# Best Security Information and Event Management (SIEM) Software Solutions

## How Many Security Information and Event Management (SIEM) Software Products Does G2 Track?

**Total Products under this Category:** 123

### Category Stats (Aug 2026)

- **Average Rating:** 4.46/5 (↑0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+23.8%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank Security Information and Event Management (SIEM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 5,900+ Authentic Reviews
- 123+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Security Information and Event Management (SIEM) Software
 ![G2 Grid® for Security Information and Event Management (SIEM) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/security-information-and-event-management-siem/grids.png?focus%5B%5D=68606&focus%5B%5D=30500&focus%5B%5D=1430041&focus%5B%5D=5691&focus%5B%5D=10436&focus%5B%5D=53174&focus%5B%5D=58203&focus%5B%5D=122123)

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Google Security Operations, Palo Alto Cortex XSIAM, ManageEngine ADAudit Plus, Sumo Logic, Todyl Security Platform, Check Point Infinity Platform, and Microsoft Sentinel.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-information-and-event-management-siem/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=google-security-operations&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=manageengine-adaudit-plus&focus%5B%5D=sumo-logic&focus%5B%5D=todyl-security-platform&focus%5B%5D=check-point-infinity-platform&focus%5B%5D=microsoft-sentinel)

**Sponsored**

### AWS Glue

AWS Glue is a serverless data integration service that makes it easier for analytics users to discover, prepare, move, and integrate data from multiple sources for analytics, machine learning, and application develop-ment. You can discover and connect to 70+ diverse data sources, manage your data in a centralized data catalog, and visually create, run, and monitor ETL pipelines to load data into your data lakes. You can im-mediately search and query catalogued data using Amazon Athena, Amazon EMR, and Amazon Redshift Spectrum.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1081&secure%5Bchosen_at%5D=2026-08-13T12%3A53%3A28Z&secure%5Bdisplayable_resource_id%5D=2838&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=40849&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=40849&secure%5Bresource_id%5D=1081&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-information-and-event-management-siem&secure%5Btoken%5D=59b26f8b685a87f555a24db8fb7fec116e277dddd3dfe81ff9ec9518db20090e&secure%5Burl%5D=https%3A%2F%2Faws.amazon.com%2Fglue%2F%3Ftrk%3D5f10e0f2-36c8-4421-b616-5578db3fe15e%26sc_channel%3Ddisplay%2Bads&secure%5Burl_type%5D=custom_url)

### [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/it/products/crowdstrike-falcon-endpoint-protection-platform/reviews)

Le organizzazioni oggi affrontano una sfida seria: gestire numerosi fornitori e strumenti di sicurezza mentre si confrontano con un panorama di minacce in continua evoluzione. Gli avversari sofisticati stanno diventando più intelligenti, veloci e sfuggenti, lanciando attacchi complessi che possono colpire in minuti o addirittura secondi. Gli approcci di sicurezza tradizionali faticano a tenere il passo, lasciando le aziende vulnerabili. La piattaforma CrowdStrike Falcon affronta questo problema offrendo una soluzione unificata e nativa del cloud. Consolida soluzioni di sicurezza precedentemente isolate e incorpora dati di terze parti in un'unica piattaforma con un agente efficiente e attento alle risorse, sfruttando l'IA avanzata e l'intelligence sulle minacce in tempo reale. Questo approccio semplifica le operazioni di sicurezza, accelera il processo decisionale degli analisti e migliora la protezione per fermare la violazione, permettendo alle organizzazioni di ridurre il rischio con meno complessità e costi inferiori. La piattaforma Falcon di CrowdStrike include: - Sicurezza degli endpoint: Proteggi l'endpoint, ferma la violazione - Protezione dell'identità: L'identità è la prima linea, difendila - SIEM di nuova generazione: Il futuro del SIEM, oggi - Protezione dei dati: Protezione dei dati in tempo reale dall'endpoint al cloud - Gestione dell'esposizione: Comprendi il rischio per fermare le violazioni - Charlotte AI: Alimentando la prossima evoluzione del SOC

**Average Rating:** 4.6/5.0

**Total Reviews:** 418

#### How Do G2 Users Rate CrowdStrike Falcon Endpoint Protection Platform?

- **Monitoraggio delle attività:** 9.5/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.8/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 9.0/10 (Category avg: 8.7/10)
- **Gestione dei log:** 8.7/10 (Category avg: 9.1/10)

#### Who Is the Company Behind CrowdStrike Falcon Endpoint Protection Platform?

- **Venditore:** [CrowdStrike](https://www.g2.com/it/sellers/crowdstrike)
- **Sito web dell'azienda:** www.crowdstrike.com
- **Anno di Fondazione:** 2011
- **Sede centrale:** Sunnyvale, CA
- **Twitter:** @CrowdStrike  
110,809 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f13dce0bc1628ccb762ed9d5acb4e0f0998a717639b903c3d3a271ef1da6ad7b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2497653%2F&secure%5Burl_type%5D=linkedin_company_website)  
11,343 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Analyst, Cyber Security Analyst
- **Top Industries:** Tecnologia dell'informazione e servizi, Sicurezza informatica e di rete
- **Company Size:** 43% Large, 42% Medium

#### What Do G2 Reviewers Say About CrowdStrike Falcon Endpoint Protection Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano le **prestazioni leggere e la potente rilevazione delle minacce** di CrowdStrike Falcon, migliorando l'efficienza operativa e la sicurezza.
- Gli utenti apprezzano la **rilevazione efficace delle minacce** di CrowdStrike Falcon, garantendo una sicurezza robusta senza compromettere le prestazioni del sistema.
- Gli utenti apprezzano la **facilità d'uso** di CrowdStrike Falcon, beneficiando di una soluzione di sicurezza leggera ed efficiente.
- Gli utenti apprezzano la **protezione avanzata in tempo reale dalle minacce** di CrowdStrike Falcon, migliorando la sicurezza con un impatto minimo sul sistema.
- Gli utenti apprezzano la **forte rilevazione delle minacce** di CrowdStrike Falcon, che cattura efficacemente sia le minacce conosciute che quelle sconosciute senza problemi.

##### Cons

- Gli utenti trovano il **costo di CrowdStrike Falcon** elevato, specialmente per i team più piccoli che necessitano di funzionalità avanzate.
- Gli utenti affrontano **una complessità iniziale e una curva di apprendimento ripida** con CrowdStrike Falcon, rendendolo impegnativo per il personale non tecnico.
- Gli utenti trovano **la curva di apprendimento iniziale** di CrowdStrike impegnativa, soprattutto nel passaggio da altri sistemi come Splunk.
- Gli utenti trovano **frustrante l'alto costo e le funzionalità limitate** , in particolare per i team più piccoli che necessitano di capacità avanzate.
- Gli utenti esprimono preoccupazione per **problemi di prezzo** , specialmente per le organizzazioni più piccole che necessitano di funzionalità avanzate con costi di licenza aggiuntivi.

#### What Are Recent G2 Reviews of CrowdStrike Falcon Endpoint Protection Platform?

**["Crowdstrike Falcon: Sicurezza Proattiva, Curva di Apprendimento Ripida"](https://www.g2.com/it/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)**

**Rating:** 5.0/5.0 stars

_— Ansh B._

[Read full review](https://www.g2.com/it/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)

**["Distribuzione Leggera, Potente Visibilità di Risposta agli Incidenti"](https://www.g2.com/it/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12952621)**

**Rating:** 5.0/5.0 stars

_— Anup A._

[Read full review](https://www.g2.com/it/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12952621)

#### What Are G2 Users Discussing About CrowdStrike Falcon Endpoint Protection Platform?

- [Come impedisce Falcon il lavoro?](https://www.g2.com/it/discussions/how-does-falcon-prevent-work) - 1 comment
- [CrowdStrike offre l'autenticazione a più fattori (MFA)?](https://www.g2.com/it/discussions/does-crowdstrike-offer-mfa) - 1 comment
- [Che cos'è OverWatch in CrowdStrike?](https://www.g2.com/it/discussions/what-is-overwatch-in-crowdstrike) - 1 comment
- [How much does CrowdStrike Falcon X cost?](https://www.g2.com/it/discussions/how-much-does-crowdstrike-falcon-x-cost)
- [What is MDR detection?](https://www.g2.com/it/discussions/what-is-mdr-detection)

### [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)

Google Security Operations offers a unified experience across SIEM, SOAR, and threat intelligence to drive better detection, investigation, and response. Collect security telemetry data, apply threat intel to identify high priority threats, drive response with playbook automation, case management, and collaboration. It also provides Gemini-native agentic defense to help autonomously handle workflows like alert triage, threat hunting, and detection engineering. Google Security Operations also supports AI Threat Defense to monitor, detect, and respond to threats from code you do not own or cannot patch.

**Average Rating:** 4.4/5.0

**Total Reviews:** 73

#### How Do G2 Users Rate Google Security Operations?

- **Activity Monitoring:** 9.8/10 (Category avg: 9.1/10)
- **Data Examination:** 9.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.3/10 (Category avg: 8.7/10)
- **Log Management:** 9.6/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Google Security Operations?

