Best Network Traffic Analysis (NTA) Software

How Many Network Traffic Analysis (NTA) Software Products Does G2 Track?

Total Products under this Category: 94

Category Stats (Oct 2026)

  • Average Rating: 4.4/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Darktrace / EMAIL (+0.66%) - Among all products in this category, Darktrace / EMAIL recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Network Traffic Analysis (NTA) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 4,400+ Authentic Reviews
  • 94+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Network Traffic Analysis (NTA) Software

G2 Grid® for Network Traffic Analysis (NTA) Software plotting products by satisfaction and market presence

Highlighted products: Check Point Next Generation Firewalls (NGFWs), SolarWinds Observability, IBM QRadar SIEM, Palo Alto Cortex XSIAM, IBM SevOne, Rapid7 Next-Gen SIEM, Datadog, and Trellix Network Detection and Response (NDR).

Underlying data: [Grid® JSON](https://www.g2.com/categories/network-traffic-analysis-nta/grids.json?focus%5B%5D=check-point-next-generation-firewalls-ngfws&focus%5B%5D=solarwinds-worldwide-llc-solarwinds-observability&focus%5B%5D=ibm-ibm-qradar-siem&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=ibm-sevone&focus%5B%5D=rapid7-next-gen-siem&focus%5B%5D=datadog&focus%5B%5D=trellix-network-detection-and-response-ndr)

Check Point Next Generation Firewalls (NGFWs)

Strengthen Your Security with Check Point Gateways and Firewalls Check Point Hybrid Mesh Network Security is a comprehensive cybersecurity solution designed to protect networks from sophisticated cyber threats while ensuring seamless management across diverse hybrid environments – on-premises, cloud, SaaS, and remote users. This product encompasses advanced threat prevention, real-time global threat intelligence, and unified policy management, making it an essential tool for organizations looking to secure their IT infrastructure, including data centers, hybrid clouds, and remote endpoints. Targeted at enterprises of all sizes, Check Point's solution caters to a wide range of industries that require robust security measures to safeguard sensitive data and maintain operational integrity. The product is particularly beneficial for organizations with complex network architectures, including those utilizing cloud services, Software as a Service (SaaS) applications, and remote workforces. By addressing the unique security challenges posed by these environments, Check Point enables businesses to maintain a secure and resilient IT ecosystem. One of the standout features of Check Point Hybrid Mesh Network Security is its AI-powered threat prevention capabilities. This technology allows for the identification and mitigation of threats in real-time, ensuring that organizations can respond swiftly to potential breaches. Additionally, the solution offers comprehensive security for various aspects of the IT landscape, including network and cloud security. This multi-faceted approach ensures that users, applications, and data are protected regardless of their location, whether on-premises, or in the cloud. This adaptability is complemented by unified security management, which simplifies operations through a single platform that provides visibility, policy enforcement, and posture control across the entire network. Furthermore, Check Point Hybrid Mesh Network Security is designed to optimize performance and cost. With high-speed, prevention-first security and on-device security controls, organizations can achieve effective protection without compromising on efficiency. The consistent application of zero-trust policies across the hybrid mesh network enhances security posture, ensuring that all components of the IT environment are uniformly protected against evolving cyber threats. This comprehensive solution empowers organizations to level up their protection and confidently navigate the complexities of modern cybersecurity challenges.

Average Rating: 4.5/5.0

Total Reviews: 517

How Do G2 Users Rate Check Point Next Generation Firewalls (NGFWs)?

  • Anomaly Detection: 8.9/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.8/10)
  • Network Visibility: 9.1/10 (Category avg: 9.0/10)
  • Metadata Management: 8.8/10 (Category avg: 8.4/10)

Who Is the Company Behind Check Point Next Generation Firewalls (NGFWs)?

Who Uses This Product?

  • Who Uses This: Network Security Engineer, Network Engineer
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 44% Medium, 42% Large

What Do G2 Reviewers Say About Check Point Next Generation Firewalls (NGFWs)?

AI-generated summary from verified user reviews

Pros
  • Users highlight the impressive threat prevention engine of Check Point NGFWs, ensuring strong and accurate network security.
  • Users are impressed by the strong and accurate threat detection of Check Point NGFWs, ensuring robust network protection.
  • Users value the reliable performance and ease of use of Check Point NGFWs with its comprehensive features.
  • Users value the threat prevention capabilities of Check Point NGFWs, ensuring robust network security against external threats.
  • Users value the centralized management system of Check Point NGFWs, which simplifies updates and policy modifications efficiently.
Cons
  • Users find the high cost of Check Point NGFWs to be a significant barrier to adoption and satisfaction.
  • Users find the complexity of configuration challenging, particularly for those lacking technical expertise.
  • Users find the complex setup of Check Point NGFWs to be overwhelming, especially for those new to the system.
  • Users experience slow performance issues, particularly with TAC response delays and latency affecting application operation.
  • Users find the difficult learning curve of Check Point NGFWs challenging, especially for those new to the system.

