Arbor Sightline (formerly Arbor SP) is a network behavior analytics platform developed by Arbor Networks, now owned and supported by NETSCOUT.
N/A
ManageEngine NetFlow Analyzer
Score 9.4 out of 10
N/A
NetFlow Analyzer is a complete bandwidth monitoring tool that utilizes flow technology to monitor and analyze network bandwidth usage. It helps users identify and avoid bandwidth delays and bottlenecks with customized reports, and set threshold-based email and SMS alerts to help understand the severity of an issue. This analytics tool detects, diagnoses, and troubleshoots network anomalies and zero-day intrusions, and plans future bandwidth needs based on application growth to…
Arbor has the propensity to deal with even the larger firms. I have been using it for a year span and I don’t have any such complaint which is affecting us in a bad way. I can recommend this to all the companies who want to have a good network behavior analysis and to monitor the problems if there is any chance of it to occur and which has the potential to affect the whole working environment of the company.
Identifying network traffic anomalies. Identifying applications, devices, or users that are utilizing high bandwidth. Capacity planning for network links and internet circuits. Detecting potential security threats or breaches. Network performance and troubleshooting. Reporting network utilization.
Arbor's layer 7 countermeasures are very good out of the box, but it is very easy to reconfigure values and see the impact in real-time.
Peakflow SP provides fairly detailed traffic analysis and breakdown for top-N data such as top talkers, top ASNs, top ports and so on. They offer "SP Insight" as a product to build in more powerful reporting on the already-collected metrics with an interface very similar to Kibana or one of its many forks. We are not licensed for that so I can't speak to its capabilities.
Arbor allows for a good amount of automation. Fast flood detection ensures that if pre-determined thresholds are quickly exceeded, preconfigured mitigations can be started or in the event of an extremely large volumetric attack you can trigger an Arbor Cloud (sold separately) mitigation or a remotely-triggered blackhole announcement to drop traffic to the attacked destination IP address(es) upstream.
ATAC (Arbor support) is very helpful. The level of support our organization maintains covers ATAC performing all update functions to all Arbor appliances - SP and TMS.
Arbor is a highly expensive company. this was the major reason behind not going for the Arbor sightline in the first place. Although its features are good but the cost is unjustifiable.
The implementation and the understanding of this tool are full of complexity and perplexity.
I am looking forward to having a new update on it. They used to update their versions quite frequently but it's been a long time they haven’t updated or maybe it is not in their priority lists right now.
The support is always on point, fast, reliable, and their employees go above and beyond to help when we need it. I have yet to call them on any product we use and not get the issue resolved in a fast and timely manner. Also, they are also very pleasant while on the phone and/or in teh email chain. Overall I just couldn't ask for better.
We evaluated Corero and a number of external scrubbing services. In the POC, we found Corero's mitigation capabilities to extremely limited beyond blocking common traffic types at preconfigured rates. It's not impossible to configure custom mitigation methods and countermeasures, but it requires a deep understanding of BPF and bytecode, where Arbor is checkboxes, radio buttons, and dialog buttons that all sit next to a graph showing traffic dropped and permitted by the current settings. I'm not going to enumerate each of the cloud services evaluated because the decision came down to the same reasoning. The amount of traffic we receive is enough that it would be prohibitively expensive for our use case.
Each of these solutions does what they aim to do. Based off of cost and need, ManageEngine fit better with our organization. We already use multiple ManageEngine products so bundling was a no brainer.