- **Seller:** [Google](https://www.g2.com/sellers/google)
- **Year Founded:** 1998
- **HQ Location:** Mountain View, CA
- **Twitter:** @google  
31,899,995 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fe4a5936665c9702418dd53c477fef5a7baea08078bb117ed67e966fc581b9ec&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1441%2F&secure%5Burl_type%5D=linkedin_company_website)  
341,888 employees on LinkedIn®
- **Ownership:** NASDAQ:GOOG

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Medium, 37% Large

#### What Do G2 Reviewers Say About Google Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **excellent cybersecurity features** of Google Security Operations, appreciating its ease of use and scalability.
- Users find Google Security Operations to be **very easy to use** , effectively detecting threats with seamless integration.
- Users appreciate the **efficient threat detection** capabilities of Google Security Operations, enhancing security and response times.
- Users value the **comprehensive security** features of Google Security Operations for effective threat detection and response.
- Users value the **easy integrations** of Google Security Operations, enhancing their overall security management experience.

##### Cons

- Users find Google Security Operations to be **costly and complex** , posing challenges for both setup and ongoing maintenance.
- Users report a **steep learning curve** with Google Security Operations, making effective utilization challenging for some organizations.
- Users find the **implementation complexity** of Google Security Operations challenging, requiring time and resources for effective use.
- Users find the **learning difficulty** of Google Security Operations to be a barrier due to complex features and configuration.
- Users find **limited customization** in Google Security Operations hinders adaptability and affects overall user experience.

#### What Are Recent G2 Reviews of Google Security Operations?

**["Unified, AI-Powered Security Operations with Fast Performance and Seamless Google Integrations"](https://www.g2.com/survey_responses/google-security-operations-review-13254539)**

**Rating:** 4.0/5.0 stars

_— Hatim B._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13254539)

**["Powerful Dashboard, Automation & AI Insights—But a Steep Learning Curve"](https://www.g2.com/survey_responses/google-security-operations-review-13239114)**

**Rating:** 4.5/5.0 stars

_— Parthik P._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13239114)

### [Palo Alto Cortex XSIAM](https://www.g2.com/it/products/palo-alto-cortex-xsiam/reviews)

Descrizione del Prodotto: Cortex XSIAM di Palo Alto Networks è una piattaforma di operazioni di sicurezza guidata dall'IA progettata per trasformare i tradizionali Centri Operativi di Sicurezza integrando e automatizzando funzioni chiave come la centralizzazione dei dati, il rilevamento delle minacce e la risposta agli incidenti. Sfruttando l'apprendimento automatico e l'automazione, consente alle organizzazioni di rilevare e rispondere alle minacce in modo più efficiente, riducendo i carichi di lavoro manuali e migliorando la postura complessiva della sicurezza. Caratteristiche e Funzionalità Principali: - Centralizzazione dei Dati: Aggrega i dati da varie fonti in una piattaforma unificata, fornendo una visibilità completa in tutta l'impresa. - Rilevamento delle Minacce Alimentato dall'IA: Utilizza algoritmi di apprendimento automatico per identificare anomalie e potenziali minacce in tempo reale. - Risposta agli Incidenti Automatizzata: Semplifica i processi di risposta attraverso l'automazione, consentendo una rapida mitigazione degli incidenti di sicurezza. - Capacità SOC Integrate: Combina funzioni come Rilevamento e Risposta Estesi, Orchestrazione della Sicurezza, Automazione e Risposta, Gestione della Superficie di Attacco e Gestione delle Informazioni e degli Eventi di Sicurezza in una piattaforma coesa, eliminando la necessità di più strumenti disparati. - Scalabilità: Progettato per gestire grandi volumi di dati e adattarsi alle esigenze in evoluzione delle imprese moderne. Valore Primario e Problema Risolto: Cortex XSIAM affronta le sfide dei dati disgiunti, della debole difesa dalle minacce e della forte dipendenza dal lavoro manuale nei SOC tradizionali. Centralizzando i dati e automatizzando le operazioni di sicurezza, semplifica i processi, migliora l'accuratezza del rilevamento delle minacce e accelera i tempi di risposta agli incidenti. Questa trasformazione consente alle organizzazioni di superare proattivamente le minacce, ridurre i costi operativi e raggiungere una postura di sicurezza più robusta.

**Average Rating:** 4.5/5.0

**Total Reviews:** 83

#### How Do G2 Users Rate Palo Alto Cortex XSIAM?

- **Monitoraggio delle attività:** 9.3/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.5/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.6/10 (Category avg: 8.7/10)
- **Gestione dei log:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Palo Alto Cortex XSIAM?

- **Venditore:** [Palo Alto Networks](https://www.g2.com/it/sellers/palo-alto-networks)
- **Sito web dell'azienda:** www.paloaltonetworks.com
- **Anno di Fondazione:** 2005
- **Sede centrale:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Tecnologia dell'informazione e servizi, Sicurezza informatica e di rete
- **Company Size:** 44% Large, 38% Medium

#### What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti evidenziano **la gestione dei log di prim'ordine** e le funzionalità di allerta efficaci, migliorando l'usabilità e l'integrazione complessive.
- Gli utenti apprezzano i **dashboard intuitivi** di Palo Alto Cortex XSIAM, evidenziando la facilità di comprensione degli avvisi e delle metriche.
- Gli utenti apprezzano le capacità di **monitoraggio in tempo reale** di Palo Alto Cortex XSIAM, migliorando l'efficienza del rilevamento e della risposta alle minacce.
- Gli utenti apprezzano l' **interfaccia intuitiva** di Palo Alto Cortex XSIAM, rendendo il monitoraggio e la distribuzione senza soluzione di continuità ed efficiente.
- Gli utenti apprezzano la **buona personalizzazione del cruscotto** in Palo Alto Cortex XSIAM, citando la facilità d'uso e l'integrazione.

##### Cons

- Gli utenti trovano la soluzione **intensiva in termini di risorse** , aumentando i costi e complicando l'implementazione a causa dei requisiti hardware elevati.
- Gli utenti trovano l' **implementazione complessa** di Palo Alto Cortex XSIAM dispendiosa in termini di tempo e risorse, richiedendo una significativa competenza tecnica.
- Gli utenti trovano che il **costo** di Palo Alto Cortex XSIAM sia più alto rispetto ai concorrenti, influenzando l'accessibilità economica per le aziende più piccole.
- Gli utenti segnalano **problemi con il cruscotto** che ostacolano il monitoraggio e creano un'interfaccia disordinata, influenzando l'usabilità e la visibilità.
- Gli utenti hanno difficoltà con la **configurazione difficile** di Palo Alto Cortex XSIAM, trovandola complessa e dispendiosa in termini di tempo per l'implementazione.

#### What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

**["Monitoraggio della sicurezza efficiente con potente automazione"](https://www.g2.com/it/survey_responses/palo-alto-cortex-xsiam-review-13129157)**

**Rating:** 4.0/5.0 stars

_— Anas M._

[Read full review](https://www.g2.com/it/survey_responses/palo-alto-cortex-xsiam-review-13129157)

**["Palo Alto Cortex XSIAM: Sicurezza Centralizzata con Potente Automazione AI"](https://www.g2.com/it/survey_responses/palo-alto-cortex-xsiam-review-13174734)**

**Rating:** 4.5/5.0 stars

_— Tim H._

[Read full review](https://www.g2.com/it/survey_responses/palo-alto-cortex-xsiam-review-13174734)

#### What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

- [A cosa serve IBM Security ReaQta?](https://www.g2.com/it/discussions/what-is-ibm-security-reaqta-used-for) - 1 comment
- [What does QRadar stand for?](https://www.g2.com/it/discussions/what-does-qradar-stand-for) - 1 comment, 1 upvote
- [Come faccio a usare IBM QRadar?](https://www.g2.com/it/discussions/how-do-i-use-ibm-qradar) - 1 comment
- [Quali sono i componenti chiave di IBM QRadar?](https://www.g2.com/it/discussions/what-are-the-key-component-of-ibm-qradar) - 1 comment
- [Che cos'è IBM QRadar Siem?](https://www.g2.com/it/discussions/what-is-ibm-qradar-siem) - 1 comment

### [ManageEngine ADAudit Plus](https://www.g2.com/it/products/manageengine-adaudit-plus/reviews)

ADAudit Plus è un auditor guidato da UBA che aiuta a mantenere sicuri e conformi il tuo AD, Azure AD, i sistemi di file (inclusi Windows, NetApp, EMC, Synology, Hitachi e Huawei), i server Windows e le workstation. ADAudit Plus trasforma i dati grezzi e rumorosi dei log degli eventi in report e avvisi in tempo reale, permettendoti di ottenere una visibilità completa sulle attività che avvengono nel tuo ecosistema Windows Server in pochi clic. Più di 10.000 organizzazioni in tutto il mondo si affidano ad ADAudit Plus per: 1. Notificarli istantaneamente sui cambiamenti nei loro ambienti Windows Server. 2. Tracciare continuamente l'attività di accesso degli utenti Windows. 3. Monitorare il tempo attivo e inattivo trascorso dai dipendenti alle loro workstation. 4. Rilevare e risolvere i blocchi degli account AD. 5. Fornire una traccia di audit consolidata delle attività degli utenti privilegiati nei loro domini. 6. Tracciare i cambiamenti e gli accessi in Azure AD. 7. Auditare gli accessi ai file su sistemi di file Windows, NetApp, EMC, Synology, Hitachi e Huawei. 8. Monitorare l'integrità dei file sui file locali presenti sui sistemi Windows. 9. Mitigare le minacce interne sfruttando UBA e l'automazione delle risposte. 10. Generare report di conformità pronti per l'audit per SOX, il GDPR e altri mandati IT.