What Are Recent G2 Reviews of Check Point Next Generation Firewalls (NGFWs)?

What Are G2 Users Discussing About Check Point Next Generation Firewalls (NGFWs)?

SolarWinds Observability

SolarWinds® Observability is a comprehensive full-stack observability solution designed to meet the diverse needs of modern organizations, regardless of their size. This solution provides deep visibility into hybrid ecosystems, enabling users to monitor and manage both on-premises and cloud environments effectively. By optimizing performance and ensuring availability across distributed hybrid IT infrastructures, SolarWinds Observability supports organizations in navigating the complexities of their IT environments. Targeted at IT professionals and organizations that require robust monitoring capabilities, SolarWinds Observability caters to a wide range of use cases. It is particularly beneficial for businesses operating in hybrid environments, where the integration of on-premises and cloud resources is essential. The solution allows users to gain a holistic view of their networks, applications, databases, and user experiences, thereby facilitating better decision-making and operational efficiency. This is especially crucial in today’s fast-paced digital landscape, where downtime can significantly impact service reliability and customer satisfaction. One of the standout features of SolarWinds Observability is its built-in intelligence powered by AIOps capabilities. This functionality accelerates issue remediation by enabling users to detect, troubleshoot, and resolve problems more efficiently. The advanced predictive analysis and anomaly-based alerts help organizations proactively address potential issues before they escalate, ultimately reducing downtime and enhancing service reliability. Additionally, the solution's log pattern analysis further streamlines the troubleshooting process, allowing IT teams to focus on strategic initiatives rather than being bogged down by operational challenges. SolarWinds Observability offers flexibility in deployment, providing users with the option to choose between self-hosted and SaaS models. The self-hosted option integrates seamlessly with other SolarWinds services, such as security and storage monitoring, while the SaaS option is tailored for deeper monitoring of custom and cloud-based applications. This adaptability ensures that organizations can select the deployment method that best aligns with their operational needs and infrastructure. Moreover, SolarWinds Observability stands out by consolidating multiple monitoring tools into a single, integrated solution. This not only simplifies the monitoring process but also helps organizations reduce costs associated with managing disparate systems. By offering comprehensive visibility across hybrid IT environments, SolarWinds Observability empowers organizations to optimize their operations and enhance overall performance.

Average Rating: 4.3/5.0

Total Reviews: 831

How Do G2 Users Rate SolarWinds Observability?

  • Anomaly Detection: 7.6/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.8/10)
  • Network Visibility: 9.2/10 (Category avg: 9.0/10)
  • Metadata Management: 7.4/10 (Category avg: 8.4/10)

Who Is the Company Behind SolarWinds Observability?

  • Seller: SolarWinds Worldwide LLC
  • Company Website:
  • Year Founded: 1999
  • HQ Location: Austin, TX
  • Twitter: @solarwinds
    19,570 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,864 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Network Engineer, Network Administrator
  • Top Industries: Information Technology and Services, Hospital & Health Care
  • Company Size: 44% Large, 35% Medium

What Do G2 Reviewers Say About SolarWinds Observability?

AI-generated summary from verified user reviews

Pros
  • Users love the intuitive interface of SolarWinds Observability, making system management and monitoring effortless and efficient.
  • Users appreciate the comprehensive visibility of SolarWinds Observability, simplifying performance monitoring across diverse environments.
  • Users value the unified visibility across infrastructure that simplifies monitoring and accelerates troubleshooting effectively.
  • Users appreciate the monitoring capabilities of SolarWinds Observability, effectively managing and analyzing network environments.
  • Users appreciate the intuitive user interface of SolarWinds, enhancing the management and visibility of network performance.
Cons
  • Users find the pricing escalates quickly, making SolarWinds Observability less affordable for larger setups and features.
  • Users face a significant learning curve with SolarWinds Observability, complicating the use of advanced features and integrations.
  • Users face integration issues due to complex setups and limited support for ITSM platform connections, affecting usability.
  • Users find the complex setup of SolarWinds Observability challenging, requiring significant technical expertise and time investment.
  • Users find the configuration difficulty of SolarWinds Observability to be a significant hurdle in effective deployment.

What Are Recent G2 Reviews of SolarWinds Observability?

What Are G2 Users Discussing About SolarWinds Observability?

IBM QRadar SIEM

Outsmart threats with an end-to-end award-winning security suite; proven to prevent, endure and recover from both known & unknown IT hazards faced by SoCs in the modern-day.

Average Rating: 4.4/5.0

Total Reviews: 284

How Do G2 Users Rate IBM QRadar SIEM?

