NetWitness Platform
NetWitnessReviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
24 reviews
from
External reviews are not included in the AWS star rating for the product.
Good experience
What do you like best about the product?
Great to get insights about the risk score and alerts and incidents give a broader picture on activity
What do you dislike about the product?
Dashboards could habe been a bit more pleasing to see. Nonetheless this will be achieved in the near future probably
What problems is the product solving and how is that benefiting you?
It's a one stope solution to SIEM , to identify threats and take necessary actions well in time. To protect endpoints from danger
Best siem out there in market, best in performance best in managing
What do you like best about the product?
The best part the ueba and the latest soar capability which reduces multiple work heads collate under one umbrella.
What do you dislike about the product?
The complexity in the architecture, most of the issues which occur in environment requires lot of investigation to find the RCA.
What problems is the product solving and how is that benefiting you?
The day to day security incidents and event management, combined together with soar capability the response has also become more easy.
Great for someone with mid level knowledge in networking
What do you like best about the product?
The way you can follow packets and the UI
What do you dislike about the product?
A lot of features and it's a bit overwhelming to use
What problems is the product solving and how is that benefiting you?
Fast find of suspicious activity
Recommendations to others considering the product:
I think it's a great product. I haven't used it for the past 4 years but when I did I loved it.
Easy to deploy and manage with good features.
What do you like best about the product?
Availablity of out of the box usecases (Correlation rules, reports and dashboards). Network (packet) capture component and also have inbuilt EDR and UEBA components.
Good product documention.
New version is good.
Good product documention.
New version is good.
What do you dislike about the product?
Application level HA is not there.
Support can be improved.
Migration from older versions.
Support can be improved.
Migration from older versions.
What problems is the product solving and how is that benefiting you?
Flexible licensing options.
Easy to do custom application/device integration and custom parser development.
Easy to do custom application/device integration and custom parser development.
RSA Netwitness Review
What do you like best about the product?
The investigation tab is helping me a lot during my investigation as it shows all the available meta keys in the logs, which makes it easier to notice suspicious artifacts.
What do you dislike about the product?
RSA Net witness needs enhancing in showing the details of the entire packet, for example (headers and body)
What problems is the product solving and how is that benefiting you?
The investigation tab is helping me a lot during my investigation as it shows all the available meta keys in the logs, which makes it easier to notice suspicious artifacts.
I started my experience with version 10.6 and it was good enough
What do you like best about the product?
It is easy to use and packets is an added value
What do you dislike about the product?
The complexity of the devices specifically the Hybrid and the ESA appliances
What problems is the product solving and how is that benefiting you?
Easy to get alerts and notifications in case of any attacks
I am RSA engineer for the L1, responsible for incident handling
What do you like best about the product?
Log collection and event management, Incident investigation
What do you dislike about the product?
GUI console, RSS Hirarchay, log analysis,
What problems is the product solving and how is that benefiting you?
While starting the investigation checking each tab for ex. Respond and investigations is a bit confusing
RSA Netwitness Logs & Networks
What do you like best about the product?
The response speed at GUI for Security Analysis and threat hunting purpose is the best part. Even to fetch the old data for any of the audit purposes it takes just seconds.
What do you dislike about the product?
I don't like the Hybrid component i.e Hybrid log decoder (Decoder+ Concentrator) as if in case we face problem in any of the component we have to face trouble with other as well. Better to prefer all the standalone component in RSA Netwitness.
What problems is the product solving and how is that benefiting you?
All the technical issues whether it is related to storage, licences, upgrade or any other troubleshooting part I am working upon. The benefits of even getting a issue is that you will get to learn things from that as the RSA support is quite good.
Recommendations to others considering the product:
It's a one of the good SIEM technology in the market one can opt for
The better web gateway security management.
What do you like best about the product?
We like this tool at the gateway because it allows us to capture network data and transmit it to security and network staff. With that we have visibility, detection of threats and then mitigate them. I also like the friendly, intuitive interface and easy to administer and configure security rules.
What do you dislike about the product?
We have been using it for a long time and no one has reported any problems with using the RSA NetWitness Network. The tool offers great cost-benefit protection against simple and complex threats.
What problems is the product solving and how is that benefiting you?
The RSA NetWitness Network tool is complete. It deals with the recognition and detection of threats, such as responses to security incidents. In addition, he is able to conduct a forensic investigation and analysis. It is always updated frequently, has great support and quality.
RSA NetWitness
What do you like best about the product?
RSA is a superb vendor. They have been engaged with each of subsidiaries from the get-go.
What do you dislike about the product?
The learning curve is steep. The overall solution is a large effort to implement correctly.
What problems is the product solving and how is that benefiting you?
Needed a flexible SIEM solution required for multiple subsidiaries with very different infrastructures.
Recommendations to others considering the product:
It is a big tool with a steep learning curve. Put in the time and effort to properly leverage it's full potential.
showing 11 - 20