**Average Rating:** 4.6/5.0

**Total Reviews:** 59

#### How Do G2 Users Rate ManageEngine ADAudit Plus?

- **Monitoraggio delle attività:** 9.4/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.5/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.8/10 (Category avg: 8.7/10)
- **Gestione dei log:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind ManageEngine ADAudit Plus?

- **Venditore:** [Zoho](https://www.g2.com/it/sellers/zoho-b00ca9d5-bca8-41b5-a8ad-275480841704)
- **Anno di Fondazione:** 1996
- **Sede centrale:** Austin, TX
- **Twitter:** @Zoho  
137,880 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9c8e45ddb296c32c6c5597ef9ba945c94562c57624f7bd1dcf1a9e9931f71578&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F38373%2F&secure%5Burl_type%5D=linkedin_company_website)  
30,766 dipendenti su LinkedIn®
- **Telefono:** +1 (888) 900-9646 

#### Who Uses This Product?

- **Top Industries:** Ospedali e assistenza sanitaria, Tecnologia dell'informazione e servizi
- **Company Size:** 59% Medium, 32% Large

#### What Do G2 Reviewers Say About ManageEngine ADAudit Plus?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano la **profondità dei report** in ADAudit Plus, migliorando la visibilità negli ambienti AD con opzioni predefinite.
- Gli utenti apprezzano l' **usabilità intuitiva del cruscotto** di ADAudit Plus, che offre una facile navigazione e opzioni di reportistica complete.
- Gli utenti apprezzano la **facile configurazione e le ampie opzioni di reportistica** in ManageEngine ADAudit Plus per un monitoraggio efficace.
- Gli utenti apprezzano il **design del dashboard** di ADAudit Plus per la sua panoramica completa e le opzioni di reportistica dettagliate.
- Gli utenti apprezzano il **cruscotto intuitivo e le ampie opzioni di reportistica** in ADAudit Plus per una gestione efficace di Active Directory.

##### Cons

- Gli utenti trovano i **livelli di allerta limitati** insufficienti per regolare finemente le notifiche, nonostante le opzioni di reportistica utili e le funzionalità di ricerca.
- Gli utenti trovano il **sovraccarico di dati** derivante dalle numerose opzioni di reportistica opprimente, rendendo difficile individuare report specifici.
- Gli utenti trovano il prodotto **costoso** , il che influisce sulla loro soddisfazione complessiva nonostante le sue caratteristiche e capacità.
- Gli utenti sperimentano **falsi positivi** con gli avvisi, che potrebbero essere migliorati con una maggiore granularità nei livelli di gravità.
- Gli utenti sono frustrati dall' **elevato utilizzo delle risorse** di ManageEngine ADAudit Plus, che influisce significativamente sulle prestazioni del sistema.

#### What Are Recent G2 Reviews of ManageEngine ADAudit Plus?

**["Configurazione Facile, Reportistica Potente e Grande Valore"](https://www.g2.com/it/survey_responses/manageengine-adaudit-plus-review-12999020)**

**Rating:** 4.5/5.0 stars

_— Ryan A._

[Read full review](https://www.g2.com/it/survey_responses/manageengine-adaudit-plus-review-12999020)

**["Ottimo strumento per l'auditing e le indagini di Active Directory"](https://www.g2.com/it/survey_responses/manageengine-adaudit-plus-review-13001820)**

**Rating:** 5.0/5.0 stars

_— Jose R._

[Read full review](https://www.g2.com/it/survey_responses/manageengine-adaudit-plus-review-13001820)

#### What Are G2 Users Discussing About ManageEngine ADAudit Plus?

- [What does AD audit do?](https://www.g2.com/it/discussions/what-does-ad-audit-do)
- [Is Ad audit plus a SIEM?](https://www.g2.com/it/discussions/is-ad-audit-plus-a-siem)
- [What is ManageEngine Audit Plus?](https://www.g2.com/it/discussions/what-is-manageengine-audit-plus)
- [What does ADAudit plus do?](https://www.g2.com/it/discussions/what-does-adaudit-plus-do)

### [Sumo Logic](https://www.g2.com/it/products/sumo-logic/reviews)

Sumo Logic, Inc. unifica e analizza i dati aziendali, traducendoli in intuizioni attuabili attraverso una piattaforma di analisi dei log nativa del cloud potenziata dall'IA. Questa singola fonte di verità consente ai team Dev, Sec e Ops di semplificare la complessità, collaborare in modo efficiente e accelerare le decisioni basate sui dati che guidano il valore aziendale. Clienti in tutto il mondo si affidano alla Piattaforma SaaS di Analisi dei Log di Sumo Logic per ottenere intuizioni affidabili per garantire l'affidabilità delle applicazioni, proteggere e difendersi dalle moderne minacce alla sicurezza e ottenere informazioni sulle loro infrastrutture cloud. Per ulteriori informazioni, visita: SUMOLOGIC.COM

**Average Rating:** 4.3/5.0

**Total Reviews:** 392

#### How Do G2 Users Rate Sumo Logic?

- **Monitoraggio delle attività:** 9.1/10 (Category avg: 9.1/10)
- **Esame dei dati:** 9.0/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.2/10 (Category avg: 8.7/10)
- **Gestione dei log:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Sumo Logic?

- **Venditore:** [Sumo Logic](https://www.g2.com/it/sellers/sumo-logic)
- **Sito web dell'azienda:** www.sumologic.com
- **Anno di Fondazione:** 2010
- **Sede centrale:** Redwood City, CA
- **Twitter:** @SumoLogic  
6,542 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=405f2514b57035d31a9696f673d9692138c137173787398caeba6974c512d779&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1037816%2F&secure%5Burl_type%5D=linkedin_company_website)  
838 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Tecnologia dell'informazione e servizi, Software per computer
- **Company Size:** 48% Medium, 37% Large

#### What Do G2 Reviewers Say About Sumo Logic?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano la **facilità d'uso** di Sumo Logic, trovandolo semplice da imparare e configurare efficacemente.
- Gli utenti apprezzano la **facilità di ricerca e configurazione dei log** , migliorando le loro capacità di monitoraggio e tracciamento senza sforzo.
- Gli utenti apprezzano la **funzionalità di Intelligenza Continua** di Sumo Logic per i suoi rapidi e utili approfondimenti da dati diversi.
- Gli utenti elogiano **la potenza visiva e la flessibilità di Sumo Logic** , migliorando la visualizzazione degli KPI e riducendo il carico di lavoro legato ai log.
- Gli utenti apprezzano le **intuizioni in tempo reale** offerte da Sumo Logic, migliorando il monitoraggio e l'analisi per prendere decisioni migliori.

##### Cons

- Gli utenti trovano Sumo Logic **costoso** , spesso si chiedono se il suo valore giustifichi il prezzo elevato.
- Gli utenti trovano che la **difficile curva di apprendimento** di Sumo Logic ostacoli una rapida padronanza nell'uso efficace delle sue funzionalità.
- Gli utenti trovano **ripida curva di apprendimento** di Sumo Logic impegnativa, specialmente quando si tratta di padroneggiare query complesse e processi di configurazione.
- Gli utenti trovano la **ripida curva di apprendimento** di Sumo Logic impegnativa, richiedendo un tempo significativo per acquisire competenza.
- Gli utenti sperimentano **prestazioni lente** a causa di un'interfaccia utente ingombrante e di avvisi ritardati, influenzando l'efficienza e i tempi di risposta.

#### What Are Recent G2 Reviews of Sumo Logic?

**["Registrazione AI sicura e incentrata sulla privacy che aiuta a ridurre il rischio di violazione dei dati"](https://www.g2.com/it/survey_responses/sumo-logic-review-13156334)**

**Rating:** 5.0/5.0 stars

_— Aiyappa Baleyada B._

[Read full review](https://www.g2.com/it/survey_responses/sumo-logic-review-13156334)

**["Registrazione centralizzata con dashboard intuitive"](https://www.g2.com/it/survey_responses/sumo-logic-review-12948839)**

**Rating:** 4.5/5.0 stars

_— Sudarshan B._

[Read full review](https://www.g2.com/it/survey_responses/sumo-logic-review-12948839)

#### What Are G2 Users Discussing About Sumo Logic?

- [A cosa serve Cloud SOAR?](https://www.g2.com/it/discussions/what-is-cloud-soar-used-for) - 1 comment, 1 upvote
- [Is Sumo Logic a SIEM?](https://www.g2.com/it/discussions/is-sumo-logic-a-siem)
- [What is Sumo Logic used for?](https://www.g2.com/it/discussions/what-is-sumo-logic-used-for)
- [Chi sono i concorrenti di Sumo Logic?](https://www.g2.com/it/discussions/who-are-sumo-logic-competitors) - 1 comment
- [How much does Sumo Logic cost?](https://www.g2.com/it/discussions/how-much-does-sumo-logic-cost)

### [Todyl Security Platform](https://www.g2.com/it/products/todyl-security-platform/reviews)

Todyl è una piattaforma di sicurezza informatica e garanzia basata sull'intelligenza artificiale per la gestione delle minacce, dei rischi e della conformità, fornita attraverso un unico agente e un unico portale. La nostra piattaforma difende dalle minacce moderne e avanzate che spaziano dall'identità, endpoint, rete, cloud, SaaS e altro ancora. Inoltre, semplifichiamo il rispetto e la dimostrazione di ampi requisiti di conformità e assicurazione con la raccolta e il reporting centralizzati dei dati, strumenti di valutazione facili da usare, un registro dei rischi integrato e dashboard per ridurre la reportistica manuale e la dispersione dei fogli di calcolo. La nostra piattaforma offre un approccio stratificato alla sicurezza informatica, che copre SASE, Micro-Segmentazione (LZT), Sicurezza degli Endpoint, SIEM, MXDR e GRC, tutto fornito attraverso lo stesso agente, in una piattaforma nativa del cloud. È facile da implementare come soluzione unica, integrata e conveniente che può consolidare e semplificare i tuoi programmi di sicurezza e conformità. Puoi anche distribuire moduli individuali per soddisfare le tue esigenze attuali, con un semplice interruttore nell'interfaccia utente per aggiungere o provare nuovi moduli quando ne hai bisogno. E un Mercato della Garanzia integrato ti aiuta a completare il tuo programma di sicurezza con servizi aggiuntivi come la risposta agli incidenti e i test di penetrazione, e un accesso semplificato ai fornitori di assicurazioni informatiche.