  • Anomaly Detection: 8.6/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 8.8/10)
  • Network Visibility: 8.9/10 (Category avg: 9.0/10)
  • Metadata Management: 8.4/10 (Category avg: 8.4/10)

Who Is the Company Behind IBM QRadar SIEM?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Who Uses This: Security Engineer, SOC Analyst
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 53% Large, 29% Medium

What Do G2 Reviewers Say About IBM QRadar SIEM?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of IBM QRadar SIEM, facilitating effective threat management and investigation.
  • Users appreciate the flexible integration capabilities of IBM QRadar SIEM, enhancing log management across diverse sources.
  • Users value the advanced threat detection and centralized log management features of IBM QRadar SIEM for enhanced security.
  • Users appreciate the easy integrations of IBM QRadar SIEM, enhancing its functionality with various platforms seamlessly.
  • Users appreciate the user-friendly interface of IBM QRadar SIEM, making it accessible for both tech and non-tech users.
Cons
  • Users find the UX improvements lacking, struggling with limited features and an unfriendly interface in QRadar SIEM.
  • Users find IBM QRadar SIEM expensive, particularly small and mid-sized companies struggling with the overall cost.
  • Users find the high cost of IBM QRadar SIEM challenging, particularly for smaller organizations needing comprehensive support.
  • Users face dashboard issues with IBM QRadar SIEM, lacking customization, usability, and integration for optimal performance.
  • Users find the time-consuming nature of QRadar SIEM frustrating, especially with complicated queries and log fetching delays.

What Are Recent G2 Reviews of IBM QRadar SIEM?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

IBM SevOne

IBM® SevOne, now part of the Concert platform, gives NetOps teams deep, real-time visibility into hybrid cloud and SD-WAN performance — combining network-layer intelligence and app-aware insights to speed up resolution, reduce complexity, and ensure seamless digital experiences. In a world of hybrid clouds and ever-rising user expectations, downtime is not an option. IBM SevOne 8.0 equips NetOps teams with real-time, unified visibility across complex networks—from SD-WAN and multi-cloud (AWS, GCP, Azure) to Kubernetes. Built for speed and scale, it reduces time-to-value with native widget deployment, enhances diagnostics with advanced Flow Filters, and integrates seamlessly with vendors like Cisco, Aruba, and Palo Alto. The result? A cloud-smart, app-aware network that proactively detects issues before they impact users. With SevOne, you don’t just monitor. You take control of the future of network observability—today.

Average Rating: 4.3/5.0

Total Reviews: 70

How Do G2 Users Rate IBM SevOne?

  • Anomaly Detection: 8.3/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 8.8/10)
  • Network Visibility: 8.9/10 (Category avg: 9.0/10)
  • Metadata Management: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind IBM SevOne?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 38% Medium, 32% Large

What Do G2 Reviewers Say About IBM SevOne?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time monitoring capabilities of IBM SevOne, enabling proactive management and rapid issue resolution.
  • Users commend the reliability of IBM SevOne, providing timely insights and consistent performance monitoring for complex networks.
  • Users value the real-time monitoring capabilities of IBM SevOne, enhancing their ability to track network performance effectively.
  • Users appreciate the customizable dashboards of IBM SevOne, which enhance network monitoring and team collaboration effectively.
  • Users value the customizable dashboards in IBM SevOne, enhancing their ability to monitor network health effectively.
Cons
  • Users find the steep learning curve of IBM SevOne challenging, requiring significant time and effort to master.
  • Users find the difficult learning curve of IBM SevOne challenging, requiring significant effort to master the platform.
  • Users find the complex setup of IBM SevOne to be a significant hurdle, requiring considerable effort and expertise.
  • Users find the steep learning curve challenging, making initial setup and configuration time-consuming and complex.
  • Users find the complex configuration of IBM SevOne overwhelming, making it difficult for newcomers to navigate effectively.

What Are Recent G2 Reviews of IBM SevOne?

What Are G2 Users Discussing About IBM SevOne?

Palo Alto Cortex XSIAM

Product Description: Palo Alto Networks' Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.

Average Rating: 4.4/5.0

Total Reviews: 103

How Do G2 Users Rate Palo Alto Cortex XSIAM?

  • Anomaly Detection: 9.2/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 8.8/10)
  • Network Visibility: 8.9/10 (Category avg: 9.0/10)
  • Metadata Management: 9.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Palo Alto Cortex XSIAM?

