# Mejores soluciones de software de gestión de información y eventos de seguridad (SIEM)

## How Many Software de Gestión de Información y Eventos de Seguridad (SIEM) Products Does G2 Track?

**Total Products under this Category:** 123

### Category Stats (Aug 2026)

- **Average Rating:** 4.46/5 (↑0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+23.8%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank Software de Gestión de Información y Eventos de Seguridad (SIEM) Products?

**Por qué puedes confiar en las clasificaciones de software de G2:**

- 30 Analistas y Expertos en Datos
- 6,000+ Reseñas auténticas
- 123+ Productos
- Clasificaciones Imparciales

Las clasificaciones de software de G2 se basan en reseñas de usuarios verificadas, moderación rigurosa y una metodología de investigación consistente mantenida por un equipo de analistas y expertos en datos. Cada producto se mide utilizando los mismos criterios transparentes, sin colocación pagada ni influencia del proveedor. Aunque las reseñas reflejan experiencias reales de los usuarios, que pueden ser subjetivas, ofrecen información valiosa sobre cómo funciona el software en manos de profesionales. Juntos, estos aportes impulsan el G2 Score, una forma estandarizada de comparar herramientas dentro de cada categoría.

## G2 Grid® for Software de Gestión de Información y Eventos de Seguridad (SIEM)
 ![G2 Grid® for Software de Gestión de Información y Eventos de Seguridad (SIEM) plotting products by satisfaction and market presence](https://www.g2.com/es/categories/security-information-and-event-management-siem/grids.png?focus%5B%5D=30500&focus%5B%5D=68606&focus%5B%5D=1430041&focus%5B%5D=5691&focus%5B%5D=10436&focus%5B%5D=53174&focus%5B%5D=122123&focus%5B%5D=1408626)

Highlighted products: Google Security Operations, CrowdStrike Falcon Endpoint Protection Platform, Palo Alto Cortex XSIAM, ManageEngine ADAudit Plus, Sumo Logic, Todyl Security Platform, Microsoft Sentinel, y Huntress Managed SIEM.

Underlying data: [Grid® JSON](https://www.g2.com/es/categories/security-information-and-event-management-siem/grids.json?focus%5B%5D=google-security-operations&focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=manageengine-adaudit-plus&focus%5B%5D=sumo-logic&focus%5B%5D=todyl-security-platform&focus%5B%5D=microsoft-sentinel&focus%5B%5D=huntress-managed-siem)

**Sponsored**

### Graylog

Graylog es una solución de gestión de registros e información de seguridad y gestión de eventos (SIEM) diseñada para ayudar a los equipos de seguridad y TI a detectar, investigar y responder a posibles amenazas con mayor eficiencia. Al aprovechar tecnologías avanzadas como la gestión de registros escalable, la correlación de datos en tiempo real y la inteligencia artificial (IA) explicable, Graylog transforma conjuntos de datos complejos en información procesable, permitiendo a las organizaciones tomar decisiones informadas rápidamente. La plataforma atiende a una amplia gama de usuarios, desde pequeñas empresas hasta grandes corporaciones, todos los cuales requieren una mayor visibilidad y control sobre sus entornos de TI. Graylog es particularmente beneficioso para los analistas de seguridad y profesionales de TI que necesitan examinar grandes cantidades de datos de registros para identificar anomalías, rastrear incidentes y garantizar el cumplimiento de varios estándares regulatorios. Su interfaz fácil de usar y sus potentes herramientas analíticas agilizan el proceso de detección y respuesta a amenazas, convirtiéndolo en un activo esencial para las organizaciones que buscan fortalecer su postura de ciberseguridad. Las características clave de Graylog incluyen flujos de trabajo automatizados que simplifican tareas repetitivas, capacidades de detección de anomalías que señalan patrones inusuales en los datos e investigaciones guiadas que ayudan a los usuarios a navegar por incidentes de seguridad complejos. La plataforma también ofrece resúmenes impulsados por IA que destilan información crítica, permitiendo a los analistas centrarse en problemas de alta prioridad sin verse abrumados por datos excesivos. Estas características colectivamente mejoran la velocidad y precisión de las respuestas a amenazas, asegurando que los equipos de seguridad mantengan el control de sus entornos. La versatilidad de Graylog es evidente en su gama de productos, que incluye Graylog Security, Enterprise, API Security y soluciones Open. Cada producto está diseñado para satisfacer las necesidades específicas de diferentes organizaciones, proporcionando claridad y contexto a través de diversos paisajes operativos. Con una base de usuarios de más de 60,000 organizaciones a nivel mundial, Graylog se ha establecido como un socio de confianza en el ámbito de la ciberseguridad y la gestión de registros, ayudando a los equipos a navegar por las complejidades de las amenazas modernas mientras mantienen un enfoque claro en sus objetivos.

[Visitar sitio web](https://www.g2.com/es/external_clickthroughs/record?secure%5Bad_program%5D=paid_promo&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1081&secure%5Bchosen_at%5D=2026-08-15T09%3A58%3A39Z&secure%5Bmedium%5D=sponsored&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=42017&secure%5Bresource_id%5D=1081&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fes%2Fcategories%2Fsecurity-information-and-event-management-siem&secure%5Btoken%5D=70cd21934b72d5858539e191c69bfed31888bbb3db1bb6045a39eef2197a04c9&secure%5Burl%5D=https%3A%2F%2Fwww.graylog.org%2Foverview&secure%5Burl_type%5D=paid_promos)

### [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)

Google Security Operations offers a unified experience across SIEM, SOAR, and threat intelligence to drive better detection, investigation, and response. Collect security telemetry data, apply threat intel to identify high priority threats, drive response with playbook automation, case management, and collaboration. It also provides Gemini-native agentic defense to help autonomously handle workflows like alert triage, threat hunting, and detection engineering. Google Security Operations also supports AI Threat Defense to monitor, detect, and respond to threats from code you do not own or cannot patch.

**Average Rating:** 4.4/5.0

**Total Reviews:** 88

#### How Do G2 Users Rate Google Security Operations?

- **Activity Monitoring:** 9.6/10 (Category avg: 9.1/10)
- **Data Examination:** 9.3/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.4/10 (Category avg: 8.7/10)
- **Log Management:** 9.6/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Google Security Operations?

- **Seller:** [Google](https://www.g2.com/sellers/google)
- **Year Founded:** 1998
- **HQ Location:** Mountain View, CA
- **Twitter:** @google  
31,899,995 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fe4a5936665c9702418dd53c477fef5a7baea08078bb117ed67e966fc581b9ec&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1441%2F&secure%5Burl_type%5D=linkedin_company_website)  
341,888 employees on LinkedIn®
- **Ownership:** NASDAQ:GOOG

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 41% Medium, 34% Large

#### What Do G2 Reviewers Say About Google Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **excellent cybersecurity features** of Google Security Operations, appreciating its ease of use and scalability.
- Users find Google Security Operations to be **very easy to use** , effectively detecting threats with seamless integration.
- Users appreciate the **efficient threat detection** capabilities of Google Security Operations, enhancing security and response times.
- Users value the **comprehensive security** features of Google Security Operations for effective threat detection and response.
- Users value the **easy integrations** of Google Security Operations, enhancing their overall security management experience.

##### Cons

- Users find Google Security Operations to be **costly and complex** , posing challenges for both setup and ongoing maintenance.
- Users report a **steep learning curve** with Google Security Operations, making effective utilization challenging for some organizations.
- Users find the **implementation complexity** of Google Security Operations challenging, requiring time and resources for effective use.
- Users find the **learning difficulty** of Google Security Operations to be a barrier due to complex features and configuration.
- Users find **limited customization** in Google Security Operations hinders adaptability and affects overall user experience.

#### What Are Recent G2 Reviews of Google Security Operations?

**["Unified, AI-Powered Security Operations with Fast Performance and Seamless Google Integrations"](https://www.g2.com/survey_responses/google-security-operations-review-13254539)**

**Rating:** 4.0/5.0 stars

_— Hatim B._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13254539)

**["Blazing-Fast Petabyte Log Search with Smooth Integrations and Smart Gemini Summaries"](https://www.g2.com/survey_responses/google-security-operations-review-13259660)**

**Rating:** 5.0/5.0 stars

_— Bilal M._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13259660)

### [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)

Organizations today face a serious challenge: managing numerous security vendors and tools while confronting an ever-evolving threat landscape. Sophisticated adversaries are becoming smarter, faster, and more evasive, launching complex attacks that can strike in minutes or even seconds. Traditional security approaches struggle to keep pace, leaving businesses vulnerable. The CrowdStrike Falcon Platform addresses this by offering a unified, cloud-native solution. It consolidates previously siloed security solutions and incorporates third-party data into a single platform with one efficient and resource-conscious agent, leveraging advanced AI and real-time threat intelligence. This approach simplifies security operations, speeds analyst decision making, and enhances protection to stop the breach, allowing organizations to reduce risk with less complexity and lower costs. CrowdStrike's Falcon Platform includes: - Endpoint Security: Secure the endpoint, stop the breach - Identify Protection: Identity is the front line, defend it - Next-Gen SIEM: The future of SIEM, today - Data Protection: Real-time data protection from endpoint to cloud - Exposure Management: Understand risk to stop breaches - Charlotte AI: Powering the next evolution of the SOC

**Average Rating:** 4.6/5.0

**Total Reviews:** 418

#### How Do G2 Users Rate CrowdStrike Falcon Endpoint Protection Platform?

- **Activity Monitoring:** 9.5/10 (Category avg: 9.1/10)
- **Data Examination:** 8.8/10 (Category avg: 8.6/10)
- **Ease of Use:** 9.0/10 (Category avg: 8.7/10)
- **Log Management:** 8.7/10 (Category avg: 9.1/10)

#### Who Is the Company Behind CrowdStrike Falcon Endpoint Protection Platform?

- **Seller:** [CrowdStrike](https://www.g2.com/sellers/crowdstrike)
- **Company Website:** www.crowdstrike.com
- **Year Founded:** 2011
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @CrowdStrike  
110,809 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f13dce0bc1628ccb762ed9d5acb4e0f0998a717639b903c3d3a271ef1da6ad7b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2497653%2F&secure%5Burl_type%5D=linkedin_company_website)  
11,343 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Analyst, Cyber Security Analyst
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 43% Large, 42% Medium

#### What Do G2 Reviewers Say About CrowdStrike Falcon Endpoint Protection Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **lightweight performance and powerful threat detection** of CrowdStrike Falcon, enhancing operational efficiency and security.
- Users value the **effective threat detection** of CrowdStrike Falcon, ensuring robust security without compromising system performance.
- Users appreciate the **ease of use** of CrowdStrike Falcon, benefiting from a lightweight and efficient security solution.
- Users appreciate the **advanced real-time threat protection** of CrowdStrike Falcon, enhancing security with minimal system impact.
- Users appreciate the **strong threat detection** of CrowdStrike Falcon, effectively catching both known and unknown threats seamlessly.

##### Cons

- Users find the **cost of CrowdStrike Falcon** to be high, especially for smaller teams needing advanced features.
- Users face **initial complexity and a steep learning curve** with CrowdStrike Falcon, making it challenging for non-technical personnel.
- Users find the **initial learning curve** of CrowdStrike challenging, especially transitioning from other systems like Splunk.
- Users find the **high cost and limited features** frustrating, particularly for smaller teams needing advanced capabilities.
- Users express concern over **pricing issues** , especially for smaller organizations needing advanced features with additional licensing costs.