**Average Rating:** 4.7/5.0

**Total Reviews:** 106

#### How Do G2 Users Rate Todyl Security Platform?

- **Monitoraggio delle attività:** 9.4/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.9/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.7/10 (Category avg: 8.7/10)
- **Gestione dei log:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Todyl Security Platform?

- **Venditore:** [Todyl](https://www.g2.com/it/sellers/todyl)
- **Sito web dell'azienda:** www.todyl.com
- **Anno di Fondazione:** 2015
- **Sede centrale:** Denver, CO
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=05d7ce90e9975077322588a582ff9aca56286ea0270706e601aa212b6ec71ed8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftodylprotection&secure%5Burl_type%5D=linkedin_company_website)  
122 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** President, Owner
- **Top Industries:** Tecnologia dell'informazione e servizi, Sicurezza informatica e di rete
- **Company Size:** 75% Small, 8% Medium

#### What Do G2 Reviewers Say About Todyl Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano la **facilità d'uso** della piattaforma di sicurezza Todyl, trovandola intuitiva e facilmente gestibile.
- Gli utenti elogiano il **supporto clienti reattivo e accessibile** di Todyl, garantendo soluzioni rapide e un'integrazione senza problemi.
- Gli utenti apprezzano le **funzionalità complete e facili da usare** della Piattaforma di Sicurezza Todyl, migliorando la sicurezza con facilità e integrazione.
- Gli utenti apprezzano le **funzionalità di sicurezza complete** di Todyl, migliorando la protezione per i dispositivi lontano dall'ufficio.
- Gli utenti evidenziano la **facilità di distribuzione** della Todyl Security Platform, apprezzandone la configurazione intuitiva e l'integrazione senza problemi.

##### Cons

- Gli utenti ritengono che **siano necessari miglioramenti** nella personalizzazione, integrazione e facilitazione della curva di apprendimento per la piattaforma di Todyl.
- Gli utenti notano **problemi di integrazione** con Todyl, citando un'API limitata e la necessità di migliorare l'interoperabilità con terze parti.
- Gli utenti trovano **inadeguata la reportistica** e cercano miglioramenti per migliori capacità di revisione strategica.
- Gli utenti notano **funzionalità limitate** in Todyl, desiderando in particolare capacità di personalizzazione e reportistica migliorate.
- Gli utenti trovano **difficile navigare nei report** , ostacolando la loro capacità di estrarre informazioni preziose in modo efficace.

#### What Are Recent G2 Reviews of Todyl Security Platform?

**["Todyl ha semplificato il nostro stack con sicurezza a livello aziendale a un ottimo prezzo"](https://www.g2.com/it/survey_responses/todyl-security-platform-review-12841444)**

**Rating:** 5.0/5.0 stars

_— Nahjee M._

[Read full review](https://www.g2.com/it/survey_responses/todyl-security-platform-review-12841444)

**["Visibilità preziosa con margini di miglioramento"](https://www.g2.com/it/survey_responses/todyl-security-platform-review-9155307)**

**Rating:** 4.0/5.0 stars

_— Ethan D._

[Read full review](https://www.g2.com/it/survey_responses/todyl-security-platform-review-9155307)

### [Check Point Infinity Platform](https://www.g2.com/it/products/check-point-infinity-platform/reviews)

Check Point Infinity è l'unica architettura di sicurezza informatica completamente consolidata che offre una protezione senza precedenti contro gli attacchi informatici di quinta generazione (Gen V) e le future minacce informatiche su tutte le reti, endpoint, cloud e dispositivi mobili. L'architettura è progettata per risolvere le complessità della crescente connettività e della sicurezza inefficiente.

**Average Rating:** 4.6/5.0

**Total Reviews:** 109

#### How Do G2 Users Rate Check Point Infinity Platform?

- **Facilità d'uso:** 9.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Check Point Infinity Platform?

- **Venditore:** [Check Point Software Technologies](https://www.g2.com/it/sellers/check-point-software-technologies)
- **Anno di Fondazione:** 1993
- **Sede centrale:** Redwood City, CA
- **Twitter:** @CheckPointSW  
70,955 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d885813f6605ba84238ae4a21d169e0c9ade054cf0c99ff53e72483b54a8b521&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheck-point-software-technologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
8,554 dipendenti su LinkedIn®
- **Proprietà:** NASDAQ:CHKP

#### Who Uses This Product?

- **Top Industries:** Sicurezza informatica e di rete, Tecnologia dell'informazione e servizi
- **Company Size:** 44% Large, 37% Medium

#### What Do G2 Reviewers Say About Check Point Infinity Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano le **funzionalità di sicurezza avanzate** della piattaforma Check Point Infinity, garantendo una protezione robusta contro futuri attacchi.
- Gli utenti apprezzano le **funzionalità di sicurezza cloud** della piattaforma Check Point Infinity, garantendo audit di sicurezza efficienti e valutazione dell'infrastruttura.
- Gli utenti apprezzano le caratteristiche di **rilevamento proattivo delle minacce** della piattaforma Check Point Infinity, migliorando la sicurezza per le applicazioni cloud.
- Gli utenti apprezzano le **funzionalità di sicurezza complete** della piattaforma Check Point Infinity, garantendo una protezione robusta contro le minacce cloud.
- Gli utenti apprezzano le **funzionalità avanzate di sicurezza cloud** della piattaforma Check Point Infinity, garantendo una protezione robusta contro futuri attacchi.

##### Cons

- Gli utenti trovano la **ripida curva di apprendimento** impegnativa a causa della configurazione complessa e della mancanza di documentazione completa.
- Gli utenti trovano che la **complessità** delle impostazioni e della documentazione della piattaforma Check Point Infinity possa ostacolare l'usabilità e l'efficienza.
- Gli utenti ritengono che **siano necessari miglioramenti** nel supporto e nella visibilità dei server nativi nei log di Check Point.
- Gli utenti trovano **i servizi di supporto scadenti** dannosi, evidenziando la necessità di migliorare l'assistenza clienti e la visibilità dei log.
- Gli utenti affrontano **opzioni di personalizzazione limitate** per i set di regole e le metriche, rendendo le valutazioni dettagliate difficili.

#### What Are Recent G2 Reviews of Check Point Infinity Platform?

**["Eccellente opzione Harmony Platform per la sicurezza centrale"](https://www.g2.com/it/survey_responses/check-point-infinity-platform-review-11868343)**

**Rating:** 4.5/5.0 stars

_— Tania V._

[Read full review](https://www.g2.com/it/survey_responses/check-point-infinity-platform-review-11868343)

**["Seamless Hybrid Security Integration Across All Environments"](https://www.g2.com/it/survey_responses/check-point-infinity-platform-review-11954684)**

**Rating:** 4.5/5.0 stars

_— Sonu S._

[Read full review](https://www.g2.com/it/survey_responses/check-point-infinity-platform-review-11954684)

#### What Are G2 Users Discussing About Check Point Infinity Platform?

- [How does Check Point Infinity help customers?](https://www.g2.com/it/discussions/how-does-check-point-infinity-help-customers)
- [What are the benefits of Check Point unified security architecture?](https://www.g2.com/it/discussions/what-are-the-benefits-of-check-point-unified-security-architecture)
- [What are the 4 components of the Infinity architecture?](https://www.g2.com/it/discussions/what-are-the-4-components-of-the-infinity-architecture)
- [What is Infinity Total protection?](https://www.g2.com/it/discussions/what-is-infinity-total-protection)

### [Microsoft Sentinel](https://www.g2.com/it/products/microsoft-sentinel/reviews)

Microsoft Sentinel ti consente di vedere e fermare le minacce prima che causino danni, con SIEM reinventato per un mondo moderno. Microsoft Sentinel è la tua vista dall'alto sull'intera azienda. Metti al lavoro il cloud e l'intelligenza su larga scala derivata da decenni di esperienza nella sicurezza di Microsoft. Rendi più intelligente e veloce il rilevamento e la risposta alle minacce con l'intelligenza artificiale (AI). Elimina la configurazione e la manutenzione dell'infrastruttura di sicurezza e scala elasticamente per soddisfare le tue esigenze di sicurezza, riducendo al contempo i costi IT. Con Microsoft Sentinel, puoi: - Raccogliere dati su scala cloud—attraverso tutti gli utenti, dispositivi, applicazioni e infrastrutture, sia on-premises che in più cloud - Rilevare minacce precedentemente non scoperte e ridurre al minimo i falsi positivi utilizzando l'analisi e un'intelligence sulle minacce senza pari di Microsoft - Indagare sulle minacce con l'AI e cercare attività sospette su larga scala, attingendo a decenni di lavoro sulla cybersecurity di Microsoft - Rispondere rapidamente agli incidenti con l'orchestrazione e l'automazione integrate delle attività comuni

**Average Rating:** 4.4/5.0

**Total Reviews:** 274

#### How Do G2 Users Rate Microsoft Sentinel?

- **Monitoraggio delle attività:** 8.9/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.5/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.5/10 (Category avg: 8.7/10)
- **Gestione dei log:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Microsoft Sentinel?