  • Seller: Palo Alto Networks
  • Company Website:
  • Year Founded: 2005
  • HQ Location: Santa Clara, CA
  • Twitter: @PaloAltoNtwks
    128,951 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,492 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 39% Large, 35% Medium

What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

AI-generated summary from verified user reviews

Pros
  • Users value the best-in-class log management of Palo Alto Cortex XSIAM, benefiting from its effective alerting and integration features.
  • Users find the user-friendly dashboard of Palo Alto Cortex XSIAM essential for monitoring and understanding alerts effectively.
  • Users value the real-time monitoring capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
  • Users value the simple and user-friendly interface of Palo Alto Cortex XSIAM, making monitoring effortless.
  • Users value the good dashboard creation tools in Palo Alto Cortex XSIAM, enhancing ease of use and implementation.
Cons
  • Users note that Palo Alto Cortex XSIAM requires significant resources, impacting implementation time and increasing infrastructure costs.
  • Users find the complexity of implementation for Palo Alto Cortex XSIAM to be time-consuming and resource-intensive.
  • Users find the cost of Palo Alto Cortex XSIAM to be high, especially for smaller businesses.
  • Users face dashboard issues with XSIAM, finding it difficult to monitor assets and navigate the interface.
  • Users face difficult setup issues with Palo Alto Cortex XSIAM, requiring expertise and extensive time for initial implementation.

What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

Rapid7 Next-Gen SIEM

Rapid7 InsightIDR is a SaaS SIEM for modern threat detection and response. InsightIDR enables security analysts to work more efficiently and effectively, by unifying diverse data sources, providing early and reliable out of the box detections, and delivering rich visual investigations and automation to expedite response. With a lightweight cloud deployment and intuitive UI and onboarding experience, InsightIDR customers recognize an accelerated return on their investment and start seeing valuable insights from Day 1. With InsightIDR, teams can advance their threat detection and response program without adding headcount.

Average Rating: 4.4/5.0

Total Reviews: 68

How Do G2 Users Rate Rapid7 Next-Gen SIEM?

  • Anomaly Detection: 8.0/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 8.8/10)
  • Network Visibility: 9.0/10 (Category avg: 9.0/10)
  • Metadata Management: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind Rapid7 Next-Gen SIEM?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    8,746 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 67% Medium, 31% Large

What Do G2 Reviewers Say About Rapid7 Next-Gen SIEM?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Rapid7 Next-Gen SIEM unparalleled, with simple implementation and clear alerts.
  • Users appreciate the easy integrations of Rapid7 Next-Gen SIEM, benefiting from pre-built connections with numerous third-party tools.
  • Users appreciate the pre-built integrations of Rapid7 Next-Gen SIEM, making it easy to connect with various third-party tools.
  • Users appreciate the seamless integration of UEBA and deception tools for efficient threat detection across the network.
  • Users value the excellent visibility provided by Rapid7 Next-Gen SIEM, enabling easy log searches and clear alerts.
Cons
  • Users find the limited features of Rapid7 Next-Gen SIEM restrict overall functionality and alert setup capabilities.
  • Users find the alerting issues cumbersome, particularly when trying to create and set up pattern-based alerts.
  • Users find the limited alert management capabilities frustrating, complicating the creation of effective and timely alerts.
  • Users find the difficult customization in Rapid7 Next-Gen SIEM limits their ability to create effective alerts.
  • Users find the difficult setup of Rapid7 Next-Gen SIEM hinders effective alert creation and pattern configurations.

What Are Recent G2 Reviews of Rapid7 Next-Gen SIEM?

What Are G2 Users Discussing About Rapid7 Next-Gen SIEM?

Datadog

Datadog is the monitoring, security and analytics platform for developers, IT operations teams, security engineers and business users in the cloud age. The SaaS platform integrates and automates infrastructure monitoring, application performance monitoring and log management to provide unified, real-time observability of our customers' entire technology stack. Datadog is used by organizations of all sizes and across a wide range of industries to enable digital transformation and cloud migration, drive collaboration among development, operations, security and business teams, accelerate time to market for applications, reduce time to problem resolution, secure applications and infrastructure, understand user behavior and track key business metrics.

Average Rating: 4.4/5.0

Total Reviews: 720

How Do G2 Users Rate Datadog?

  • Anomaly Detection: 8.0/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 8.8/10)
  • Network Visibility: 8.0/10 (Category avg: 9.0/10)
  • Metadata Management: 6.7/10 (Category avg: 8.4/10)

Who Is the Company Behind Datadog?

  • Seller: Datadog
  • Company Website:
  • Year Founded: 2010
  • HQ Location: New York
  • Twitter: @datadoghq
    51,207 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10,780 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, DevOps Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Medium, 34% Large

What Do G2 Reviewers Say About Datadog?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Datadog, enjoying intuitive dashboard creation and straightforward implementation.
  • Users appreciate the intuitive monitoring features of Datadog, enabling easy integration and insightful data analysis.
  • Users value the real-time monitoring capabilities of Datadog, enhancing oversight across various applications and infrastructures.
  • Users appreciate the user-friendly interface and robust integration capabilities of Datadog for effective monitoring.
  • Users value the intuitive dashboard creation in Datadog, which enhances monitoring and analysis efficiency.
Cons
  • Users find Datadog's pricing to be expensive, suggesting it should be more affordable given its features.
  • Users find pricing issues with Datadog, citing rapidly escalating costs and high subscription fees as concerns.
  • Users find the steep learning curve challenging, especially with rapidly evolving features and required knowledge.
  • Users find the costs to be unpredictable and excessively high, especially with data storage and additional features.
  • Users find learning difficulty in Datadog, noting that new users may require training to understand its complexities.

