What do you like best?
One of the things that I love about ExtraHop is the ability to go back in time to identify issues. We've all gotten that email where someone asks for help: "There was an issue on server2 last night, but it is working now. What happened?" Usually, there is a very slim chance of answering that question unless the issue happens again. With ExtraHop, I can go back to the exact time and see that the server started taking 2 seconds to return a response when it usually takes 10ms. Oh, and this happens every Tuesday night at the same time, is there a backup scheduled? When brought in to help troubleshoot an issue, I often feel like I understand an application better than the application owners because of all the visibility that I have at my fingers.
What do you dislike?
We had to get professional services to get us started with building out dashboards. Once built, we just copy-paste other applications using the same template. If there were some pre-canned dashboards to help get us started, we could have started using them much sooner.
What problems are you solving with the product? What benefits have you realized?
Performance troubleshooting was the driving force behind the purchase, but the Reveal(x) platform has boosted our security team due to the historical lookback capability and real-time alerting of potential security issues. While all security products require tuning, ExtraHop seems to do a better job of filtering out the noise, which allows us to spend our time chasing down actual issues instead of using yet another tool.