- **Venditore:** [Microsoft](https://www.g2.com/it/sellers/microsoft)
- **Anno di Fondazione:** 1975
- **Sede centrale:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 dipendenti su LinkedIn®
- **Proprietà:** MSFT

#### Who Uses This Product?

- **Who Uses This:** Senior Software Engineer, Security Analyst
- **Top Industries:** Tecnologia dell'informazione e servizi, Sicurezza informatica e di rete
- **Company Size:** 42% Large, 31% Medium

#### What Do G2 Reviewers Say About Microsoft Sentinel?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano il **monitoraggio in tempo reale** di Microsoft Sentinel, migliorando la loro capacità di rispondere rapidamente alle minacce alla sicurezza.
- Gli utenti apprezzano la **risposta automatizzata agli avvisi** di Microsoft Sentinel, che offre tranquillità con il monitoraggio centralizzato della sicurezza.
- Gli utenti apprezzano la **usabilità senza soluzione di continuità del cruscotto** di Microsoft Sentinel, facilitando la gestione intuitiva della sicurezza e il monitoraggio completo.
- Gli utenti apprezzano la **risposta rapida e sicura alle minacce** di Microsoft Sentinel, migliorando la sicurezza complessiva e la gestione del rischio.
- Gli utenti beneficiano della **gestione dati senza interruzioni** di Microsoft Sentinel, migliorando il flusso di lavoro e garantendo analisi di sicurezza complete.

##### Cons

- Gli utenti esprimono preoccupazioni riguardo alla **dipendenza dal cloud** , in particolare per quanto riguarda i problemi di connettività con internet a bassa velocità e la dipendenza commerciale.
- Gli utenti trovano la **configurazione complessa** di Microsoft Sentinel impegnativa, richiedendo competenze tecniche avanzate per un'installazione e un uso efficaci.
- Gli utenti affrontano **problemi di configurazione** con Microsoft Sentinel, richiedendo competenze tecniche e tempo per un'installazione efficace.
- Gli utenti trovano la **difficile configurazione** di Microsoft Sentinel impegnativa senza esperti di sicurezza dedicati e una formazione adeguata.
- Gli utenti hanno difficoltà con il **design dell'interfaccia scadente** di Microsoft Sentinel, rendendo la navigazione e la comprensione delle funzionalità difficili.

#### What Are Recent G2 Reviews of Microsoft Sentinel?

**["Facile Ingestione di Log tra Formati con Integrazioni Sentinel Senza Soluzione di Continuità"](https://www.g2.com/it/survey_responses/microsoft-sentinel-review-13073395)**

**Rating:** 4.5/5.0 stars

_— Sandip K._

[Read full review](https://www.g2.com/it/survey_responses/microsoft-sentinel-review-13073395)

**["Miglior SIEM nativo del cloud - Microsoft Sentinel"](https://www.g2.com/it/survey_responses/microsoft-sentinel-review-13250215)**

**Rating:** 4.5/5.0 stars

_— vimal p._

[Read full review](https://www.g2.com/it/survey_responses/microsoft-sentinel-review-13250215)

#### What Are G2 Users Discussing About Microsoft Sentinel?

- [A cosa serve Microsoft Sentinel?](https://www.g2.com/it/discussions/what-is-microsoft-sentinel-used-for) - 3 comments, 2 upvotes
- [Perché dovrei usare Azure Sentinel?](https://www.g2.com/it/discussions/why-should-i-use-azure-sentinel) - 1 comment
- [Which feature provides the extended detection and response capabilities of Azure Sentinel?](https://www.g2.com/it/discussions/which-feature-provides-the-extended-detection-and-response-capabilities-of-azure-sentinel)
- [What is the difference between Azure security Center and Azure Sentinel?](https://www.g2.com/it/discussions/what-is-the-difference-between-azure-security-center-and-azure-sentinel)
- [What does Azure Sentinel provide?](https://www.g2.com/it/discussions/what-does-azure-sentinel-provide)

### [Huntress Managed SIEM](https://www.g2.com/it/products/huntress-managed-siem/reviews)

Huntress è una soluzione di cybersecurity completa progettata specificamente per le Fortune 5.000 e i fornitori di servizi gestiti (MSP) che li supportano. Questa piattaforma combina tecnologia avanzata con un Centro Operativo di Sicurezza (SOC) attivo 24/7 completamente staffato per offrire una difesa robusta contro un panorama di minacce informatiche in continua evoluzione. Integrando strumenti all'avanguardia, servizi e conoscenze esperte, Huntress consente alle aziende di affrontare efficacemente le loro sfide di cybersecurity e proteggere i loro asset aziendali critici. Il pubblico target di Huntress include team IT interni che potrebbero non avere le risorse o l'esperienza per gestire la cybersecurity in modo indipendente, così come gli MSP che cercano soluzioni affidabili per migliorare le loro offerte di servizi. Queste aziende spesso affrontano sfide uniche, come vincoli di budget e personale IT limitato, rendendo essenziale per loro adottare una strategia di cybersecurity che sia sia efficace che conveniente. Huntress risponde a queste esigenze fornendo una suite di soluzioni appositamente progettate per questi requisiti specifici, garantendo che possano difendersi dalle minacce informatiche senza compromettere la loro efficienza operativa. Le caratteristiche principali di Huntress includono la sua Piattaforma di Sicurezza Gestita, che offre capacità di rilevamento e risposta alle minacce in tempo reale. La piattaforma monitora continuamente l'attività dannosa, consentendo l'identificazione e la risoluzione rapida delle potenziali minacce. Inoltre, il SOC attivo 24/7, staffato da esperti di cybersecurity, garantisce che qualsiasi incidente venga affrontato prontamente, offrendo tranquillità alle aziende che potrebbero non avere team di sicurezza interni. Huntress enfatizza anche l'educazione, offrendo risorse e formazione per aiutare gli utenti a comprendere le migliori pratiche di cybersecurity e rimanere informati sulle ultime minacce. Fornendo una combinazione di tecnologia, servizi e competenze, Huntress si distingue nel panorama della cybersecurity. L'approccio proattivo di Huntress non solo aiuta le aziende a difendersi dalle minacce attuali, ma le prepara anche per le sfide future, rendendola un partner prezioso nella lotta continua contro il crimine informatico.

**Average Rating:** 4.7/5.0

**Total Reviews:** 49

#### Who Is the Company Behind Huntress Managed SIEM?

- **Venditore:** [Huntress Labs](https://www.g2.com/it/sellers/huntress-labs)
- **Sito web dell'azienda:** huntress.com
- **Anno di Fondazione:** 2015
- **Sede centrale:** Ellicott City, US
- **Twitter:** @HuntressLabs  
40,338 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=570d57c2d792bb0f1dd9c97cb05ee13cfd2e93a1546d6d3c5c11e8ce22e14a55&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10172550%2F&secure%5Burl_type%5D=linkedin_company_website)  
978 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Tecnologia dell'informazione e servizi, Sicurezza informatica e di rete
- **Company Size:** 64% Small, 24% Medium

#### What Are Recent G2 Reviews of Huntress Managed SIEM?

**["Centrale di Registrazione e Investigazione Centralizzata"](https://www.g2.com/it/survey_responses/huntress-managed-siem-review-12729137)**

**Rating:** 4.5/5.0 stars

_— Paul A._

[Read full review](https://www.g2.com/it/survey_responses/huntress-managed-siem-review-12729137)

**["Servizio SIEM esemplare con supporto impareggiabile"](https://www.g2.com/it/survey_responses/huntress-managed-siem-review-12676229)**

**Rating:** 5.0/5.0 stars

_— Skylar P._

[Read full review](https://www.g2.com/it/survey_responses/huntress-managed-siem-review-12676229)

### [Panther](https://www.g2.com/products/panther/reviews)

Panther is the AI SOC Platform that scales security expertise by embedding AI agents across your security operations with native access to your data lake, detection logic, and organizational knowledge. Unlike bolt-on tools, Panther's closed-loop architecture turns every alert into compounding intelligence that makes the system smarter over time. Request a demo today at: https://panther.com/product/request-a-demo/

**Average Rating:** 4.7/5.0

**Total Reviews:** 49

#### How Do G2 Users Rate Panther?

- **Activity Monitoring:** 9.3/10 (Category avg: 9.1/10)
- **Data Examination:** 9.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.9/10 (Category avg: 8.7/10)
- **Log Management:** 9.7/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Panther?