What Are Recent G2 Reviews of Datadog?

What Are G2 Users Discussing About Datadog?

Trellix Network Detection and Response (NDR)

Trellix Network Detection and Response (NDR) converts passive network monitoring into proactive defense. It inspects all hybrid cloud traffic—north-south and east-west—to eliminate blind spots, uncover unmanaged devices, and detect lateral threat movement. Central to its capability is Trellix Wise, a built-in generative AI engine that automates complex forensics, triage, and threat investigations. Wise leverages specialized AI agents to turn cryptic telemetry into plain-language narratives, draft automated remediation steps, and prioritize high-fidelity alerts. This reduces Mean Time to Detect and Respond (MTTD/MTTR) by 50%. Trellix NDR runs advanced machine learning and Trellix Wise workflows locally in air-gapped environments. It also delivers "Active NDR" via native Intrusion Prevention System (IPS) engines to actively block threats at line rate. Correlating endpoints and email data, it stops adversaries before damage is done.

Average Rating: 4.1/5.0

Total Reviews: 72

How Do G2 Users Rate Trellix Network Detection and Response (NDR)?

  • Anomaly Detection: 8.9/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 8.8/10)
  • Network Visibility: 8.9/10 (Category avg: 9.0/10)
  • Metadata Management: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind Trellix Network Detection and Response (NDR)?

  • Seller: Trellix
  • Company Website:
  • Year Founded: 2004
  • HQ Location: Plano, TX
  • Twitter: @Trellix
    241,168 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,811 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 38% Medium, 32% Small

What Are Recent G2 Reviews of Trellix Network Detection and Response (NDR)?

What Are G2 Users Discussing About Trellix Network Detection and Response (NDR)?

FortiAnalyzer

FortiAnalyzer is a comprehensive security operations platform designed to streamline and enhance the efficiency of security teams. By integrating Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) capabilities, it provides centralized logging, reporting, and real-time threat intelligence. This unified approach enables organizations to proactively identify and remediate risks, ensuring complete visibility across the entire attack surface. Key Features and Functionality: - Centralized Logging and Reporting: Aggregates logs from multiple Fortinet devices, offering a consolidated view of network activity. - Advanced Threat Detection: Utilizes AI-driven automation to detect and respond to threats swiftly, reducing the need for extensive personnel or multiple security tools. - Scalable Data Lake: Supports large-scale data ingestion and storage, accommodating the needs of growing organizations. - Real-Time Threat Intelligence: Integrates with global Indicators of Compromise (IOC) feeds to provide actionable analytics and insights into emerging threats. - Automated Incident Response: Employs SOAR capabilities to automate response workflows, minimizing manual intervention and accelerating remediation processes. Primary Value and User Solutions: FortiAnalyzer empowers resource-constrained security teams to operate at the level of large, well-resourced operations without the associated complexity. By consolidating multiple security functions into a single platform, it reduces operational overhead, enhances threat detection and response times, and provides comprehensive visibility into network security. This holistic approach enables organizations to effectively manage hybrid environments, mitigate risks, and maintain compliance with industry standards.

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate FortiAnalyzer?

  • Anomaly Detection: 8.4/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 8.8/10)
  • Network Visibility: 9.2/10 (Category avg: 9.0/10)
  • Metadata Management: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind FortiAnalyzer?

  • Seller: Fortinet
  • Year Founded: 2000
  • HQ Location: Sunnyvale, CA
  • Twitter: @Fortinet
    151,422 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16,564 employees on LinkedIn®
  • Ownership: NASDAQ: FTNT

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Large, 35% Medium

What Do G2 Reviewers Say About FortiAnalyzer?

AI-generated summary from verified user reviews

Pros
  • Users find the centralized log collection and analysis features of FortiAnalyzer extremely beneficial for security management.
  • Users value the log collection and analysis capabilities of FortiAnalyzer, enhancing security management and insight.
  • Users find the data visualization of FortiAnalyzer essential for log collection and effective analysis in security solutions.
  • Users value the easy integrations of FortiAnalyzer, allowing seamless connection with other solutions for enhanced functionality.
  • Users find FortiAnalyzer to be a valuable security solution for centralized log collection and analysis.
Cons
  • Users find the complex interface of FortiAnalyzer challenging, leading to difficulties in navigation and usability.
  • Users find the complex UI/UX of FortiAnalyzer difficult to navigate and understand effectively.
  • Users find the difficult learning curve of FortiAnalyzer challenging due to poor UI/UX design.
  • Users often face integration issues with FortiManager, complicating their experience with FortiAnalyzer.
  • Users find the UI/UX difficult to understand, leading to frustration and a challenging user experience.

