Currently, there is only one license. There aren't different licensing models. Hardware is included in the price.
What other advice do I have?
I'm on the latest version of the solution. I tend to work on updated versions.
We are systems integrators. We have a partnership with RSA.
If a company decides to try out this product, they need to do the homework properly due to the fact that sometimes on the hardware side or on the software side, you may face some issues. It is better to study thoroughly the troubleshooting part and prepare properly. Only then you can go for implementation.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Computer Security Consultant at SECURE SOFT
Deployment flexibility and robust integration enhance reporting and analytics capabilities in financial industry
Pros and Cons
- "NetWitness Platform offers flexibility for deployment and robust integration capabilities."
What is our primary use case?
I use NetWitness Platform in the financial industry as a good product with excellent capabilities and integration with various devices.
What is most valuable?
NetWitness Platform offers flexibility for deployment and robust integration capabilities. It excels in research events, analytics data, and reporting. It is particularly beneficial for reporting purposes, offering efficient solutions.
What needs improvement?
There is currently no need for improvement in the SIEM, though there could be potential enhancements by integrating with AI.
How are customer service and support?
The support is good, and I would rate it nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup was not complex. On a scale of zero to ten, where ten is the easiest, I would rate it seven or eight.
What was our ROI?
The solution is efficient, though I do not provide specific ROI details.
What's my experience with pricing, setup cost, and licensing?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
Which other solutions did I evaluate?
What other advice do I have?
I would rate the SIEM eight out of ten.
Which deployment model are you using for this solution?
I am using the on-premises deployment model.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Delivery Partner APAC and MEA at Tata Consultancy
Streamlined solution that's easy to implement
Pros and Cons
- "The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
- "Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients."
- "An area for improvement would be better automation and more inbuilt use cases."
What is our primary use case?
Primarily, I use this solution to integrate with applications and systems like firewalls and routers. For example, if somebody is trying to log on from two different locations simultaneously, we can catch that.
How has it helped my organization?
Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients.
What needs improvement?
An area for improvement would be better automation and more inbuilt use cases. In the next release, RSA should include an inbuilt migration framework that can do remediation.
For how long have I used the solution?
I've been using this solution since 2011.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
The software is scalable to whatever is required, and you can also put a lot of resources in the cloud.
How was the initial setup?
The initial setup isn't much of a challenge and can be completed in under twelve hours.
What's my experience with pricing, setup cost, and licensing?
Our license price is updated yearly, and there are no additional costs.
What other advice do I have?
I would rate NetWitness Logs and Packets as eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber security Lead at a manufacturing company with 1,001-5,000 employees
Great wireless feature, provides many automatic rules that are very helpful
Pros and Cons
- "Offers a good wireless feature."
- "Technically speaking, this is a good product."
- "Technical support could be improved."
- "I believe they could improve their support, there are often delays."
What is our primary use case?
The RSA Netwitness packet plays a major role in identifying cyber attacks from different sources. We integrated in a very large environment, deploying it in a container corporation in India. The company has around 86 locations across the country. Another use case of RSA is for running full scans and the third use case is for blocking malware and viruses. Nowadays, people hide behind encaptured networks and use proxies to look through the door. Then they'll try to come in.
What is most valuable?
The wireless feature is good, it tells you when to check a spot, which file it has used to encrypt, whether it is spreading and how many hosts have been infected. It's about data analysis. Looking at the network logs, it's difficult to figure out where the problem is coming from and where it's going, but those kinds of features help me a lot. The solution provides lots of automatic rules which is helpful. Technically speaking, this is a good product.
What needs improvement?
I believe they could improve their support, there are often delays. The price of the solution could be reduced, it's very costly.
What do I think about the stability of the solution?
This is a stable product.
What do I think about the scalability of the solution?
We're using the solution extensively in our shipping business so it is scalable. We probably have seven or eight users and the solution is in use 24/7.
How are customer service and technical support?
Getting technical support takes time, they get a lot of calls and we generally only get a response the following day. Cisco is better with technical support.
How was the initial setup?
The initial setup is not straightforward because of all the integrations required. It needs the aggregate data, data concentrator, defense, correlation roots, and more.
What's my experience with pricing, setup cost, and licensing?
It would help if they could provide the malware analytics in the core package as that would make the cost more reasonable. Licensing is paid annually and I believe the cost is somewhere between 12,000 - 15,000 Pounds per year. It's very high.
What other advice do I have?
I would recommend this solution.
I rate this solution a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate Manager Human Resources at a financial services firm with 1,001-5,000 employees
Good packet inspection and automated incident response, but it needs to be more customizable
Pros and Cons
- "The most valuable features are the packet inspection and the automated incident response."
- "More customizability is required, which is something that they need to improve on."
What is our primary use case?
We are using this solution for security.
What is most valuable?
The most valuable features are the packet inspection and the automated incident response.
What needs improvement?
More customizability is required, which is something that they need to improve on.
When it comes to starting a log event, there are not many options available. It is very limited.
The log and event correlation need improvement.
The threat detection capability should be enhanced.
For how long have I used the solution?
I have been using this solution for one month.
What do I think about the stability of the solution?
We are using it on a daily basis and, so far, it has been stable.
What do I think about the scalability of the solution?
We have approximately 6000 employees, which means that we have 6000 endpoints that this product is working with. It is easy to scale it up to production.
How are customer service and technical support?
We have not had to contact technical support.
Which solution did I use previously and why did I switch?
In this company, they did not use a similar solution prior to this one. Personally, I used Splunk in my previous organization. Definitely, I prefer to use Splunk because there is more functionality, visibility, and options. You can do whatever you want with Splunk.
How was the initial setup?
The initial setup is not complex, and more on the simple side. Our deployment took almost five months in total.
What about the implementation team?
We had assistance from an integrator and the vendor for our deployment.
We have administrators in the company who take care of administration and maintenance. The vendor was only needed for the implementation.
What other advice do I have?
RSA is something that I can recommend.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Analyst at Microland Limited
Easy to set up with good UEBA functionality
Pros and Cons
- "What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
- "Stability has not been an issue with this product."
- "Security needs improvement."
- "Security needs improvement. We would still like to know how the traffic is entering the organization."
What is our primary use case?
The primary use case of this solution is for security.
We use the UEBA tool.
What is most valuable?
What we are mainly using are the RSA Concentrator, RSA Decoder, Archiver, Broker, and Log Decoder.
What needs improvement?
Security needs improvement.
We would still like to know how the traffic is entering the organization. We can find out but it will take time before we know, leaving the organization vulnerable for attack.
There is no SIEM tool in the world that can provide 100% security.
For how long have I used the solution?
I have been using this solution for five months.
What do I think about the stability of the solution?
Stability has not been an issue with this product.
What do I think about the scalability of the solution?
It's a scalable solution.
How was the initial setup?
The initial setup was straightforward, not at all complex.
There are approximately 1,400 devices that are integrated into RSA in my organization. While I was not a part of the integration, from my knowledge, it would take a week.
Which other solutions did I evaluate?
We have looked at similar systems and find that the architecture is somewhat different, yet the functionality is similar.
What other advice do I have?
This is a product that I recommend.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free NetWitness Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Graylog Enterprise
Fortinet FortiSIEM
Security Onion
Gigamon Deep Observability Pipeline
Buyer's Guide
Download our free NetWitness Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?
