- **Seller:** [Panther Labs](https://www.g2.com/sellers/panther-labs)
- **Year Founded:** 2018
- **HQ Location:** San Francisco, CA
- **Twitter:** @runpanther  
4,437 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5e833e3ee9905da8ffc2168b1d7db4af5d6a4643d77358f095ebefb033c5103a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Frunpanther%2F&secure%5Burl_type%5D=linkedin_company_website)  
269 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Senior Security Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 53% Medium, 29% Large

#### What Do G2 Reviewers Say About Panther?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Panther's **outstanding customer support** , highlighting its responsiveness and commitment to resolving issues efficiently.
- Users commend Panther for its **exceptional detection efficiency** , enabling effective and purposeful responses in security operations.
- Users find Panther's **intuitive interface** and comprehensive documentation make it easy to navigate and use effectively.
- Users praise the **easy integrations** with various log sources, simplifying security management and boosting team efficiency.
- Users praise Panther for its **purposeful features and continuous improvements** , enhancing usability and aligning with market needs.

##### Cons

- Users find Panther has **missing features** like version control and underdeveloped response workflows, complicating overall use.
- Users find Panther's **complexity challenging** , particularly for non-technical teams and in managing version controls.
- Users find the **Alert Management limited** due to lack of customization and configuration challenges affecting efficiency.
- Users find the **complex configuration** of Panther burdensome, complicating integration with deployment pipelines and automation systems.
- Users find the **dashboard issues** in Panther limit comprehensive security leadership insights and advanced customization options.

#### What Are Recent G2 Reviews of Panther?

**["Panther’s SIEM + AI Makes Triage and Threat Hunting Fast and Seamless"](https://www.g2.com/survey_responses/panther-review-12919421)**

**Rating:** 5.0/5.0 stars

_— Richard E._

[Read full review](https://www.g2.com/survey_responses/panther-review-12919421)

**["Panther Makes Security Operations Simpler and Faster"](https://www.g2.com/survey_responses/panther-review-12890548)**

**Rating:** 5.0/5.0 stars

_— Busra K._

[Read full review](https://www.g2.com/survey_responses/panther-review-12890548)

#### What Are G2 Users Discussing About Panther?

- [What is Panther used for?](https://www.g2.com/discussions/what-is-panther-used-for) - 1 comment

### [Splunk Enterprise](https://www.g2.com/it/products/splunk-enterprise/reviews)

Scopri cosa sta succedendo nella tua azienda e prendi rapidamente azioni significative con Splunk Enterprise. Automatizza la raccolta, l'indicizzazione e l'allerta dei dati macchina che sono critici per le tue operazioni. Scopri le intuizioni attuabili da tutti i tuoi dati, indipendentemente dalla fonte o dal formato. Sfrutta l'intelligenza artificiale e l'apprendimento automatico per decisioni aziendali predittive e proattive.

**Average Rating:** 4.3/5.0

**Total Reviews:** 415

#### How Do G2 Users Rate Splunk Enterprise?

- **Monitoraggio delle attività:** 9.1/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.4/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.1/10 (Category avg: 8.7/10)
- **Gestione dei log:** 9.3/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Splunk Enterprise?

- **Venditore:** [Cisco](https://www.g2.com/it/sellers/cisco)
- **Anno di Fondazione:** 1984
- **Sede centrale:** San Jose, CA
- **Twitter:** @Cisco  
720,366 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 dipendenti su LinkedIn®
- **Proprietà:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Tecnologia dell'informazione e servizi, Software per computer
- **Company Size:** 64% Large, 27% Medium

#### What Do G2 Reviewers Say About Splunk Enterprise?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano l' **innovazione** di Splunk Enterprise, apprezzando le sue funzionalità intuitive e le potenti capacità analitiche.
- Gli utenti apprezzano le **funzionalità di personalizzazione** di Splunk Enterprise, che consentono approfondimenti su misura e dashboard dinamici per un monitoraggio efficace.
- Gli utenti elogiano la **facilità d'uso** di Splunk Enterprise, migliorando il monitoraggio efficace e la rapida risoluzione dei problemi.
- Gli utenti apprezzano le **capacità di gestione dei log efficienti** di Splunk Enterprise per un'analisi accurata e approfondimenti.
- Gli utenti apprezzano le **potenti funzionalità di reporting** di Splunk Enterprise, migliorando significativamente le capacità di analisi e visualizzazione dei dati.

##### Cons

- Gli utenti trovano Splunk Enterprise **costoso** , specialmente con l'aumento dei volumi di dati, influenzando le operazioni dei team più piccoli.
- Gli utenti affrontano una **ripida curva di apprendimento** con Splunk Enterprise, che può ostacolare una rapida padronanza delle sue funzionalità.
- Gli utenti evidenziano la **costosa licenza** di Splunk Enterprise, rendendo difficile l'adozione per alcune aziende.
- Gli utenti affrontano **problemi di integrazione** con Splunk Enterprise, richiedendo migliori componenti aggiuntivi e un'architettura più semplice per una distribuzione più facile.
- Gli utenti ritengono che Splunk Enterprise abbia **funzionalità mancanti** , manchi di componenti aggiuntivi importanti e opzioni di onboarding dei dati più flessibili.

#### What Are Recent G2 Reviews of Splunk Enterprise?

**["La ricerca SPL e le dashboard sono davvero utili"](https://www.g2.com/it/survey_responses/splunk-enterprise-review-12547655)**

**Rating:** 4.0/5.0 stars

_— Nishith J._

[Read full review](https://www.g2.com/it/survey_responses/splunk-enterprise-review-12547655)

**["Eccellente soluzione di osservabilità aziendale e gestione dei log per infrastrutture cloud ibride"](https://www.g2.com/it/survey_responses/splunk-enterprise-review-12045230)**

**Rating:** 4.5/5.0 stars

_— RaviShankar S._

[Read full review](https://www.g2.com/it/survey_responses/splunk-enterprise-review-12045230)

#### What Are G2 Users Discussing About Splunk Enterprise?

- [A cosa serve Splunk Enterprise?](https://www.g2.com/it/discussions/what-is-splunk-enterprise-used-for) - 1 comment
- [Qual è la differenza tra Splunk Enterprise e Splunk Enterprise Security?](https://www.g2.com/it/discussions/splunk-enterprise-what-is-the-difference-between-splunk-enterprise-and-splunk-enterprise-security) - 1 comment
- [Quali sono i componenti di Splunk Enterprise?](https://www.g2.com/it/discussions/what-are-splunk-enterprise-components) - 1 comment
- [Quali app sono incluse con Splunk Enterprise?](https://www.g2.com/it/discussions/which-apps-ship-with-splunk-enterprise) - 1 comment
- [Cosa fa Splunk Enterprise?](https://www.g2.com/it/discussions/what-does-splunk-enterprise-do) - 1 comment

### [Cynet](https://www.g2.com/products/cynet/reviews)

Cynet is the unified, AI-powered cybersecurity platform that delivers robust and comprehensive protection for security teams while maximizing operational efficiency for managed service providers (MSPs). This platform consolidates a wide array of security capabilities into a single, user-friendly interface, ensuring that organizations can effectively safeguard their digital assets without the complexity often associated with multi-solution environments. Cynet’s platform simplifies security management by integrating various functionalities, such as endpoint protection, threat detection, and incident response, into one cohesive system. This integration not only streamlines operations but also allows organizations to allocate their resources more effectively, ultimately enhancing their overall security posture. One of the standout features of Cynet’s platform is its remarkable performance in the MITRE ATT&CK Evaluations. Cynet delivered 100% visibility and 100% analytic coverage without requiring any configuration changes three years in a row. This capability ensures that organizations can monitor their environments comprehensively and respond to threats with precision. The platform’s built-in analytics and reporting tools provide actionable insights, enabling users to make informed decisions about their cybersecurity strategies. Additionally, Cynet offers 24/7 expert support, which is crucial for organizations that may not have in-house cybersecurity expertise. This round-the-clock assistance ensures that users can quickly address any security incidents or concerns, minimizing potential downtime and damage. The combination of advanced technology and dedicated support positions Cynet as a valuable partner for SMEs and service providers looking to enhance their cybersecurity measures. In summary, Cynet’s unified, AI-powered cybersecurity platform stands out in the crowded cybersecurity market by offering a unified solution tailored to the needs of MSPs. Its comprehensive features, exceptional performance in industry evaluations, and continuous expert support make it a compelling choice for organizations seeking to bolster their cybersecurity defenses while maintaining operational efficiency.

**Average Rating:** 4.7/5.0

**Total Reviews:** 216

#### How Do G2 Users Rate Cynet?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.8/10 (Category avg: 8.6/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **Log Management:** 8.9/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Cynet?