What Are Recent G2 Reviews of FortiAnalyzer?

What Are G2 Users Discussing About FortiAnalyzer?

Faddom

Faddom is an agentless Application Dependency Mapping (ADM) platform designed for complex hybrid environments. In less than 60 minutes, Faddom automatically discovers and continuously maps infrastructure, business applications, and dependencies across on-premises and cloud environments without deploying agents. By enriching infrastructure visibility with real-time business application context, organizations gain actionable insights into how their environments truly operate. Faddom eliminates the need for outdated spreadsheets, siloed visibility, and complex deployments by creating a continuously updated single source of truth for Security, Cloud, and IT teams. Organizations worldwide use Faddom to simplify change management, accelerate cloud and data center migration planning, strengthen security posture, support compliance initiatives, and improve operational resilience through accurate, real-time infrastructure visibility.

Average Rating: 4.5/5.0

Total Reviews: 108

How Do G2 Users Rate Faddom?

  • Anomaly Detection: 7.7/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.8/10)
  • Network Visibility: 9.3/10 (Category avg: 9.0/10)
  • Metadata Management: 7.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Faddom?

  • Seller: Faddom
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Tel Aviv
  • Twitter: @faddommapping
    57 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    76 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Hospital & Health Care
  • Company Size: 44% Large, 41% Medium

What Do G2 Reviewers Say About Faddom?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use and intuitive UI of Faddom, facilitating efficient network mapping and troubleshooting.
  • Users praise Faddom for its user-friendly interface and efficient network mapping, greatly enhancing their network management capabilities.
  • Users value the effective tracking capabilities of Faddom, aiding in network monitoring and asset management.
  • Users commend Faddom's exceptional customer support, highlighting their availability and effectiveness in assisting with onboarding and troubleshooting.
  • Users appreciate Faddom's integration options, which streamline deployment and enhance visibility across networks and systems.
Cons
  • Users note a learning difficulty with Faddom's terminology and features, requiring time and effort to master.
  • Users find the limited features of Faddom restrict usability, particularly in complex environments requiring deeper customization.
  • Many users find Faddom's pricing challenging, especially for smaller organizations with limited budgets and growing needs.
  • Users face integration issues with Faddom, as it lacks native remediation and struggles in complex environments.
  • Users face a steep learning curve with Faddom's terminology and initial setup, affecting ease of use.

What Are Recent G2 Reviews of Faddom?

What Are G2 Users Discussing About Faddom?

Arista NDR

Arista NDR is the only advanced network traffic analysis company that delivers a privacy-aware solution capable of detecting and visualizing behavioral, mal-intent and compliance incidents with full forensics context. Powered by Ava, Arista's security expert system, the Arista NDR Platform combines federated machine learning, threat intelligence and human expertise. The platform analyzes billions of communications to autonomously discover, profile and classify every device, user and application on any network. Through automated hunting and investigation, Arista NDR uncovers malicious intent from insiders and external attackers alike. The company is ranked #1 for time to value because of its frictionless approach that delivers answers rather than alerts.

Average Rating: 4.3/5.0

Total Reviews: 21

How Do G2 Users Rate Arista NDR?

  • Anomaly Detection: 8.9/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.8/10)
  • Network Visibility: 8.3/10 (Category avg: 9.0/10)
  • Metadata Management: 8.8/10 (Category avg: 8.4/10)

Who Is the Company Behind Arista NDR?

  • Seller: Arista Networks
  • Year Founded: 2004
  • HQ Location: Santa Clara, US
  • Twitter: @arista_channels
    2,437 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,823 employees on LinkedIn®
  • Ownership: NYSE:ANET

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 38% Medium, 38% Small

What Are Recent G2 Reviews of Arista NDR?

Coralogix

Coralogix is a modern, full-stack observability platform transforming how businesses process and understand their data. Our unique architecture powers in-stream analytics without reliance on indexing or hot storage. We specialize in comprehensive monitoring of logs, metrics, trace and security events, enhancing operational efficiency and reducing total cost of ownership by up to 70%. Coralogix stands out for its simple pricing model, based solely on data volume ingested and retained, and offers free, fast customer support with less than 30 second response time and 1 hour resolution time. Our platform covers the entire range of observability with features such as APM, RUM, SIEM, Kubernetes monitoring and more, all streamlined for quick integration and immediate value. Components within the stream store the system state to provide stateful insights and real-time alerting without ever needing to index the data — so there are never any trade-offs to achieve observability. Once ingested, parsed, and enriched, data is written remotely to an archive bucket controlled by the client. The archive can be queried directly at any time, from the platform UI or via CLI, giving users infinite retention with full control over, and access to, their data. View and query your data from any dashboard using any syntax. Coralogix has successfully completed relevant security and privacy compliances by BDO including GDPR, SOC 2, PCI, HIPAA, and ISO 27001/27701.