#### What Are Recent G2 Reviews of CrowdStrike Falcon Endpoint Protection Platform?

**["Crowdstrike Falcon: Proactive Security, Steep Learning Curve"](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)**

**Rating:** 5.0/5.0 stars

_— Ansh B._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)

**["Lightweight Deployment, Powerful Incident Response Visibility"](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12952621)**

**Rating:** 5.0/5.0 stars

_— Anup A._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12952621)

#### What Are G2 Users Discussing About CrowdStrike Falcon Endpoint Protection Platform?

- [How does Falcon prevent work?](https://www.g2.com/discussions/how-does-falcon-prevent-work) - 1 comment
- [Does CrowdStrike offer MFA?](https://www.g2.com/discussions/does-crowdstrike-offer-mfa) - 1 comment
- [What is OverWatch in CrowdStrike?](https://www.g2.com/discussions/what-is-overwatch-in-crowdstrike) - 1 comment
- [How much does CrowdStrike Falcon X cost?](https://www.g2.com/discussions/how-much-does-crowdstrike-falcon-x-cost)
- [What is MDR detection?](https://www.g2.com/discussions/what-is-mdr-detection)

### [Palo Alto Cortex XSIAM](https://www.g2.com/products/palo-alto-cortex-xsiam/reviews)

Product Description: Palo Alto Networks' Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.

**Average Rating:** 4.5/5.0

**Total Reviews:** 85

#### How Do G2 Users Rate Palo Alto Cortex XSIAM?

- **Activity Monitoring:** 9.3/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.6/10 (Category avg: 8.7/10)
- **Log Management:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Palo Alto Cortex XSIAM?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Company Website:** www.paloaltonetworks.com
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 43% Large, 37% Medium

#### What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight **best-in-class log management** and effective alerting features, enhancing the overall usability and integration.
- Users appreciate the **user-friendly dashboards** of Palo Alto Cortex XSIAM, highlighting ease of understanding alerts and metrics.
- Users value the **real-time monitoring** capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
- Users appreciate the **user-friendly interface** of Palo Alto Cortex XSIAM, making monitoring and deployment seamless and efficient.
- Users appreciate the **good dashboard customization** in Palo Alto Cortex XSIAM, citing ease of use and integration.

##### Cons

- Users find the solution **resource intensive** , increasing costs and complicating implementation due to high hardware requirements.
- Users find the **complex implementation** of Palo Alto Cortex XSIAM time-consuming and resource-intensive, requiring significant technical expertise.
- Users find the **cost** of Palo Alto Cortex XSIAM to be higher than competitors, impacting affordability for smaller companies.
- Users report **dashboard issues** that hinder monitoring and create a messy interface, impacting usability and visibility.
- Users struggle with the **difficult setup** of Palo Alto Cortex XSIAM, finding it complex and time-consuming for implementation.

#### What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

**["Cortex XSIAM Streamlines Threat Detection and Security Monitoring"](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13245886)**

**Rating:** 4.5/5.0 stars

_— Jacob Karthigayan V._

[Read full review](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13245886)

**["Palo Alto Cortex XSIAM: Centralized Security with Powerful AI Automation"](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13174734)**

**Rating:** 4.5/5.0 stars

_— Tim H._

[Read full review](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13174734)

#### What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

- [What is IBM Security ReaQta used for?](https://www.g2.com/discussions/what-is-ibm-security-reaqta-used-for) - 1 comment
- [What does QRadar stand for?](https://www.g2.com/discussions/what-does-qradar-stand-for) - 1 comment, 1 upvote
- [How do I use IBM QRadar?](https://www.g2.com/discussions/how-do-i-use-ibm-qradar) - 1 comment
- [What are the key component of IBM QRadar?](https://www.g2.com/discussions/what-are-the-key-component-of-ibm-qradar) - 1 comment
- [What is IBM QRadar Siem?](https://www.g2.com/discussions/what-is-ibm-qradar-siem) - 1 comment

### [ManageEngine ADAudit Plus](https://www.g2.com/products/manageengine-adaudit-plus/reviews)

ADAudit Plus is a UBA-driven auditor that helps keep your AD, Azure AD, file systems (including Windows, NetApp, EMC, Synology, Hitachi, and Huawei), Windows servers, and workstations secure and compliant. ADAudit Plus transforms raw and noisy event log data into real-time reports and alerts, enabling you to get full visibility into activities happening across your Windows Server ecosystem in just a few clicks. More than 10,000 organizations across the world trust ADAudit Plus to: 1. Instantly notify them about changes in their Windows Server environments. 2. Continuously track Windows user logon activity. 3. Monitor the active and idle time spent by employees at their workstations. 4. Detect and troubleshoot AD account lockouts. 5. Provide a consolidated audit trail of privileged user activities across their domains. 6. Track changes and sign-ins in Azure AD. 7. Audit file accesses across Windows, NetApp, EMC, Synology, Hitachi, and Huawei file systems. 8. Monitor file integrity across local files residing on Windows systems. 9. Mitigate insider threats by leveraging UBA and response automation. 10. Generate audit-ready compliance reports for SOX, the GDPR, and other IT mandates.

**Average Rating:** 4.6/5.0

**Total Reviews:** 59

#### How Do G2 Users Rate ManageEngine ADAudit Plus?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.8/10 (Category avg: 8.7/10)
- **Log Management:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind ManageEngine ADAudit Plus?

- **Seller:** [Zoho](https://www.g2.com/sellers/zoho-b00ca9d5-bca8-41b5-a8ad-275480841704)
- **Year Founded:** 1996
- **HQ Location:** Austin, TX
- **Twitter:** @Zoho  
137,880 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9c8e45ddb296c32c6c5597ef9ba945c94562c57624f7bd1dcf1a9e9931f71578&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F38373%2F&secure%5Burl_type%5D=linkedin_company_website)  
30,766 employees on LinkedIn®
- **Phone:** +1 (888) 900-9646 

#### Who Uses This Product?

- **Top Industries:** Hospital & Health Care, Information Technology and Services
- **Company Size:** 59% Medium, 32% Large

#### What Do G2 Reviewers Say About ManageEngine ADAudit Plus?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **depth of reporting** in ADAudit Plus, enhancing visibility into AD environments with prebuilt options.
- Users value the **intuitive dashboard usability** of ADAudit Plus, offering easy navigation and comprehensive reporting options.
- Users appreciate the **easy setup and extensive reporting options** in ManageEngine ADAudit Plus for effective monitoring.
- Users value the **dashboard design** of ADAudit Plus for its comprehensive overview and detailed reporting options.
- Users value the **intuitive dashboard and extensive reporting options** in ADAudit Plus for effective Active Directory management.

##### Cons

- Users find the **limited alert levels** insufficient for fine-tuning notifications, despite helpful reporting options and search features.
- Users find the **data overload** from numerous reporting options overwhelming, making it hard to locate specific reports.
- Users find the product **expensive** , which impacts their overall satisfaction despite its features and capabilities.
- Users experience **false positives** with alerts, which could be improved by more granularity in severity levels.
- Users are frustrated with the **high resource usage** of ManageEngine ADAudit Plus, impacting system performance significantly.

#### What Are Recent G2 Reviews of ManageEngine ADAudit Plus?

**["Easy Setup, Powerful Reporting, and Great Value"](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-12999020)**

**Rating:** 4.5/5.0 stars

_— Ryan A._

[Read full review](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-12999020)

**["Great Tool for Active Directory Auditing and Investigations"](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-13001820)**

**Rating:** 5.0/5.0 stars

_— Jose R._

[Read full review](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-13001820)

#### What Are G2 Users Discussing About ManageEngine ADAudit Plus?

- [What does AD audit do?](https://www.g2.com/discussions/what-does-ad-audit-do)
- [Is Ad audit plus a SIEM?](https://www.g2.com/discussions/is-ad-audit-plus-a-siem)
- [What is ManageEngine Audit Plus?](https://www.g2.com/discussions/what-is-manageengine-audit-plus)
- [What does ADAudit plus do?](https://www.g2.com/discussions/what-does-adaudit-plus-do)

### [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)

Sumo Logic, Inc. unifies and analyzes enterprise data, translating it into actionable insights through one AI-powered cloud-native log analytics platform. This single source of truth enables Dev, Sec and Ops teams to simplify complexity, collaborate efficiently and accelerate data-driven decisions that drive business value. Customers around the world rely on the Sumo Logic SaaS Log Analytics Platform for trusted insights to ensure application reliability, secure and protect against modern security threats, and gain insights into their cloud infrastructures. For more information, visit: SUMOLOGIC.COM

**Average Rating:** 4.3/5.0

**Total Reviews:** 392

#### How Do G2 Users Rate Sumo Logic?

- **Activity Monitoring:** 9.1/10 (Category avg: 9.1/10)
- **Data Examination:** 9.0/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **Log Management:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Sumo Logic?

- **Seller:** [Sumo Logic](https://www.g2.com/sellers/sumo-logic)
- **Company Website:** www.sumologic.com
- **Year Founded:** 2010
- **HQ Location:** Redwood City, CA
- **Twitter:** @SumoLogic  
6,542 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=405f2514b57035d31a9696f673d9692138c137173787398caeba6974c512d779&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1037816%2F&secure%5Burl_type%5D=linkedin_company_website)  
838 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 48% Medium, 37% Large

#### What Do G2 Reviewers Say About Sumo Logic?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Sumo Logic, finding it simple to learn and configure effectively.
- Users appreciate the **ease of searching and configuring logs** , enhancing their monitoring and tracing capabilities effortlessly.
- Users value the **Continuous Intelligence feature** of Sumo Logic for its quick and actionable insights from diverse data.
- Users commend **Sumo Logic's visual power and flexibility** , enhancing KPI display and minimizing log-related workload.
- Users value the **real-time insights** offered by Sumo Logic, enhancing monitoring and analytics for better decision-making.

##### Cons

- Users find Sumo Logic to be **expensive** , often questioning if its value justifies the high pricing.
- Users find the **difficult learning** curve of Sumo Logic hampers quick proficiency in using its features effectively.
- Users find Sumo Logic's **steep learning curve** challenging, especially when mastering complex queries and setup processes.
- Users find the **steep learning curve** of Sumo Logic challenging, requiring significant time to gain proficiency.
- Users experience **slow performance** due to a clunky UI and delayed alerting, impacting efficiency and response times.