- **Seller:** [Cynet](https://www.g2.com/sellers/cynet)
- **Year Founded:** 2014
- **HQ Location:** Boston, MA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5a5ebaacd6a1a812a193b2886c91aa7e64aeee7fb30bb25e658549d729d68178&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcynet-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
332 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** SOC Analyst, Technical Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 58% Medium, 31% Small

#### What Do G2 Reviewers Say About Cynet?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Cynet, enjoying its simplicity and comprehensive features in one dashboard.
- Users value the **unified platform** of Cynet for its ease of use and comprehensive security features.
- Users value Cynet for its **effective threat detection** and seamless integration, ensuring robust cybersecurity for their business.
- Users appreciate the **exceptional customer support** of Cynet, facilitating smooth deployment and effective threat management.
- Users commend Cynet for its **flawless threat monitoring and response** , enhancing overall security with effective detection capabilities.

##### Cons

- Users express concern over **limited customization** options in reports and third-party integrations, impacting their experience.
- Users note the **feature limitations** of Cynet, especially in report customization and external tool integrations.
- Users express concern over the **lack of customization** , particularly in reporting and dashboard options for better usability.
- Users find Cynet has **limited features** like integrations and customization, which may restrict advanced functionality.
- Users note the **missing features** in Cynet, particularly the lack of web filtering and a firewall option.

#### What Are Recent G2 Reviews of Cynet?

**["Outstanding Product"](https://www.g2.com/survey_responses/cynet-review-9063334)**

**Rating:** 5.0/5.0 stars

_— David W._

[Read full review](https://www.g2.com/survey_responses/cynet-review-9063334)

**["One platform to manage centralized Endpoint Security"](https://www.g2.com/survey_responses/cynet-review-10264337)**

**Rating:** 4.5/5.0 stars

_— Guido I._

[Read full review](https://www.g2.com/survey_responses/cynet-review-10264337)

#### What Are G2 Users Discussing About Cynet?

- [What is Cynet 360 AutoXDR™ used for?](https://www.g2.com/discussions/what-is-cynet-360-autoxdr-used-for)
- [What is cynet XDR?](https://www.g2.com/discussions/what-is-cynet-xdr) - 1 comment
- [What is cynet used for?](https://www.g2.com/discussions/what-is-cynet-used-for) - 1 comment
- [Is cynet 360 good?](https://www.g2.com/discussions/is-cynet-360-good) - 3 comments
- [How much does cynet cost?](https://www.g2.com/discussions/how-much-does-cynet-cost) - 1 comment

### [IBM QRadar SIEM](https://www.g2.com/it/products/ibm-ibm-qradar-siem/reviews)

Supera le minacce con una suite di sicurezza pluripremiata end-to-end; provata per prevenire, resistere e recuperare da pericoli IT sia noti che sconosciuti affrontati dai SoC al giorno d'oggi.

**Average Rating:** 4.4/5.0

**Total Reviews:** 283

#### How Do G2 Users Rate IBM QRadar SIEM?

- **Monitoraggio delle attività:** 8.7/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.3/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.4/10 (Category avg: 8.7/10)
- **Gestione dei log:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind IBM QRadar SIEM?

- **Venditore:** [IBM](https://www.g2.com/it/sellers/ibm)
- **Anno di Fondazione:** 1911
- **Sede centrale:** Armonk, New York, United States
- **Twitter:** @IBMSecurity  
74,660 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=14b544adaece4fdbc987f1d7f7028048c22259946811200cc751263825586af9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1009%2F&secure%5Burl_type%5D=linkedin_company_website)  
328,202 dipendenti su LinkedIn®
- **Proprietà:** SWX:IBM

#### Who Uses This Product?

- **Who Uses This:** Security Engineer, SOC Analyst
- **Top Industries:** Sicurezza informatica e di rete, Tecnologia dell'informazione e servizi
- **Company Size:** 52% Large, 29% Medium

#### What Do G2 Reviewers Say About IBM QRadar SIEM?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti trovano IBM QRadar SIEM altamente **user-friendly** , apprezzando la sua facilità di implementazione e integrazione con altre piattaforme.
- Gli utenti apprezzano le **capacità di integrazione senza soluzione di continuità** di IBM QRadar SIEM, migliorando la funzionalità complessiva di gestione dei log e analisi.
- Gli utenti apprezzano le **funzionalità di rilevamento avanzato delle minacce e gestione centralizzata dei log** di IBM QRadar SIEM per una sicurezza migliorata.
- Gli utenti apprezzano le **facili integrazioni** di IBM QRadar SIEM, semplificando la collaborazione con varie piattaforme e strumenti.
- Gli utenti trovano che l' **interfaccia intuitiva** di IBM QRadar SIEM renda facile la navigazione per gli utenti non tecnici.

##### Cons

- Gli utenti trovano **miglioramenti dell'interfaccia utente insufficienti** , con limitazioni nella ricerca e una scarsa costruzione dei report che ostacolano la loro esperienza.
- Gli utenti trovano IBM QRadar SIEM **costoso** , soprattutto per le piccole o medie imprese a causa dei costi elevati.
- Gli utenti notano i **costi elevati** associati a IBM QRadar SIEM, che possono gravare significativamente sulle organizzazioni più piccole.
- Gli utenti sono frustrati dai **problemi del cruscotto** , inclusi diritti di modifica limitati e difficoltà nella gestione delle infrazioni e nella creazione di report.
- Gli utenti trovano le **ricerche di query che richiedono tempo** frustranti e inefficienti per il recupero dei log in QRadar SIEM.

#### What Are Recent G2 Reviews of IBM QRadar SIEM?

**["QRADAR si integra facilmente e rende i log e gli avvisi pronti per i report"](https://www.g2.com/it/survey_responses/ibm-qradar-siem-review-13061810)**

**Rating:** 4.5/5.0 stars

_— Zahid A._

[Read full review](https://www.g2.com/it/survey_responses/ibm-qradar-siem-review-13061810)

**["Forte Correlazione, Monitoraggio della Sicurezza Maturo e Reporting di Conformità"](https://www.g2.com/it/survey_responses/ibm-qradar-siem-review-12986703)**

**Rating:** 5.0/5.0 stars

_— Utente verificato in Tecnologia dell'informazione e servizi_

[Read full review](https://www.g2.com/it/survey_responses/ibm-qradar-siem-review-12986703)

### [Elastic Security](https://www.g2.com/it/products/elastic-elastic-security/reviews)

Modernizza il tuo SOC con l'IA La sicurezza è un problema di dati. Il tuo team deve rilevare, investigare e rispondere rapidamente alle minacce. Elastic Security unifica SIEM e XDR di nuova generazione con automazione nativa, con l'IA integrata in ogni fase. Costruito su Elasticsearch, la piattaforma di ricerca open-source fidata da milioni di utenti, Elastic fornisce visibilità completa nel tuo ambiente. La nostra architettura di data mesh semplifica l'analisi per aumentare la produttività del team e ridurre il tempo di permanenza degli attaccanti. Rafforza le tue difese - Rileva le minacce più velocemente analizzando i dati da tutta la tua superficie di attacco - Ferma gli attacchi con la protezione XDR più valutata del settore - Chiudi il ciclo più velocemente con Elastic Workflows, combinando automazione scriptata con ragionamento AI agentico - Ottieni assistenza AI più accurata, basata sui tuoi dati utilizzando le capacità di rilevanza leader di Elasticsearch Con Elastic Security, il tuo team SOC può utilizzare l'IA generativa per distillare avvisi, automatizzare compiti ripetitivi e ottenere guida su misura, tutto con la tua scelta di LLM e piena trasparenza nel ragionamento e nelle fonti. I leader SOC scelgono Elastic Security quando hanno bisogno di una piattaforma unificata e aperta pronta a funzionare su qualsiasi cloud, on-premise o isolata.

**Average Rating:** 4.5/5.0

**Total Reviews:** 23

#### How Do G2 Users Rate Elastic Security?

- **Monitoraggio delle attività:** 9.7/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.3/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.8/10 (Category avg: 8.7/10)
- **Gestione dei log:** 9.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Elastic Security?

- **Venditore:** [Elastic](https://www.g2.com/it/sellers/elastic)
- **Sito web dell'azienda:** www.elastic.co
- **Anno di Fondazione:** 2012
- **Sede centrale:** San Francisco, CA
- **Twitter:** @elastic  
65,200 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=bc8e533876f16af617380aaa3922cb6a39a1d6233f0b32a0fa987a5fdffd799e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F814025%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,079 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Tecnologia dell'informazione e servizi
- **Company Size:** 61% Medium, 52% Small

#### What Do G2 Reviewers Say About Elastic Security?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano le **integrazioni senza soluzione di continuità** di Elastic Security, migliorando l'efficienza della visualizzazione dei dati e della gestione degli incidenti.
- Gli utenti apprezzano la **facilità d'uso** di Elastic Security, apprezzando la sua configurazione semplice e le integrazioni senza soluzione di continuità.
- Gli utenti ammirano la **flessibilità e i casi d'uso di sicurezza predefiniti** di Elastic Security per un'integrazione e un'adattabilità senza soluzione di continuità.
- Gli utenti apprezzano le **facili integrazioni** di Elastic Security, facilitando flussi di lavoro senza interruzioni e indagini efficienti tra gli strumenti.
- Gli utenti apprezzano il **miglioramento dell'efficienza** nelle indagini, consentendo intuizioni rapide e attuabili grazie alle robuste funzionalità di Elastic Security.