Average Rating: 4.5/5.0

Total Reviews: 368

How Do G2 Users Rate Coralogix?

  • Anomaly Detection: 8.7/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.8/10)
  • Network Visibility: 8.5/10 (Category avg: 9.0/10)
  • Metadata Management: 8.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Coralogix?

  • Seller: Coralogix
  • Company Website:
  • Year Founded: 2014
  • HQ Location: San Francisco, CA
  • Twitter: @Coralogix
    4,102 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    591 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, DevOps Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 55% Medium, 33% Large

What Do G2 Reviewers Say About Coralogix?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Coralogix, highlighting its simple setup and efficient integrations.
  • Users value the ease of log monitoring and seamless integration, enhancing overall observability and support responsiveness.
  • Users value the integration of logs, metrics, and alerts, enhancing efficiency in root-cause analysis and monitoring.
  • Users commend the exceptional customer support of Coralogix, ensuring quick resolutions and a smooth experience.
  • Users value the real-time monitoring of Coralogix, enhancing their understanding of user behavior and improving incident response.
Cons
  • Users find that the learning curve is steep for beginners, making navigation and understanding features challenging.
  • Users experience slow performance with Coralogix, leading to frustration due to delayed log fetching and UI loading.
  • Users find the difficult learning curve of Coralogix challenging, especially for beginners navigating complex options.
  • Users find the missing feature for downloading log results a significant limitation in Coralogix's functionality.
  • Users find the learning difficulty of Coralogix challenging, especially when navigating advanced features and the overwhelming UI.

What Are Recent G2 Reviews of Coralogix?

Darktrace / HYBRID NETWORK

Darktrace / HYBRID NETWORK uses Adaptive AI to continuously learn behavior across your infrastructure, combining NDR, CDR, OT security, ITDR, exposure management, attack path modelling and forensic investigations into a single solution. - Unify visibility - Detect and contain known, novel and insider threats - AI-led triage and investigations - Increase resilience Named a Leader in the 2025 and 2026 Gartner® Magic Quadrant™ for NDR and the only Visionary in the 2025 Gartner® Magic Quadrant™ for CPS.

Average Rating: 4.4/5.0

Total Reviews: 47

How Do G2 Users Rate Darktrace / HYBRID NETWORK?

  • Anomaly Detection: 9.2/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 8.8/10)
  • Network Visibility: 9.6/10 (Category avg: 9.0/10)
  • Metadata Management: 9.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Darktrace / HYBRID NETWORK?

  • Seller: Darktrace
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Cambridgeshire, England
  • Twitter: @Darktrace
    18,177 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,597 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 63% Medium, 31% Large

What Do G2 Reviewers Say About Darktrace / HYBRID NETWORK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent monitoring capabilities of Darktrace, offering impressive visibility and efficient network analysis.
  • Users appreciate the self-learning AI technology of Darktrace/Network, effectively adapting to threats without extensive configuration.
  • Users commend Darktrace's rapid threat detection, ensuring robust security with minimal manual intervention for maximum efficiency.
  • Users commend the responsive customer support of Darktrace/Network, enhancing learning and facilitating efficient troubleshooting.
  • Users highlight the autonomous AI-driven cybersecurity of Darktrace, which effectively detects and responds to threats in real time.
Cons
  • Users report a significant learning curve with Darktrace as the AI generates numerous alerts during initial setup.
  • Users note that the product can be expensive, particularly for smaller organizations with constrained budgets and significant training costs.
  • Users experience alert issues with Darktrace, needing extensive manual tuning to manage false positives during the learning phase.
  • Users find the complex setup of Darktrace challenging, requiring skilled teams for effective management and configuration.
  • Users experience false positives occasionally, requiring IT support to resolve issues affecting network connectivity.

What Are Recent G2 Reviews of Darktrace / HYBRID NETWORK?

What Are G2 Users Discussing About Darktrace / HYBRID NETWORK?