#### What Are Recent G2 Reviews of Sumo Logic?

**["Secure, Privacy-First AI Logging That Helps Reduce Data Breach Risk"](https://www.g2.com/survey_responses/sumo-logic-review-13156334)**

**Rating:** 5.0/5.0 stars

_— Aiyappa Baleyada B._

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-13156334)

**["Centralized Logging with Intuitive Dashboards"](https://www.g2.com/survey_responses/sumo-logic-review-12948839)**

**Rating:** 4.5/5.0 stars

_— Sudarshan B._

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-12948839)

#### What Are G2 Users Discussing About Sumo Logic?

- [What is Cloud SOAR used for?](https://www.g2.com/discussions/what-is-cloud-soar-used-for) - 1 comment, 1 upvote
- [Is Sumo Logic a SIEM?](https://www.g2.com/discussions/is-sumo-logic-a-siem)
- [What is Sumo Logic used for?](https://www.g2.com/discussions/what-is-sumo-logic-used-for)
- [Who are Sumo Logic competitors?](https://www.g2.com/discussions/who-are-sumo-logic-competitors) - 1 comment
- [How much does Sumo Logic cost?](https://www.g2.com/discussions/how-much-does-sumo-logic-cost)

### [Todyl Security Platform](https://www.g2.com/products/todyl-security-platform/reviews)

Todyl is an AI-powered Cybersecurity and Assurance Platform for threat, risk, and compliance management delivered through a single agent and a single portal. Our platform defends against modern, advanced threats spanning identity, endpoint, network, cloud, SaaS, and more. We also simplify meeting and demonstrating extensive compliance and insurance requirements with centralized data collection and reporting, easy-to-use assessment tools, a built-in risk register, and dashboards to cut back on manual reporting and spreadsheet sprawl. Our platform delivers a layered approach to cybersecurity, spanning SASE, Micro-Segmentation (LZT), Endpoint Security, SIEM, MXDR, and GRC all delivered through the same agent, in a cloud native platform. It’s easy to implement as a cost effective, fully integrated single solution that can consolidate and simplify your security and compliance programs. You can also deploy individual modules to meet your current needs, with a simple toggle within the UI to add or trial new modules when you need them. And an integrated Assurance Marketplace helps you complete your security program with additional services like incident response and penetration testing, and streamlined access to cyber insurance providers.

**Average Rating:** 4.7/5.0

**Total Reviews:** 106

#### How Do G2 Users Rate Todyl Security Platform?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.9/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.7/10 (Category avg: 8.7/10)
- **Log Management:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Todyl Security Platform?

- **Seller:** [Todyl](https://www.g2.com/sellers/todyl)
- **Company Website:** www.todyl.com
- **Year Founded:** 2015
- **HQ Location:** Denver, CO
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=05d7ce90e9975077322588a582ff9aca56286ea0270706e601aa212b6ec71ed8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftodylprotection&secure%5Burl_type%5D=linkedin_company_website)  
122 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** President, Owner
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 75% Small, 8% Medium

#### What Do G2 Reviewers Say About Todyl Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Todyl Security Platform, finding it intuitive and effortlessly manageable.
- Users commend the **responsive and accessible customer support** of Todyl, ensuring quick solutions and seamless integration.
- Users value the **comprehensive and user-friendly features** of Todyl Security Platform, enhancing security with ease and integration.
- Users value the **comprehensive security features** of Todyl, enhancing protection for devices away from the office.
- Users highlight the **deployment ease** of Todyl Security Platform, appreciating its intuitive setup and seamless integration.

##### Cons

- Users feel that **improvements are needed** in customization, integration, and easing the learning curve for Todyl's platform.
- Users note **integration issues** with Todyl, citing limited API and a need for improved third-party interoperability.
- Users find the **reporting inadequate** and seek improvements for better strategic review capabilities.
- Users note **limited features** in Todyl, particularly wishing for enhanced customization and reporting capabilities.
- Users find **reporting difficult** to navigate, hindering their ability to extract valuable insights effectively.

#### What Are Recent G2 Reviews of Todyl Security Platform?

**["Todyl Simplified Our Stack with Enterprise-Level Security at a Great Price"](https://www.g2.com/survey_responses/todyl-security-platform-review-12841444)**

**Rating:** 5.0/5.0 stars

_— Nahjee M._

[Read full review](https://www.g2.com/survey_responses/todyl-security-platform-review-12841444)

**["Valuable Visibility with Room for Improvement"](https://www.g2.com/survey_responses/todyl-security-platform-review-9155307)**

**Rating:** 4.0/5.0 stars

_— Ethan D._

[Read full review](https://www.g2.com/survey_responses/todyl-security-platform-review-9155307)

### [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)

Microsoft Sentinel lets you see and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can: - Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds - Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft - Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft -Respond to incidents rapidly with built-in orchestration and automation of common tasks

**Average Rating:** 4.4/5.0

**Total Reviews:** 275

#### How Do G2 Users Rate Microsoft Sentinel?

- **Activity Monitoring:** 8.9/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **Log Management:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Microsoft Sentinel?

- **Seller:** [Microsoft](https://www.g2.com/sellers/microsoft)
- **Year Founded:** 1975
- **HQ Location:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 employees on LinkedIn®
- **Ownership:** MSFT

#### Who Uses This Product?

- **Who Uses This:** Senior Software Engineer, Security Analyst
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 42% Large, 31% Medium

#### What Do G2 Reviewers Say About Microsoft Sentinel?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **real-time monitoring** of Microsoft Sentinel, enhancing their ability to quickly respond to security threats.
- Users value the **automated alert response** of Microsoft Sentinel, providing peace of mind with centralized security monitoring.
- Users value the **seamless dashboard usability** of Microsoft Sentinel, facilitating intuitive security management and comprehensive monitoring.
- Users value the **fast and secure threat response** of Microsoft Sentinel, enhancing overall security and risk management.
- Users benefit from the **seamless data management** of Microsoft Sentinel, enhancing workflow and ensuring comprehensive security analytics.

##### Cons

- Users express concerns about **cloud dependency** , particularly regarding connectivity issues with low-speed internet and commercial reliance.
- Users find the **complex configuration** of Microsoft Sentinel challenging, requiring advanced technical skills for effective setup and use.
- Users face **configuration issues** with Microsoft Sentinel, requiring technical expertise and time for effective setup.
- Users find the **difficult setup** of Microsoft Sentinel challenging without dedicated security experts and proper training.
- Users struggle with the **poor interface design** of Microsoft Sentinel, making navigation and understanding features difficult.

#### What Are Recent G2 Reviews of Microsoft Sentinel?

**["Easy Log Ingestion Across Formats with Seamless Sentinel Integrations"](https://www.g2.com/survey_responses/microsoft-sentinel-review-13073395)**

**Rating:** 4.5/5.0 stars

_— Sandip K._

[Read full review](https://www.g2.com/survey_responses/microsoft-sentinel-review-13073395)

**["Best Cloud native SIEM - Microsoft Sentinel"](https://www.g2.com/survey_responses/microsoft-sentinel-review-13250215)**

**Rating:** 4.5/5.0 stars

_— vimal p._

[Read full review](https://www.g2.com/survey_responses/microsoft-sentinel-review-13250215)

#### What Are G2 Users Discussing About Microsoft Sentinel?

- [What is Microsoft Sentinel used for?](https://www.g2.com/discussions/what-is-microsoft-sentinel-used-for) - 3 comments, 2 upvotes
- [Why should I use Azure Sentinel?](https://www.g2.com/discussions/why-should-i-use-azure-sentinel) - 1 comment
- [Which feature provides the extended detection and response capabilities of Azure Sentinel?](https://www.g2.com/discussions/which-feature-provides-the-extended-detection-and-response-capabilities-of-azure-sentinel)
- [What is the difference between Azure security Center and Azure Sentinel?](https://www.g2.com/discussions/what-is-the-difference-between-azure-security-center-and-azure-sentinel)
- [What does Azure Sentinel provide?](https://www.g2.com/discussions/what-does-azure-sentinel-provide)

### [Huntress Managed SIEM](https://www.g2.com/products/huntress-managed-siem/reviews)

Huntress is a comprehensive cybersecurity solution designed specifically for the Fortune 5,000 and the managed service providers (MSPs) that support them. This platform combines advanced technology with a fully staffed 24/7 Security Operations Center (SOC) to deliver a robust defense against an ever-evolving landscape of cyber threats. By integrating cutting-edge tools, services, and expert knowledge, Huntress empowers businesses to effectively tackle their cybersecurity challenges and safeguard their critical business assets. The target audience for Huntress includes internal IT teams that may lack the resources or expertise to manage cybersecurity independently, as well as MSPs looking for reliable solutions to enhance their service offerings. These businesses often face unique challenges, such as budget constraints and limited IT staff, making it essential for them to adopt a cybersecurity strategy that is both effective and affordable. Huntress addresses these needs by providing a suite of purpose-built solutions tailored to these specific requirements, ensuring they can defend against cyber threats without compromising their operational efficiency. Key features of Huntress include its Managed Security Platform, which offers real-time threat detection and response capabilities. The platform continuously monitors for malicious activity, enabling rapid identification and remediation of potential threats. Additionally, the 24/7 SOC staffed by cybersecurity experts ensures that any incidents are promptly addressed, providing peace of mind to businesses that may not have in-house security teams. Huntress also emphasizes education, offering resources and training to help users understand cybersecurity best practices and stay informed about the latest threats. By delivering a combination of technology, services, and expertise, Huntress stands out in the cybersecurity landscape. The proactive approach of Huntress not only helps businesses defend against current threats but also prepares them for future challenges, making it a valuable partner in the ongoing fight against cybercrime.

**Average Rating:** 4.7/5.0

**Total Reviews:** 49

#### Who Is the Company Behind Huntress Managed SIEM?

- **Seller:** [Huntress Labs](https://www.g2.com/sellers/huntress-labs)
- **Company Website:** huntress.com
- **Year Founded:** 2015
- **HQ Location:** Ellicott City, US
- **Twitter:** @HuntressLabs  
40,338 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=570d57c2d792bb0f1dd9c97cb05ee13cfd2e93a1546d6d3c5c11e8ce22e14a55&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10172550%2F&secure%5Burl_type%5D=linkedin_company_website)  
978 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 64% Small, 24% Medium

#### What Are Recent G2 Reviews of Huntress Managed SIEM?

**["Centralized Logging and Investigation Powerhouse"](https://www.g2.com/survey_responses/huntress-managed-siem-review-12729137)**

**Rating:** 4.5/5.0 stars

_— Paul A._

[Read full review](https://www.g2.com/survey_responses/huntress-managed-siem-review-12729137)

**["Exemplary SIEM Service with Unmatched Support"](https://www.g2.com/survey_responses/huntress-managed-siem-review-12676229)**

**Rating:** 5.0/5.0 stars

_— Skylar P._

[Read full review](https://www.g2.com/survey_responses/huntress-managed-siem-review-12676229)

### [Check Point Infinity Platform](https://www.g2.com/products/check-point-infinity-platform/reviews)

Check Point Infinity is the only fully consolidated cyber security architecture that provides unprecedented protection against Gen V mega-cyber attacks as well as future cyber threats across all networks, endpoint, cloud and mobile. The architecture is designed to resolve the complexities of growing connectivity and inefficient security.

**Average Rating:** 4.6/5.0

**Total Reviews:** 109

#### How Do G2 Users Rate Check Point Infinity Platform?

- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Check Point Infinity Platform?

- **Seller:** [Check Point Software Technologies](https://www.g2.com/sellers/check-point-software-technologies)
- **Year Founded:** 1993
- **HQ Location:** Redwood City, CA
- **Twitter:** @CheckPointSW  
70,955 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d885813f6605ba84238ae4a21d169e0c9ade054cf0c99ff53e72483b54a8b521&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheck-point-software-technologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
8,554 employees on LinkedIn®
- **Ownership:** NASDAQ:CHKP

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 44% Large, 37% Medium

#### What Do G2 Reviewers Say About Check Point Infinity Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **advanced security features** of Check Point Infinity Platform, ensuring robust protection against future attacks.
- Users appreciate the **cloud security features** of Check Point Infinity Platform, ensuring efficient security audits and infrastructure assessment.
- Users value the **proactive threat detection** features of Check Point Infinity Platform, enhancing security for cloud applications.
- Users value the **comprehensive security** features of Check Point Infinity Platform, ensuring robust protection against cloud threats.
- Users appreciate the **advanced cloud security features** of Check Point Infinity Platform, ensuring robust protection against future attacks.

##### Cons

- Users find the **steep learning curve** challenging due to complex setup and lack of comprehensive documentation.
- Users find the **complexity** of the Check Point Infinity Platform's settings and documentation can hinder usability and efficiency.
- Users find that **improvement is needed** in support and visibility of native servers in Check Point logs.
- Users find **poor support services** detrimental, highlighting the need for improved customer assistance and log visibility.
- Users face **limited customization** options for rulesets and metrics, making detailed assessments challenging.

#### What Are Recent G2 Reviews of Check Point Infinity Platform?

**["Excellent option Harmony Platform for security central"](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11868343)**

**Rating:** 4.5/5.0 stars

_— Tania V._

[Read full review](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11868343)

**["Seamless Hybrid Security Integration Across All Environments"](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11954684)**

**Rating:** 4.5/5.0 stars

_— Sonu S._

[Read full review](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11954684)

#### What Are G2 Users Discussing About Check Point Infinity Platform?

- [How does Check Point Infinity help customers?](https://www.g2.com/discussions/how-does-check-point-infinity-help-customers)
- [What are the benefits of Check Point unified security architecture?](https://www.g2.com/discussions/what-are-the-benefits-of-check-point-unified-security-architecture)
- [What are the 4 components of the Infinity architecture?](https://www.g2.com/discussions/what-are-the-4-components-of-the-infinity-architecture)
- [What is Infinity Total protection?](https://www.g2.com/discussions/what-is-infinity-total-protection)

### [Panther](https://www.g2.com/products/panther/reviews)

Panther is the AI SOC Platform that scales security expertise by embedding AI agents across your security operations with native access to your data lake, detection logic, and organizational knowledge. Unlike bolt-on tools, Panther's closed-loop architecture turns every alert into compounding intelligence that makes the system smarter over time. Request a demo today at: https://panther.com/product/request-a-demo/

**Average Rating:** 4.7/5.0

**Total Reviews:** 49

#### How Do G2 Users Rate Panther?

- **Activity Monitoring:** 9.3/10 (Category avg: 9.1/10)
- **Data Examination:** 9.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.9/10 (Category avg: 8.7/10)
- **Log Management:** 9.7/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Panther?

- **Seller:** [Panther Labs](https://www.g2.com/sellers/panther-labs)
- **Year Founded:** 2018
- **HQ Location:** San Francisco, CA
- **Twitter:** @runpanther  
4,437 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5e833e3ee9905da8ffc2168b1d7db4af5d6a4643d77358f095ebefb033c5103a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Frunpanther%2F&secure%5Burl_type%5D=linkedin_company_website)  
269 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Senior Security Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 53% Medium, 29% Large

#### What Do G2 Reviewers Say About Panther?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Panther's **outstanding customer support** , highlighting its responsiveness and commitment to resolving issues efficiently.
- Users commend Panther for its **exceptional detection efficiency** , enabling effective and purposeful responses in security operations.
- Users find Panther's **intuitive interface** and comprehensive documentation make it easy to navigate and use effectively.
- Users praise the **easy integrations** with various log sources, simplifying security management and boosting team efficiency.
- Users praise Panther for its **purposeful features and continuous improvements** , enhancing usability and aligning with market needs.

##### Cons

- Users find Panther has **missing features** like version control and underdeveloped response workflows, complicating overall use.
- Users find Panther's **complexity challenging** , particularly for non-technical teams and in managing version controls.
- Users find the **Alert Management limited** due to lack of customization and configuration challenges affecting efficiency.
- Users find the **complex configuration** of Panther burdensome, complicating integration with deployment pipelines and automation systems.
- Users find the **dashboard issues** in Panther limit comprehensive security leadership insights and advanced customization options.

#### What Are Recent G2 Reviews of Panther?

**["Panther’s SIEM + AI Makes Triage and Threat Hunting Fast and Seamless"](https://www.g2.com/survey_responses/panther-review-12919421)**

**Rating:** 5.0/5.0 stars

_— Richard E._

[Read full review](https://www.g2.com/survey_responses/panther-review-12919421)

**["Panther Makes Security Operations Simpler and Faster"](https://www.g2.com/survey_responses/panther-review-12890548)**

**Rating:** 5.0/5.0 stars

_— Busra K._

[Read full review](https://www.g2.com/survey_responses/panther-review-12890548)

#### What Are G2 Users Discussing About Panther?

- [What is Panther used for?](https://www.g2.com/discussions/what-is-panther-used-for) - 1 comment

### [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)

Find out what is happening in your business and take meaningful action quickly with Splunk Enterprise. Automate the collection, indexing and alerting of machine data that's critical to your operations. Uncover the actionable insights from all your data — no matter the source or format. Leverage artificial intelligence and machine learning for predictive and proactive business decisions.

**Average Rating:** 4.3/5.0

**Total Reviews:** 415

#### How Do G2 Users Rate Splunk Enterprise?

- **Activity Monitoring:** 9.1/10 (Category avg: 9.1/10)
- **Data Examination:** 8.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.1/10 (Category avg: 8.7/10)
- **Log Management:** 9.3/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Splunk Enterprise?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 64% Large, 27% Medium

#### What Do G2 Reviewers Say About Splunk Enterprise?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **innovation** of Splunk Enterprise, appreciating its user-friendly features and powerful analytics capabilities.
- Users value the **customization features** of Splunk Enterprise, enabling tailored insights and dynamic dashboards for effective monitoring.
- Users commend the **ease of use** of Splunk Enterprise, enhancing effective monitoring and quick issue resolution.
- Users value the **efficient log management** capabilities of Splunk Enterprise for accurate analysis and insights.
- Users value the **powerful reporting features** of Splunk Enterprise, enhancing data analysis and visualization capabilities significantly.

##### Cons

- Users find Splunk Enterprise to be **expensive** , especially as data volumes grow, impacting smaller teams' operations.
- Users face a **steep learning curve** with Splunk Enterprise, which can hinder quick mastery of its features.
- Users highlight the **expensive licensing** of Splunk Enterprise, making it difficult for some companies to adopt.
- Users face **integration issues** with Splunk Enterprise, requiring better add-ons and simpler architecture for easier deployment.
- Users feel that Splunk Enterprise has **missing features** , lacking important add-ons and more flexible data onboarding options.

#### What Are Recent G2 Reviews of Splunk Enterprise?

**["SPL search and dashboards are really useful"](https://www.g2.com/survey_responses/splunk-enterprise-review-12547655)**

**Rating:** 4.0/5.0 stars

_— Nishith J._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-review-12547655)

**["Excellent Enterprise Observability and Log Management Solution for Hybrid Cloud Infrastructure"](https://www.g2.com/survey_responses/splunk-enterprise-review-12045230)**

**Rating:** 4.5/5.0 stars

_— RaviShankar S._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-review-12045230)

#### What Are G2 Users Discussing About Splunk Enterprise?

- [What is Splunk Enterprise used for?](https://www.g2.com/discussions/what-is-splunk-enterprise-used-for) - 1 comment
- [What is the difference between Splunk Enterprise and Splunk Enterprise Security?](https://www.g2.com/discussions/splunk-enterprise-what-is-the-difference-between-splunk-enterprise-and-splunk-enterprise-security) - 1 comment
- [What are Splunk Enterprise components?](https://www.g2.com/discussions/what-are-splunk-enterprise-components) - 1 comment
- [Which apps ship with Splunk Enterprise?](https://www.g2.com/discussions/which-apps-ship-with-splunk-enterprise) - 1 comment
- [What does Splunk Enterprise do?](https://www.g2.com/discussions/what-does-splunk-enterprise-do) - 1 comment

### [Cynet](https://www.g2.com/products/cynet/reviews)

Cynet is the unified, AI-powered cybersecurity platform that delivers robust and comprehensive protection for security teams while maximizing operational efficiency for managed service providers (MSPs). This platform consolidates a wide array of security capabilities into a single, user-friendly interface, ensuring that organizations can effectively safeguard their digital assets without the complexity often associated with multi-solution environments. Cynet’s platform simplifies security management by integrating various functionalities, such as endpoint protection, threat detection, and incident response, into one cohesive system. This integration not only streamlines operations but also allows organizations to allocate their resources more effectively, ultimately enhancing their overall security posture. One of the standout features of Cynet’s platform is its remarkable performance in the MITRE ATT&CK Evaluations. Cynet delivered 100% visibility and 100% analytic coverage without requiring any configuration changes three years in a row. This capability ensures that organizations can monitor their environments comprehensively and respond to threats with precision. The platform’s built-in analytics and reporting tools provide actionable insights, enabling users to make informed decisions about their cybersecurity strategies. Additionally, Cynet offers 24/7 expert support, which is crucial for organizations that may not have in-house cybersecurity expertise. This round-the-clock assistance ensures that users can quickly address any security incidents or concerns, minimizing potential downtime and damage. The combination of advanced technology and dedicated support positions Cynet as a valuable partner for SMEs and service providers looking to enhance their cybersecurity measures. In summary, Cynet’s unified, AI-powered cybersecurity platform stands out in the crowded cybersecurity market by offering a unified solution tailored to the needs of MSPs. Its comprehensive features, exceptional performance in industry evaluations, and continuous expert support make it a compelling choice for organizations seeking to bolster their cybersecurity defenses while maintaining operational efficiency.

**Average Rating:** 4.7/5.0

**Total Reviews:** 216

#### How Do G2 Users Rate Cynet?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.8/10 (Category avg: 8.6/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **Log Management:** 8.9/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Cynet?

- **Seller:** [Cynet](https://www.g2.com/sellers/cynet)
- **Year Founded:** 2014
- **HQ Location:** Boston, MA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5a5ebaacd6a1a812a193b2886c91aa7e64aeee7fb30bb25e658549d729d68178&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcynet-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
332 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** SOC Analyst, Technical Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 58% Medium, 31% Small

#### What Do G2 Reviewers Say About Cynet?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Cynet, enjoying its simplicity and comprehensive features in one dashboard.
- Users value the **unified platform** of Cynet for its ease of use and comprehensive security features.
- Users value Cynet for its **effective threat detection** and seamless integration, ensuring robust cybersecurity for their business.
- Users appreciate the **exceptional customer support** of Cynet, facilitating smooth deployment and effective threat management.
- Users commend Cynet for its **flawless threat monitoring and response** , enhancing overall security with effective detection capabilities.

##### Cons

- Users express concern over **limited customization** options in reports and third-party integrations, impacting their experience.
- Users note the **feature limitations** of Cynet, especially in report customization and external tool integrations.
- Users express concern over the **lack of customization** , particularly in reporting and dashboard options for better usability.
- Users find Cynet has **limited features** like integrations and customization, which may restrict advanced functionality.
- Users note the **missing features** in Cynet, particularly the lack of web filtering and a firewall option.