Progress WhatsUp Gold

WhatsUp Gold is an IT infrastructure monitoring software designed to help users identify and resolve network issues swiftly, often before they impact end users. This solution provides comprehensive visibility into network performance and availability, enabling IT professionals to maintain optimal operations across their infrastructure. With its interactive mapping interface, WhatsUp Gold allows users to visualize the status of all devices connected to their network, making it easier to monitor both on-premise and cloud-based resources. Targeted primarily at IT administrators and network engineers, WhatsUp Gold is particularly beneficial for organizations that rely heavily on network performance for their daily operations. Its user-friendly design caters to both seasoned professionals and those new to network management, offering a range of features that streamline the monitoring process. The software is designed to support various use cases, from small businesses needing basic monitoring capabilities to large enterprises requiring advanced network management solutions. One of the standout features of WhatsUp Gold is its customizable drag-and-drop dashboards, which provide users with the flexibility to tailor their monitoring experience according to specific needs. These dashboards present real-time data on device status and performance, allowing users to quickly assess the health of their network. Additionally, the software’s automatic discovery and mapping capabilities enable users to visualize their entire network topology, ensuring that no device goes unnoticed during monitoring. WhatsUp Gold also emphasizes optimization, helping users manage network traffic and bandwidth utilization effectively. By providing actionable insights and unified views of network performance, the software empowers IT teams to troubleshoot issues efficiently. The ability to identify and resolve network and server problems proactively not only enhances operational efficiency but also improves overall user satisfaction by minimizing downtime. In summary, WhatsUp Gold offers a robust and interactive solution for IT infrastructure monitoring, combining ease of use with powerful features. Its focus on real-time visibility, customization, and proactive troubleshooting makes it a valuable tool for organizations looking to enhance their network management capabilities.

Average Rating: 4.4/5.0

Total Reviews: 380

How Do G2 Users Rate Progress WhatsUp Gold?

  • Anomaly Detection: 8.2/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 8.8/10)
  • Network Visibility: 8.7/10 (Category avg: 9.0/10)
  • Metadata Management: 8.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Progress WhatsUp Gold?

  • Seller: Progress Software
  • Company Website:
  • Year Founded: 1981
  • HQ Location: Burlington, MA.
  • Twitter: @ProgressSW
    48,773 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4,242 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Network Engineer, Network Administrator
  • Top Industries: Information Technology and Services, Education Management
  • Company Size: 58% Medium, 27% Large

What Do G2 Reviewers Say About Progress WhatsUp Gold?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Progress WhatsUp Gold, appreciating its intuitive interface and simple setup process.
  • Users love the real-time visibility provided by WhatsUp Gold’s interactive network maps and intuitive dashboards.
  • Users value the real-time visibility and ease of use provided by Progress WhatsUp Gold for network performance monitoring.
  • Users value the timely and proactive alert notifications of Progress WhatsUp Gold, enhancing issue detection and network reliability.
  • Users appreciate the intuitive user interface of Progress WhatsUp Gold, enhancing real-time network monitoring and management.
Cons
  • Users find the cost of Progress WhatsUp Gold to be high, especially for smaller organizations and add-ons.
  • Users find the poor interface design of Progress WhatsUp Gold can be clunky and outdated in complex setups.
  • Users find the complex setup process of Progress WhatsUp Gold to be cumbersome and challenging, especially for advanced configurations.
  • Users note a steep learning curve with Progress WhatsUp Gold, particularly for advanced configuration and initial setup.
  • Users find the interface outdated, especially when managing complex environments, impacting overall user experience.

What Are Recent G2 Reviews of Progress WhatsUp Gold?

What Are G2 Users Discussing About Progress WhatsUp Gold?

Kentik

Kentik is the network observability company. Our platform is a must-have for the network front line for companies that depend on a highly performant network. Network and cloud professionals turn to Kentik to plan, run, and fix any network, relying on our granularity, AI-driven insights, and insanely fast search. Kentik makes sense of network, cloud, host, and container flow, internet routing, DDoS defense, performance tests, and network metrics.

Average Rating: 4.8/5.0

Total Reviews: 23

How Do G2 Users Rate Kentik?

  • Anomaly Detection: 9.1/10 (Category avg: 8.7/10)
  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 8.8/10)
  • Network Visibility: 9.6/10 (Category avg: 9.0/10)
  • Metadata Management: 8.5/10 (Category avg: 8.4/10)

Who Is the Company Behind Kentik?

  • Seller: Kentik
  • Year Founded: 2014
  • HQ Location: San Francisco, CA
  • Twitter: @kentikinc
    9,472 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    253 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Telecommunications, Internet
  • Company Size: 39% Large, 35% Medium

What Do G2 Reviewers Say About Kentik?

AI-generated summary from verified user reviews

Pros
  • Users find Kentik's interface to be powerful and easy to use, facilitating quick insights and customizable reporting.
  • Users appreciate the insightful analysis provided by Kentik, facilitating effective monitoring and reporting on network interactions.
  • Users value the insightful dashboards of Kentik, enhancing their ability to analyze flow and graphics efficiently.
  • Users find Kentik's easy implementation allows for quick insights and efficient report generation, enhancing network management.
  • Users value the management ease of Kentik, enabling quick insights and customizable reporting for effective network monitoring.
Cons
  • Users note the data limitations requiring reliance on their own network, which limits broader insights and interactions.
  • Users find the difficult learning curve of Kentik requires significant time to fully understand its processes.
  • Users note a significant learning curve, requiring time to grasp Kentik's features and processes effectively.

What Are Recent G2 Reviews of Kentik?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024