#### What Are Recent G2 Reviews of Cynet?

**["Outstanding Product"](https://www.g2.com/survey_responses/cynet-review-9063334)**

**Rating:** 5.0/5.0 stars

_— David W._

[Read full review](https://www.g2.com/survey_responses/cynet-review-9063334)

**["One platform to manage centralized Endpoint Security"](https://www.g2.com/survey_responses/cynet-review-10264337)**

**Rating:** 4.5/5.0 stars

_— Guido I._

[Read full review](https://www.g2.com/survey_responses/cynet-review-10264337)

#### What Are G2 Users Discussing About Cynet?

- [What is Cynet 360 AutoXDR™ used for?](https://www.g2.com/discussions/what-is-cynet-360-autoxdr-used-for)
- [What is cynet XDR?](https://www.g2.com/discussions/what-is-cynet-xdr) - 1 comment
- [What is cynet used for?](https://www.g2.com/discussions/what-is-cynet-used-for) - 1 comment
- [Is cynet 360 good?](https://www.g2.com/discussions/is-cynet-360-good) - 3 comments
- [How much does cynet cost?](https://www.g2.com/discussions/how-much-does-cynet-cost) - 1 comment

### [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews)

Outsmart threats with an end-to-end award-winning security suite; proven to prevent, endure and recover from both known & unknown IT hazards faced by SoCs in the modern-day.

**Average Rating:** 4.4/5.0

**Total Reviews:** 283

#### How Do G2 Users Rate IBM QRadar SIEM?

- **Activity Monitoring:** 8.7/10 (Category avg: 9.1/10)
- **Data Examination:** 8.3/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.4/10 (Category avg: 8.7/10)
- **Log Management:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind IBM QRadar SIEM?

- **Seller:** [IBM](https://www.g2.com/sellers/ibm)
- **Year Founded:** 1911
- **HQ Location:** Armonk, New York, United States
- **Twitter:** @IBMSecurity  
74,660 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=14b544adaece4fdbc987f1d7f7028048c22259946811200cc751263825586af9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1009%2F&secure%5Burl_type%5D=linkedin_company_website)  
328,202 employees on LinkedIn®
- **Ownership:** SWX:IBM

#### Who Uses This Product?

- **Who Uses This:** Security Engineer, SOC Analyst
- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 52% Large, 29% Medium

#### What Do G2 Reviewers Say About IBM QRadar SIEM?

_AI-generated summary from verified user reviews_

##### Pros

- Users find IBM QRadar SIEM highly **user-friendly** , appreciating its ease of implementation and integration with other platforms.
- Users appreciate the **seamless integration capabilities** of IBM QRadar SIEM, enhancing overall log management and analytics functionality.
- Users value the **advanced threat detection and centralized log management** features of IBM QRadar SIEM for enhanced security.
- Users value the **easy integrations** of IBM QRadar SIEM, simplifying collaboration with various platforms and tools.
- Users find the **user-friendly interface** of IBM QRadar SIEM makes it easy for non-tech users to navigate.

##### Cons

- Users find the **UI improvements lacking** , with search limitations and poor report building hindering their experience.
- Users find IBM QRadar SIEM to be **expensive** , especially for small or mid-size companies due to high costs.
- Users note the **high costs** associated with IBM QRadar SIEM, which may burden smaller organizations significantly.
- Users are frustrated by **dashboard issues** , including limited editing rights and difficulties in offense management and reporting.
- Users find the **time-consuming search queries** to be frustrating and inefficient for log retrieval in QRadar SIEM.

#### What Are Recent G2 Reviews of IBM QRadar SIEM?

**["QRADAR Integrates Easily and Makes Logs & Alerts Report-Ready"](https://www.g2.com/survey_responses/ibm-qradar-siem-review-13061810)**

**Rating:** 4.5/5.0 stars

_— Zahid A._

[Read full review](https://www.g2.com/survey_responses/ibm-qradar-siem-review-13061810)

**["Strong Correlation, Mature Security Monitoring, and Compliance Reporting"](https://www.g2.com/survey_responses/ibm-qradar-siem-review-12986703)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/ibm-qradar-siem-review-12986703)

### [Elastic Security](https://www.g2.com/products/elastic-elastic-security/reviews)

Modernize your SOC with AI Security is a data problem. Your team needs to detect, investigate, and respond to threats quickly. Elastic Security unifies next-gen SIEM and XDR with native automation, with AI built into every step. Built on Elasticsearch, the open-source search platform trusted by millions, Elastic provides complete visibility across your environment. Our data mesh architecture streamlines analysis to raise team productivity and reduce attacker dwell time. Bolster your defenses - Detect threats faster by analyzing data from across your attack surface - Stop attacks with the industry's best-rated XDR protection - Close the loop faster with Elastic Workflows, blending scripted automation with agentic AI reasoning - Get more accurate AI assistance, grounded in your data using Elasticsearch's leading relevance capabilities With Elastic Security, your SOC team can use generative AI to distill alerts, automate repetitive tasks, and get tailored guidance, all with your choice of LLM and full transparency into reasoning and sources. SOC leaders choose Elastic Security when they need a unified, open platform ready to run on any cloud, on-prem, or air-gapped.

**Average Rating:** 4.5/5.0

**Total Reviews:** 23

#### How Do G2 Users Rate Elastic Security?

- **Activity Monitoring:** 9.7/10 (Category avg: 9.1/10)
- **Data Examination:** 8.3/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.8/10 (Category avg: 8.7/10)
- **Log Management:** 9.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Elastic Security?

- **Seller:** [Elastic](https://www.g2.com/sellers/elastic)
- **Company Website:** www.elastic.co
- **Year Founded:** 2012
- **HQ Location:** San Francisco, CA
- **Twitter:** @elastic  
65,200 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=bc8e533876f16af617380aaa3922cb6a39a1d6233f0b32a0fa987a5fdffd799e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F814025%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,079 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 61% Medium, 52% Small

#### What Do G2 Reviewers Say About Elastic Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **seamless integrations** of Elastic Security, enhancing data visualization and incident management efficiency.
- Users value the **ease of use** of Elastic Security, appreciating its straightforward setup and seamless integrations.
- Users admire the **flexibility and pre-built security use-cases** of Elastic Security for seamless integration and adaptability.
- Users appreciate the **easy integrations** of Elastic Security, facilitating seamless workflows and efficient investigations across tools.
- Users value the **efficiency improvement** in investigations, enabling quick, actionable insights with Elastic Security's robust features.

##### Cons

- Users face challenges with **steep learning curves and operational overhead** , impacting efficiency and resource management in Elastic Security.
- Users find the **complex implementation** of Elastic Security challenging, especially due to the steep learning curve and maintenance overhead.
- Users find the **complexity** of maintaining Elastic Security's infrastructure and learning new query languages challenging and burdensome.
- Users point out the **complex setup** of Elastic Security, citing a steep learning curve and significant administrative overhead.
- Users frequently experience **integration issues** with Elastic Security, complicating log correlation and overall functionality.

#### What Are Recent G2 Reviews of Elastic Security?

**["Powerful, Customisable Security Platform for Complex Environments"](https://www.g2.com/survey_responses/elastic-security-review-12341245)**

**Rating:** 4.5/5.0 stars

_— Jennifer S._

[Read full review](https://www.g2.com/survey_responses/elastic-security-review-12341245)

**["Seamless SIEM Solution with AI and Outstanding Support"](https://www.g2.com/survey_responses/elastic-security-review-12438374)**

**Rating:** 5.0/5.0 stars

_— Jordan J._

[Read full review](https://www.g2.com/survey_responses/elastic-security-review-12438374)

### [Splunk Enterprise Security](https://www.g2.com/products/splunk-enterprise-security/reviews)

Splunk Enterprise Security (ES) is a data-centric, modern security information and event management (SIEM) solution that delivers data-driven insights for full breadth visibility into your security posture so you can protect your business and mitigate risk at scale. With unparalleled search and reporting, advanced analytics, integrated intelligence, and prepackaged security content, Splunk ES accelerates threat detection and investigation, letting you determine the scope of high-priority threats to your environment so you can quickly take action. Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Our extensive ecosystem of Splunk, partner, and community-built integrations as well as flexible deployment options ensure your technology investments are working in tandem with Splunk ES whilst meeting you wherever you are on your cloud, multi-cloud, or hybrid journey.

**Average Rating:** 4.3/5.0

**Total Reviews:** 224

#### How Do G2 Users Rate Splunk Enterprise Security?

- **Activity Monitoring:** 8.8/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **Log Management:** 9.3/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Splunk Enterprise Security?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 59% Large, 30% Medium

#### What Do G2 Reviewers Say About Splunk Enterprise Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Splunk Enterprise Security, enhancing their monitoring and log management experience.
- Users appreciate the **easy integrations** of Splunk Enterprise Security, enabling seamless connection with various platforms and systems.
- Users highlight the **impressive threat detection** capabilities of Splunk Enterprise Security, enhancing security focus and reducing false alarms.
- Users value the **effective features** of Splunk Enterprise Security, enhancing security analysis with comprehensive logs and insights.
- Users appreciate the **user-friendly interface** of Splunk Enterprise Security, enabling efficient monitoring and attractive dashboards.

##### Cons

- Users note that the **high cost** of Splunk Enterprise Security is a major drawback for smaller organizations.
- Users find the **initial implementation complex** , needing expert resources and time to onboard Splunk Enterprise Security effectively.
- Users find the **complex implementation** of Splunk Enterprise Security challenging, requiring extensive expertise and resources.
- Users find the **complexity and extensive setup** of Splunk Enterprise Security to be time-consuming and challenging.
- Users find the **difficult learning** curve of Splunk Enterprise Security a challenge for beginners and costly to set up.

#### What Are Recent G2 Reviews of Splunk Enterprise Security?

**["Powerful Threat Detection and Investigation with Splunk Enterprise Security"](https://www.g2.com/survey_responses/splunk-enterprise-security-review-12982814)**

**Rating:** 5.0/5.0 stars

_— Priyanshu S._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-security-review-12982814)

**["Simple, Easy-to-Use UI That Brings Everything Together in One Place"](https://www.g2.com/survey_responses/splunk-enterprise-security-review-13233919)**

**Rating:** 4.5/5.0 stars

_— Yashwant S._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-security-review-13233919)

#### What Are G2 Users Discussing About Splunk Enterprise Security?

- [What is Splunk User Behavior Analytics used for?](https://www.g2.com/discussions/what-is-splunk-user-behavior-analytics-used-for)
- [What does Splunk Enterprise do?](https://www.g2.com/discussions/splunk-enterprise-security-what-does-splunk-enterprise-do)
- [What is the difference between Splunk Enterprise and Splunk Enterprise Security?](https://www.g2.com/discussions/what-is-the-difference-between-splunk-enterprise-and-splunk-enterprise-security) - 1 comment
- [Which Splunk app is used for enterprise security?](https://www.g2.com/discussions/which-splunk-app-is-used-for-enterprise-security)
- [What is Splunk Enterprise Security?](https://www.g2.com/discussions/what-is-splunk-enterprise-security)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/es/categories/security-information-and-event-management-siem?order=g2_score&page=2#product-list)
- [3](/es/categories/security-information-and-event-management-siem?order=g2_score&page=3#product-list)
- [4](/es/categories/security-information-and-event-management-siem?order=g2_score&page=4#product-list)
- [5](/es/categories/security-information-and-event-management-siem?order=g2_score&page=5#product-list)
- …
- [8](/es/categories/security-information-and-event-management-siem?order=g2_score&page=8#product-list)
- [9](/es/categories/security-information-and-event-management-siem?order=g2_score&page=9#product-list)
- [Next &rsaquo; Next ›](/es/categories/security-information-and-event-management-siem?order=g2_score&page=2#product-list)

Categorías Destacadas

[Software de formación y incorporación de ventas](https://www.g2.com/es/categories/sales-training-and-onboarding)

[Soluciones de Plataforma de Integración como Servicio (iPaaS)](https://www.g2.com/es/categories/ipaas)

[Soluciones de Gestión de Viajes](https://www.g2.com/es/categories/travel-management)

[Software de Gestión de Experiencias](https://www.g2.com/es/categories/experience-management)

[Bases de datos relacionales](https://www.g2.com/es/categories/relational-databases)

Categorías Similares

- [Respuesta a Incidentes](/es/categories/incident-response)
- [Inteligencia de Amenazas](/es/categories/threat-intelligence)
- [Agentes SOC de IA](/es/categories/ai-soc-agents)
- [Simulación de Brechas y Ataques (BAS)](/es/categories/breach-and-attack-simulation-bas)
- [Tecnología de engaño](/es/categories/deception-technology)

- [Informática Forense](/es/categories/digital-forensics)
- [Plataformas de Protección contra Riesgos Digitales (DRP)](/es/categories/digital-risk-protection-drp-platforms)
- [Soluciones de Seguridad para IoT](/es/categories/iot-security-solutions)
- [Herramientas de Análisis de Malware](/es/categories/malware-analysis-tools)
- [Detección y Respuesta Gestionada (MDR)](/es/categories/managed-detection-and-response-mdr)

- [Acceso Remoto Seguro OT](/es/categories/ot-secure-remote-access)
- [OT Security Tools](/es/categories/ot-security-tools)
- [Herramientas de Red Teaming](/es/categories/red-teaming-tools)
- [Orquestación, Automatización y Respuesta de Seguridad (SOAR)](/es/categories/security-orchestration-automation-and-response-soar)

[Browse Gestión de Información y Eventos de Seguridad (SIEM) Themes](/es/categories/security-information-and-event-management-siem/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Investigado y escrito por [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 31, 2024

El software de gestión de información y eventos de seguridad (SIEM) combina una variedad de componentes de software de seguridad en una sola plataforma. Las empresas utilizan soluciones SIEM para centralizar las operaciones de seguridad en un solo lugar. Los equipos de operaciones de TI y seguridad pueden acceder a la misma información y alertas para una comunicación y planificación más efectivas. Estos productos proporcionan capacidades para identificar y alertar a los equipos de operaciones de TI sobre anomalías detectadas en sus sistemas. Las anomalías pueden ser nuevo malware, acceso no aprobado o vulnerabilidades recién descubiertas. Las herramientas SIEM proporcionan análisis en vivo de funcionalidad y seguridad, almacenando registros e informes para reportes retrospectivos. También tienen productos para la gestión de identidad y acceso para asegurar que solo las partes aprobadas tengan acceso a sistemas sensibles. Las herramientas de análisis forense ayudan a los equipos a navegar por registros históricos, identificar tendencias y fortalecer mejor sus redes.

Los sistemas SIEM pueden confundirse con el software de [respuesta a incidentes](https://www.g2.com/es/categories/incident-response), pero los productos SIEM proporcionan un alcance más amplio de características de gestión de seguridad y TI. La mayoría tampoco tiene la capacidad de automatizar prácticas de remediación de seguridad.

Para calificar para la inclusión en la categoría SIEM, un producto debe:

- Agregar y almacenar datos de seguridad de TI
- Ayudar en la provisión y gobernanza de usuarios
- Identificar vulnerabilidades en sistemas y puntos finales
- Monitorear anomalías dentro de un sistema de TI

Principales Herramientas de un Vistazo

| Product | Mejor para | User Review |
| --- | --- | --- |
| [![Imagen del Avatar del Producto](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_56db399f44b6fabb7c667f09bc770579/crowdstrike-falcon-endpoint-protection-platform.png "Imagen del Avatar del Producto")](https://www.g2.com/es/products/crowdstrike-falcon-endpoint-protection-platform/reviews)[CrowdStrike Falcon Endpoint...](https://www.g2.com/es/products/crowdstrike-falcon-endpoint-protection-platform/reviews)[4.6/5(441)](https://www.g2.com/es/products/crowdstrike-falcon-endpoint-protection-platform/reviews) | Detección de amenazas conductuales con respuesta en tiempo real en el punto final | "Crowdstrike Falcon: Seguridad Proactiva, Curva de Aprendizaje Empinada" |
| [![Imagen del Avatar del Producto](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_bf8095de95175316574d734b1f2b2c48/sumo-logic.png "Imagen del Avatar del Producto")](https://www.g2.com/es/products/sumo-logic/reviews)[Sumo Logic](https://www.g2.com/es/products/sumo-logic/reviews)[4.3/5(404)](https://www.g2.com/es/products/sumo-logic/reviews) | Cloud-native SIEM with unified observability | "Registro centralizado con paneles intuitivos" |
| [![Imagen del Avatar del Producto](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_f7c81a73a5adf5f83fb61d5a8f5f6a15/todyl-security-platform.png "Imagen del Avatar del Producto")](https://www.g2.com/es/products/todyl-security-platform/reviews)[Todyl Security Platform](https://www.g2.com/es/products/todyl-security-platform/reviews)[4.7/5(106)](https://www.g2.com/es/products/todyl-security-platform/reviews) | SIEM unificado con MXDR integrado para MSPs | "Visibilidad valiosa con margen de mejora" |
| [![Imagen del Avatar del Producto](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_4e2b08dd17397bdc99a5658447cbc589/microsoft-sentinel.jpg "Imagen del Avatar del Producto")](https://www.g2.com/es/products/microsoft-sentinel/reviews)[Microsoft Sentinel](https://www.g2.com/es/products/microsoft-sentinel/reviews)[4.4/5(298)](https://www.g2.com/es/products/microsoft-sentinel/reviews) | SIEM nativo de la nube con integración en el ecosistema de Microsoft | "Mejor SIEM nativo de la nube - Microsoft Sentinel" |
| [![Imagen del Avatar del Producto](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8dedb235969bcb553f9e412b16e93d0a/check-point-infinity-platform.png "Imagen del Avatar del Producto")](https://www.g2.com/es/products/check-point-infinity-platform/reviews)[Check Point Infinity Platform](https://www.g2.com/es/products/check-point-infinity-platform/reviews)[4.6/5(117)](https://www.g2.com/es/products/check-point-infinity-platform/reviews) | Unified threat prevention across hybrid security infrastructure | "Excelente opción Harmony Platform para la seguridad central" |
| [![Imagen del Avatar del Producto](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_16dfa8129f7c019c451bdcef5de2a937/panther%282%29.jpg "Imagen del Avatar del Producto")](https://www.g2.com/es/products/panther/reviews)[Panther](https://www.g2.com/es/products/panther/reviews)[4.7/5(49)](https://www.g2.com/es/products/panther/reviews) | Detección como código SIEM con alertas basadas en Python | "El SIEM + IA de Panther hace que la clasificación y la búsqueda de amenazas sean rápidas y fluidas." |

* * *

Show More

### Temas de Gestión de Información y Eventos de Seguridad (SIEM)

- [¿Qué es el software de gestión de información y eventos de seguridad (SIEM)?](#que-es-el-software-de-gestion-de-informacion-y-eventos-de-seguridad-siem)
- [Tipos de soluciones SIEM](#tipos-de-soluciones-siem)
- [¿Cuáles son las características comunes de los sistemas SIEM?](#cuales-son-las-caracteristicas-comunes-de-los-sistemas-siem)
- [¿Cuáles son los beneficios de usar productos SIEM?](#cuales-son-los-beneficios-de-usar-productos-siem)
- [Software relacionado con herramientas SIEM](#software-relacionado-con-herramientas-siem)
- [Desafíos con el software SIEM](#desafios-con-el-software-siem)
- [¿Qué empresas deberían comprar soluciones SIEM?](#que-empresas-deberian-comprar-soluciones-siem)
- [Cómo elegir el mejor software SIEM](#como-elegir-el-mejor-software-siem)
- [¿Cuánto cuesta el software SIEM?](#cuanto-cuesta-el-software-siem)

[
### Temas de Gestión de Información y Eventos de Seguridad (SIEM)
 Expandir/Contraer ](#)
- [¿Qué es el software de gestión de información y eventos de seguridad (SIEM)?](#que-es-el-software-de-gestion-de-informacion-y-eventos-de-seguridad-siem)
- [Tipos de soluciones SIEM](#tipos-de-soluciones-siem)
- [¿Cuáles son las características comunes de los sistemas SIEM?](#cuales-son-las-caracteristicas-comunes-de-los-sistemas-siem)
- [¿Cuáles son los beneficios de usar productos SIEM?](#cuales-son-los-beneficios-de-usar-productos-siem)
- [Software relacionado con herramientas SIEM](#software-relacionado-con-herramientas-siem)
- [Desafíos con el software SIEM](#desafios-con-el-software-siem)
- [¿Qué empresas deberían comprar soluciones SIEM?](#que-empresas-deberian-comprar-soluciones-siem)
- [Cómo elegir el mejor software SIEM](#como-elegir-el-mejor-software-siem)
- [¿Cuánto cuesta el software SIEM?](#cuanto-cuesta-el-software-siem)

## Más Información Sobre Software de Gestión de Información y Eventos de Seguridad (SIEM)

### ¿Qué es el software de gestión de información y eventos de seguridad (SIEM)?
 

La Gestión de Información y Eventos de Seguridad (SIEM) es un sistema centralizado para la detección de amenazas que agrega alertas de seguridad de múltiples fuentes, simplificando la respuesta a amenazas y la elaboración de informes de cumplimiento. El software SIEM es una de las herramientas más comúnmente utilizadas por los administradores de seguridad y los profesionales de respuesta a incidentes de seguridad. Proporcionan una plataforma única capaz de facilitar la protección contra eventos y amenazas, el análisis e investigación de registros, y la remediación de amenazas. Algunas herramientas de vanguardia ofrecen funcionalidades adicionales para crear flujos de trabajo de respuesta, normalización de datos y protección avanzada contra amenazas.

 

Las plataformas SIEM ayudan a los programas de seguridad a operar recopilando datos de seguridad para análisis futuros, almacenando estos puntos de datos, correlacionándolos con eventos de seguridad y facilitando el análisis de esos eventos.

 

Los equipos de seguridad pueden definir reglas para actividades típicas y sospechosas con herramientas SIEM. Las soluciones avanzadas de SIEM de próxima generación aprovechan el [aprendizaje automático](https://www.g2.com/articles/what-is-machine-learning) y la [IA](https://www.g2.com/articles/what-is-artificial-intelligence) para refinar continuamente los modelos de comportamiento, mejorando el [análisis del comportamiento de usuarios y entidades (UEBA)](https://www.g2.com/categories/user-and-entity-behavior-analytics-ueba) y reduciendo los falsos positivos. Estos sistemas analizan los datos en función de reglas establecidas y patrones de comportamiento, señalando eventos notables cuando se detectan anomalías.

 

Las empresas que utilizan soluciones SIEM despliegan sensores en activos digitales para automatizar la recopilación de datos. Los sensores transmiten información de vuelta a la base de datos de registros y eventos del SIEM. Cuando surgen incidentes de seguridad adicionales, la plataforma SIEM detecta anomalías. Correlaciona registros similares para proporcionar contexto e información sobre amenazas a los equipos de seguridad mientras intentan remediar cualquier amenaza o vulnerabilidad existente.

 
#### **¿Qué significa SIEM?**
 

SIEM significa gestión de información y eventos de seguridad (SIEM), que es una combinación de dos acrónimos diferentes para tecnología de seguridad: monitoreo de información de seguridad (SIM) y gestión de eventos de seguridad (SEM).

 

SIM es la práctica de recopilar, agregar y analizar datos de seguridad, típicamente en forma de registros. Las herramientas SIM automatizan este proceso y documentan la información de seguridad para otras fuentes, como [sistemas de detección de intrusiones](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps), [cortafuegos](https://www.g2.com/categories/firewall-software) o [enrutadores](https://www.g2.com/categories/routers). Los registros de eventos y sus componentes informativos asociados se registran y almacenan durante largos períodos para análisis retrospectivos o requisitos de cumplimiento.

 

SEM es una familia de software de seguridad para descubrir, analizar, visualizar y responder a amenazas a medida que surgen. SEM es un componente central de un sistema de operaciones de seguridad. Mientras que las herramientas SIM están diseñadas para la recopilación y almacenamiento de registros, las herramientas SEM generalmente dependen de bases de datos SQL para almacenar registros específicos y otros datos de eventos a medida que se generan en tiempo real por dispositivos de seguridad y sistemas de TI. Por lo general, también proporcionan la funcionalidad para correlacionar y analizar datos de eventos, monitorear sistemas en tiempo real y alertar a los equipos de seguridad sobre actividades anormales.

 

SIEM combina la funcionalidad de SIM y SEM para centralizar el control sobre el almacenamiento de registros, la gestión de eventos y el análisis en tiempo real. SIM y SEM se han convertido en tecnologías obsoletas, ya que el auge de SIEM ha proporcionado una funcionalidad de doble propósito. Los proveedores de SIEM ofrecen una única herramienta capaz de realizar la agregación de datos, la correlación de información y la gestión de eventos.

 

### Tipos de soluciones SIEM
 
#### **SIEM tradicional**
 

Las herramientas SIEM tradicionales se despliegan en las instalaciones con sensores colocados en activos de TI para analizar eventos y recopilar registros del sistema. Los datos se utilizan para desarrollar referencias de base e identificar indicadores de compromiso. El producto SIEM alerta a los equipos de seguridad para que intervengan cuando un sistema se ve comprometido.&nbsp;

 
#### **SIEM en la nube o virtual**
 

El software SIEM basado en la nube y virtualizado son herramientas que se utilizan típicamente para asegurar la infraestructura en la nube y los servicios que un proveedor de nube ofrece. Estas herramientas suelen ser menos costosas que las soluciones en las instalaciones y más accesibles de implementar, ya que no se requiere trabajo físico. Son ideales para empresas sin infraestructura de TI local.

 
#### [**Servicios SIEM gestionados**](https://www.g2.com/categories/managed-siem-services)
 

Las empresas que no tienen un programa de seguridad completo pueden optar por servicios SIEM gestionados para ayudar en la gestión y reducir el trabajo para los empleados internos. Estos servicios SIEM son proporcionados por proveedores de servicios gestionados que proporcionan al cliente datos y paneles con información y actividad de seguridad, pero el proveedor se encarga de la implementación y la remediación.&nbsp;

 

### ¿Cuáles son las características comunes de los sistemas SIEM?
 

Las siguientes son algunas características principales dentro del software SIEM que pueden ayudar a los usuarios a recopilar datos de seguridad, analizar registros y detectar amenazas:

 

**Monitoreo de actividad:** Los sistemas SIEM documentan las acciones de los puntos finales dentro de una red. El sistema alerta a los usuarios sobre incidentes y actividades anormales y documenta el punto de acceso. El seguimiento en tiempo real documentará estos para su análisis a medida que se produzca un evento.

 

**Gestión de activos:** Estas características de SIEM mantienen registros de cada activo de la red y su actividad. La característica también puede referirse al descubrimiento de nuevos activos que acceden a la red.

 

**Gestión de registros:** Esta funcionalidad documenta y almacena registros de eventos en un repositorio seguro para referencia, análisis o razones de cumplimiento.

 

**Gestión de eventos:** A medida que ocurren eventos en tiempo real, el software SIEM alerta a los usuarios sobre incidentes. Esto permite a los equipos de seguridad intervenir manualmente o activar una respuesta automatizada para resolver el problema.

 

[**Respuesta automatizada**](https://www.g2.com/categories/security-information-and-event-management-siem/f/automated-response) **:** La automatización de la respuesta reduce el tiempo dedicado a diagnosticar y resolver problemas manualmente. Las características son típicamente capaces de resolver rápidamente incidentes comunes de seguridad de la red.

 

**Informe de incidentes:** Los informes de incidentes documentan casos de actividad anormal y sistemas comprometidos. Estos pueden ser utilizados para análisis forense o como punto de referencia para futuros incidentes.

 

**Inteligencia de amenazas:** Los feeds de inteligencia de amenazas integran información para entrenar a los sistemas SIEM a detectar amenazas emergentes y existentes. Estos feeds de amenazas almacenan información relacionada con amenazas y vulnerabilidades potenciales para asegurar que se descubran problemas y se proporcione a los equipos la información necesaria para resolver los problemas a medida que ocurren.

 

[**Evaluación de vulnerabilidades**](https://www.g2.com/categories/security-information-and-event-management-siem/f/vulnerability-assessment) **:** Las herramientas de evaluación de vulnerabilidades pueden escanear redes en busca de vulnerabilidades potenciales o auditar datos para descubrir prácticas no conformes. Principalmente, se utilizan para analizar una red existente y la infraestructura de TI para delinear puntos de acceso que pueden ser fácilmente comprometidos.

 

[**Análisis avanzado**](https://www.g2.com/categories/security-information-and-event-management-siem/f/advanced-analytics) **:** Las características de análisis avanzado permiten a los usuarios personalizar el análisis con métricas granulares o individualmente específicas pertinentes a los recursos del negocio.

 

[**Examinación de datos**](https://www.g2.com/categories/security-information-and-event-management-siem/f/data-examination) **:** Las características de examinación de datos típicamente facilitan el análisis forense de datos de incidentes y registros de eventos. Estas características permiten a los usuarios buscar en bases de datos y registros de incidentes para obtener información sobre vulnerabilidades e incidentes.

 

### ¿Cuáles son los beneficios de usar productos SIEM?

A continuación se presentan algunas de las principales razones por las que el software SIEM se utiliza comúnmente para proteger empresas de todos los tamaños:

**Agregación y correlación de datos:** Los sistemas SIEM y las empresas recopilan grandes cantidades de información de todo un entorno de red. Esta información se recopila de prácticamente cualquier cosa que interactúe con una red, desde puntos finales y servidores hasta cortafuegos y herramientas antivirus. Se entrega directamente al SIEM o utilizando agentes (programas de toma de decisiones diseñados para identificar información irregular). La plataforma está configurada para desplegar agentes y recopilar y almacenar información similar junta de acuerdo con las políticas de seguridad establecidas por los administradores.

**Alerta de incidentes:** A medida que la información llega de los diversos componentes conectados de una red, el sistema SIEM la correlaciona utilizando políticas basadas en reglas. Estas políticas informan a los agentes sobre el comportamiento normal y las amenazas. Si alguna acción viola estas políticas o se descubre malware o intrusión. Al mismo tiempo, la plataforma SIEM monitorea la actividad de la red; se etiqueta como sospechosa, los controles de seguridad restringen el acceso y se alerta a los administradores.

**Análisis de seguridad:** Se puede realizar un análisis retrospectivo buscando datos de registros durante períodos específicos o basándose en criterios específicos. Los equipos de seguridad pueden sospechar que una cierta mala configuración o tipo de malware causó un evento. También pueden sospechar que una parte no aprobada pasó desapercibida en un momento específico. Los equipos analizarán los registros y buscarán características específicas en los datos para determinar si su sospecha era correcta. También pueden descubrir vulnerabilidades o malas configuraciones que los dejan susceptibles a ataques y remediarlas.

### Software relacionado con herramientas SIEM

Muchas soluciones de seguridad de red y sistema implican la recopilación y análisis de registros de eventos e información de seguridad. Los sistemas SIEM son típicamente las soluciones más completas disponibles, pero muchas otras soluciones de seguridad pueden integrarse con ellos para obtener funcionalidad adicional o uso complementario. Estas son algunas categorías de tecnología relacionadas con el software SIEM.

[Software de inteligencia de amenazas](https://www.g2.com/categories/threat-intelligence) **:** El software de inteligencia de amenazas es un servicio informativo que proporciona a las herramientas SIEM y otros sistemas de seguridad de la información información actualizada sobre amenazas basadas en la web. Pueden informar al sistema sobre amenazas de día cero, nuevas formas de malware, posibles exploits y diferentes tipos de vulnerabilidades.

[Software de respuesta a incidentes](https://www.g2.com/categories/incident-response) **:** Los sistemas SIEM pueden facilitar la respuesta a incidentes, pero estas herramientas están específicamente diseñadas para agilizar el proceso de remediación o agregar capacidades de investigación durante los procesos de flujo de trabajo de seguridad. Las soluciones de respuesta a incidentes no proporcionarán las mismas capacidades de mantenimiento de cumplimiento o almacenamiento de registros. Aun así, pueden usarse para aumentar la capacidad de un equipo para abordar amenazas a medida que surgen.

[Software de gestión de políticas de seguridad de red (NSPM)](https://www.g2.com/categories/network-security-policy-management-nspm) **:** El software NSPM tiene algunas funcionalidades superpuestas para garantizar que el hardware de seguridad y los sistemas de TI estén configurados correctamente, pero no pueden detectar y resolver amenazas. Se utilizan típicamente para asegurar que dispositivos como cortafuegos o filtros DNS funcionen correctamente y en alineación con las reglas de seguridad establecidas por los equipos de seguridad.

[Sistemas de detección y prevención de intrusiones (IDPS)](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps) **:** Mientras que los sistemas SIEM se especializan en la gestión de registros, alertas y correlación, los IDPS proporcionan características adicionales de detección y protección para prevenir que partes no aprobadas accedan a sistemas sensibles y violaciones de red. Sin embargo, no facilitarán el análisis y la investigación forense de registros con el mismo nivel de detalle que un sistema SIEM.

[Proveedores de servicios de seguridad gestionados](https://www.g2.com/categories/managed-security-services) **:** Hay varios servicios de seguridad gestionados disponibles para empresas sin los recursos o el personal necesario para operar un equipo completo de administración y operaciones de seguridad. Los servicios gestionados son una opción viable y proporcionarán a las empresas personal capacitado para proteger los sistemas de sus clientes y mantener su información sensible protegida.

### Desafíos con el software SIEM

**Personal:** Existe una escasez actual de profesionales de seguridad capacitados. Gestionar productos SIEM y mantener una postura de seguridad bien equilibrada requiere personal dedicado con habilidades altamente especializadas. Algunas empresas más pequeñas o en crecimiento pueden no tener los medios para reclutar, contratar y retener profesionales de seguridad calificados. En tales casos, las empresas pueden considerar servicios gestionados para subcontratar el trabajo.&nbsp;

**Cumplimiento:** Algunas industrias tienen requisitos de cumplimiento específicos determinados por varios organismos gubernamentales, pero el software SIEM puede usarse en varias industrias para mantener estándares de cumplimiento. Existen muchos requisitos de cumplimiento específicos de la industria, pero la mayoría requiere que los equipos de seguridad protejan datos sensibles, restrinjan el acceso a partes no aprobadas y monitoreen los cambios realizados en identidades, información o privilegios. Por ejemplo, los sistemas SIEM pueden mantener el cumplimiento del GDPR verificando los controles de seguridad y el acceso a datos, facilitando el almacenamiento a largo plazo de datos de registros y notificando al personal de seguridad sobre incidentes de seguridad, como lo requiere el GDPR.

### ¿Qué empresas deberían comprar soluciones SIEM?

**Industrias verticales:** Las industrias verticales, como la atención médica y los servicios financieros, a menudo tienen requisitos de cumplimiento adicionales relacionados con la protección de datos y la privacidad. SIEM es una solución ideal para delinear requisitos, mapear amenazas y remediar vulnerabilidades.&nbsp;

**Negocios SaaS:** Las empresas SaaS que utilizan recursos de un proveedor de servicios en la nube siguen siendo responsables de una parte significativa de los esfuerzos de seguridad necesarios para proteger un negocio nativo de la nube. Estas empresas pueden optar por herramientas SIEM nativas de la nube, pero se beneficiarán de cualquier SIEM para prevenir, detectar y responder a amenazas.&nbsp;

### Cómo elegir el mejor software SIEM

#### Recolección de requisitos (RFI/RFP) para el software de gestión de información y eventos de seguridad (SIEM)

El primer paso para comprar una solución SIEM es delinear las opciones. Las empresas deben asegurarse de si necesitan una solución basada en la nube o en las instalaciones. También deben delinear el número de dispositivos interconectados que necesitan y si desean sensores físicos o virtuales para asegurarlos. Los requisitos adicionales y posiblemente obvios deben incluir consideraciones presupuestarias, limitaciones de personal e integraciones requeridas_.&nbsp;_

#### **Comparar productos de software de gestión de información y eventos de seguridad (SIEM)**

##### **Crear una lista larga**

Una vez que se han delineado los requisitos, los compradores deben priorizar las herramientas e identificar las que tengan tantas características como sea posible que se ajusten al presupuesto. Se recomienda restringir la lista a productos con características deseadas, precios y métodos de implementación para identificar una docena o más de opciones. Por ejemplo, si el negocio necesita un SIEM nativo de la nube por menos de $10k al año, la mitad de las opciones de SIEM se eliminarán.&nbsp;

Al elegir un proveedor de SIEM, concéntrate en la experiencia del proveedor, su reputación y la funcionalidad específica relevante para tus necesidades de seguridad. Las capacidades básicas aseguran la detección esencial de amenazas, mientras que las características de próxima generación añaden inteligencia avanzada y automatización, permitiendo una postura de seguridad más proactiva. Aquí tienes un desglose para guiar tu selección:

**Capacidades básicas de SIEM**

- Detección de amenazas: Busca SIEMs con una detección de amenazas robusta, que utilice reglas y análisis de comportamiento, junto con la integración de feeds de amenazas, para identificar con precisión amenazas potenciales.
- Inteligencia de amenazas y alertas de seguridad: Los SIEMs líderes incorporan feeds de inteligencia de amenazas, agregan datos de seguridad y te alertan cuando se detectan actividades sospechosas, asegurando actualizaciones en tiempo real sobre amenazas en evolución.
- Informes de cumplimiento: El soporte de cumplimiento es crucial, especialmente para cumplir con estándares como HIPAA, PCI y FFIEC. Los SIEMs agilizan la evaluación y el informe de cumplimiento, ayudando a prevenir costosos incumplimientos.
- Notificaciones en tiempo real: Las alertas rápidas son vitales; los SIEMs que te notifican de violaciones inmediatamente permiten respuestas más rápidas a amenazas potenciales.
- Agregación de datos: Una vista centralizada de todas las actividades de la red asegura que ninguna área quede sin monitorear, lo cual es crucial para una visibilidad completa de amenazas a medida que tu organización escala.
- Normalización de datos: Los SIEMs que normalizan los datos entrantes facilitan el análisis de eventos de seguridad y la extracción de información procesable de fuentes dispares.

**Capacidades de SIEM de próxima generación**

- Recopilación y gestión de datos: Los SIEMs de próxima generación extraen datos de la nube, en las instalaciones y dispositivos externos, consolidando información en todo el entorno de TI.
- Entrega en la nube: Los SIEMs basados en la nube utilizan almacenamiento escalable, acomodando grandes volúmenes de datos sin las limitaciones del hardware en las instalaciones.
- Análisis del comportamiento de usuarios y entidades (UEBA): Al establecer el comportamiento normal de los usuarios e identificar desviaciones, UEBA ayuda a detectar amenazas internas y nuevas amenazas desconocidas.
- Orquestación de seguridad y respuesta automatizada (SOAR): SOAR automatiza la respuesta a incidentes, se integra con la infraestructura de TI y permite respuestas coordinadas en cortafuegos, servidores de correo electrónico y controles de acceso.
- Líneas de tiempo de ataques automatizadas: Los SIEMs de próxima generación crean automáticamente líneas de tiempo visuales de ataques, simplificando la investigación y el triaje, incluso para analistas menos experimentados.

Seleccionar un proveedor de SIEM con capacidades tanto básicas como de próxima generación ofrece a tu organización un enfoque integral y ágil para la seguridad, cumpliendo con los requisitos actuales y futuros.

##### **Crear una lista corta**

Reducir una lista corta puede ser complicado, especialmente para los indecisos, pero estas decisiones deben tomarse. Una vez que la lista larga se limita a productos asequibles con las características deseadas, es hora de buscar validación de terceros. Para cada herramienta, el comprador debe analizar las reseñas de los usuarios finales, los informes de analistas y las evaluaciones empíricas de seguridad. La combinación de estos factores especificados debería ayudar a clasificar las opciones y eliminar productos de bajo rendimiento. _&nbsp;_

##### **Realizar demostraciones**

Con la lista reducida a tres a cinco productos posibles, las empresas pueden contactar a los proveedores y programar demostraciones. Esto les ayudará a obtener experiencia de primera mano con el producto, hacer preguntas específicas y evaluar la calidad del servicio de los proveedores.&nbsp;

Aquí hay algunas preguntas esenciales para guiar tu decisión:

- ¿Mejorará la herramienta la recopilación y gestión de registros?: 

La recopilación efectiva de registros es fundamental. Busca software compatible en todos los sistemas y dispositivos, que ofrezca un panel de control fácil de usar para un monitoreo simplificado.

- ¿La herramienta apoya los esfuerzos de cumplimiento?

Incluso si el cumplimiento no es una prioridad, elegir un SIEM que facilite la auditoría y el informe puede preparar tus operaciones para el futuro. Busca herramientas que simplifiquen los procesos y el informe de cumplimiento.

- ¿Puede la herramienta aprovechar eventos de seguridad pasados en la respuesta a amenazas?

Una de las fortalezas de SIEM es usar datos históricos para informar la detección de amenazas futuras. Asegúrate de que la herramienta ofrezca análisis en profundidad y capacidades de profundización para analizar y actuar sobre incidentes pasados.

- ¿Es rápida y automatizada la respuesta a incidentes?

Las respuestas oportunas y efectivas son críticas. La herramienta debe proporcionar alertas personalizables que notifiquen a tu equipo inmediatamente cuando sea necesario para que puedas dejar el panel de control con confianza.&nbsp;

#### Selección de software de gestión de información y eventos de seguridad (SIEM)

##### **Elegir un equipo de selección**

Los responsables de la toma de decisiones deben involucrar a expertos en la materia de todos los equipos que utilizarán el sistema al elegir un equipo de selección. Para el software de respaldo, esto involucra principalmente a gerentes de producto, desarrolladores, TI y personal de seguridad. Cualquier gerente o líder de departamento también debe incluir a las personas que gestionan cualquier solución con la que el producto de respaldo se integrará.&nbsp;

##### **Negociación**

La antigüedad del equipo de negociación puede variar dependiendo de la madurez del negocio. Se recomienda incluir a directores o gerentes relevantes de los departamentos de seguridad y TI, así como de cualquier otro departamento transversal que pueda verse afectado.

##### **Decisión final**

Si la empresa tiene un director de seguridad de la información (CISO), es probable que esa persona tome la decisión.&nbsp;Si no, las empresas deben confiar en la capacidad de sus profesionales de seguridad para usar y entender el producto.&nbsp;

### ¿Cuánto cuesta el software SIEM?

El crecimiento potencial debe considerarse si el comprador elige una herramienta SIEM basada en la nube que ofrece precios en el modelo SaaS de pago por uso. Algunas soluciones son económicas al principio y ofrecen precios de bajo nivel asequibles. Alternativamente, algunas pueden aumentar rápidamente los precios y tarifas a medida que la empresa y la necesidad de almacenamiento escalan. Algunos proveedores ofrecen productos de respaldo permanentemente gratuitos para individuos o equipos pequeños.

**SIEM en la nube_:_** El precio de SIEM como servicio puede variar, pero tradicionalmente escala a medida que aumenta el almacenamiento. Los costos adicionales pueden provenir de características aumentadas como remediación automatizada, orquestación de seguridad e inteligencia de amenazas integrada.&nbsp;

**SIEM en las instalaciones:** Las soluciones en las instalaciones son típicamente más costosas y requieren más esfuerzo y recursos. También serán más costosas de mantener y requerirán personal dedicado. Aun así, las empresas con altos requisitos de cumplimiento deben adoptar seguridad en las instalaciones independientemente.&nbsp;

#### Retorno de la inversión (ROI)

Las soluciones SIEM basadas en la nube proporcionarán un ROI más rápido, similar a su menor costo promedio. La situación es bastante clara ya que hay una inversión inicial mucho menor y una menor demanda de personal dedicado.&nbsp;

Sin embargo, para los sistemas en las instalaciones, el ROI dependerá de la escala y el alcance de los sistemas de TI del negocio. Cientos de servidores requerirán cientos de sensores, potencialmente más, a medida que el tiempo desgaste el equipo de computación. Una vez implementados, deben ser operados y mantenidos por profesionales de seguridad (costosos).