##### Cons

- Gli utenti affrontano sfide con **curve di apprendimento ripide e costi operativi** , influenzando l'efficienza e la gestione delle risorse in Elastic Security.
- Gli utenti trovano la **complessa implementazione** di Elastic Security impegnativa, soprattutto a causa della ripida curva di apprendimento e del sovraccarico di manutenzione.
- Gli utenti trovano la **complessità** del mantenimento dell'infrastruttura di Elastic Security e l'apprendimento di nuovi linguaggi di query impegnativo e gravoso.
- Gli utenti evidenziano la **configurazione complessa** di Elastic Security, citando una curva di apprendimento ripida e un notevole carico amministrativo.
- Gli utenti riscontrano frequentemente **problemi di integrazione** con Elastic Security, complicando la correlazione dei log e la funzionalità complessiva.

#### What Are Recent G2 Reviews of Elastic Security?

**["Piattaforma di Sicurezza Potente e Personalizzabile per Ambienti Complessi"](https://www.g2.com/it/survey_responses/elastic-security-review-12341245)**

**Rating:** 4.5/5.0 stars

_— Jennifer S._

[Read full review](https://www.g2.com/it/survey_responses/elastic-security-review-12341245)

**["Soluzione SIEM senza interruzioni con IA e supporto eccezionale"](https://www.g2.com/it/survey_responses/elastic-security-review-12438374)**

**Rating:** 5.0/5.0 stars

_— Jordan J._

[Read full review](https://www.g2.com/it/survey_responses/elastic-security-review-12438374)

### [Splunk Enterprise Security](https://www.g2.com/it/products/splunk-enterprise-security/reviews)

Splunk Enterprise Security (ES) è una soluzione moderna e incentrata sui dati per la gestione delle informazioni e degli eventi di sicurezza (SIEM) che offre approfondimenti basati sui dati per una visibilità completa della tua postura di sicurezza, in modo da poter proteggere la tua azienda e mitigare i rischi su larga scala. Con una ricerca e reportistica senza pari, analisi avanzate, intelligenza integrata e contenuti di sicurezza preconfezionati, Splunk ES accelera il rilevamento e l'indagine delle minacce, permettendoti di determinare l'entità delle minacce ad alta priorità per il tuo ambiente in modo da poter agire rapidamente. Costruito su una piattaforma dati aperta e scalabile, puoi rimanere agile di fronte a minacce e necessità aziendali in evoluzione. Il nostro ampio ecosistema di integrazioni costruite da Splunk, partner e comunità, così come le opzioni di distribuzione flessibili, assicurano che i tuoi investimenti tecnologici lavorino in tandem con Splunk ES, incontrandoti ovunque tu sia nel tuo percorso cloud, multi-cloud o ibrido.

**Average Rating:** 4.3/5.0

**Total Reviews:** 224

#### How Do G2 Users Rate Splunk Enterprise Security?

- **Monitoraggio delle attività:** 8.8/10 (Category avg: 9.1/10)
- **Esame dei dati:** 8.5/10 (Category avg: 8.6/10)
- **Facilità d'uso:** 8.2/10 (Category avg: 8.7/10)
- **Gestione dei log:** 9.3/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Splunk Enterprise Security?

- **Venditore:** [Cisco](https://www.g2.com/it/sellers/cisco)
- **Anno di Fondazione:** 1984
- **Sede centrale:** San Jose, CA
- **Twitter:** @Cisco  
720,366 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 dipendenti su LinkedIn®
- **Proprietà:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Tecnologia dell'informazione e servizi, Software per computer
- **Company Size:** 59% Large, 30% Medium

#### What Do G2 Reviewers Say About Splunk Enterprise Security?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano la **facilità d'uso** di Splunk Enterprise Security, migliorando la loro esperienza di monitoraggio e gestione dei log.
- Gli utenti apprezzano le **facili integrazioni** di Splunk Enterprise Security, che consentono una connessione senza interruzioni con varie piattaforme e sistemi.
- Gli utenti evidenziano le **impressionanti capacità di rilevamento delle minacce** di Splunk Enterprise Security, migliorando l'attenzione alla sicurezza e riducendo i falsi allarmi.
- Gli utenti apprezzano le **funzionalità efficaci** di Splunk Enterprise Security, migliorando l'analisi della sicurezza con log e approfondimenti completi.
- Gli utenti apprezzano l' **interfaccia intuitiva** di Splunk Enterprise Security, che consente un monitoraggio efficiente e dashboard attraenti.

##### Cons

- Gli utenti notano che l' **alto costo** di Splunk Enterprise Security è un grande svantaggio per le organizzazioni più piccole.
- Gli utenti trovano la **implementazione iniziale complessa** , necessitando di risorse esperte e tempo per integrare efficacemente Splunk Enterprise Security.
- Gli utenti trovano l' **implementazione complessa** di Splunk Enterprise Security impegnativa, richiedendo competenze e risorse estese.
- Gli utenti trovano la **complessità e l'ampia configurazione** di Splunk Enterprise Security dispendiosa in termini di tempo e impegnativa.
- Gli utenti trovano la **difficile curva di apprendimento** di Splunk Enterprise Security una sfida per i principianti e costosa da configurare.

#### What Are Recent G2 Reviews of Splunk Enterprise Security?

**["Rilevamento e indagine delle minacce potenti con Splunk Enterprise Security"](https://www.g2.com/it/survey_responses/splunk-enterprise-security-review-12982814)**

**Rating:** 5.0/5.0 stars

_— Priyanshu S._

[Read full review](https://www.g2.com/it/survey_responses/splunk-enterprise-security-review-12982814)

**["Interfaccia utente semplice e facile da usare che riunisce tutto in un unico posto"](https://www.g2.com/it/survey_responses/splunk-enterprise-security-review-13233919)**

**Rating:** 4.5/5.0 stars

_— Yashwant S._

[Read full review](https://www.g2.com/it/survey_responses/splunk-enterprise-security-review-13233919)

#### What Are G2 Users Discussing About Splunk Enterprise Security?

- [A cosa serve Splunk User Behavior Analytics?](https://www.g2.com/it/discussions/what-is-splunk-user-behavior-analytics-used-for)
- [What does Splunk Enterprise do?](https://www.g2.com/it/discussions/splunk-enterprise-security-what-does-splunk-enterprise-do)
- [Qual è la differenza tra Splunk Enterprise e Splunk Enterprise Security?](https://www.g2.com/it/discussions/what-is-the-difference-between-splunk-enterprise-and-splunk-enterprise-security) - 1 comment
- [Which Splunk app is used for enterprise security?](https://www.g2.com/it/discussions/which-splunk-app-is-used-for-enterprise-security)
- [What is Splunk Enterprise Security?](https://www.g2.com/it/discussions/what-is-splunk-enterprise-security)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/security-information-and-event-management-siem?order=g2_score&page=2#product-list)
- [3](/categories/security-information-and-event-management-siem?order=g2_score&page=3#product-list)
- [4](/categories/security-information-and-event-management-siem?order=g2_score&page=4#product-list)
- [5](/categories/security-information-and-event-management-siem?order=g2_score&page=5#product-list)
- …
- [8](/categories/security-information-and-event-management-siem?order=g2_score&page=8#product-list)
- [9](/categories/security-information-and-event-management-siem?order=g2_score&page=9#product-list)
- [Next &rsaquo;Next ›](/categories/security-information-and-event-management-siem?order=g2_score&page=2#product-list)

Spotlight Categories

[Accounting Software](https://www.g2.com/categories/accounting)

[Payroll Software](https://www.g2.com/categories/payroll)

[Applicant Tracking Systems (ATS)](https://www.g2.com/categories/applicant-tracking-systems-ats)

[Anti Money Laundering Software](https://www.g2.com/categories/anti-money-laundering)

[E-Signature Software](https://www.g2.com/categories/e-signature)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)
- [Deception Technology](/categories/deception-technology)

- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)
- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)

- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)
- [Security Orchestration, Automation, and Response (SOAR)](/categories/security-orchestration-automation-and-response-soar)

[Browse Security Information and Event Management (SIEM) Themes](/categories/security-information-and-event-management-siem/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 31, 2024

Security information and event management (SIEM) software combines a variety of security software components into one platform. Companies use SIEM solutions to centralize security operations into a single location. IT and security operations teams can gain access to the same information and alerts for more effective communication and planning. These products provide capabilities to identify and alert IT operations teams of anomalies detected in their systems. The anomalies may be new malware, unapproved access, or newly discovered vulnerabilities. SIEM tools provide live analysis of functionality and security, storing logs and records for retrospective reporting. They also have products for identity and access management to ensure only approved parties have access to sensitive systems. Forensic analysis tools help teams navigate historical logs, identify trends, and better fortify their networks.

SIEM systems may be confused with [incident response](https://www.g2.com/categories/incident-response) software, but SIEM products provide a larger scope of security and IT management features. Most also do not have the ability to automate security remediation practices.

To qualify for inclusion in the SIEM category, a product must:

- Aggregate and store IT security data
- Assist in user provisioning and governance 
- Identify vulnerabilities in systems and endpoints
- Monitor for anomalies within an IT system

Top Tools at a Glance

| Product | Best for | User Review |
| --- | --- | --- |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_56db399f44b6fabb7c667f09bc770579/crowdstrike-falcon-endpoint-protection-platform.png "Product Avatar Image")](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)[CrowdStrike Falcon Endpoint...](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)[4.6/5(441)](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) | Behavioral threat detection with real-time endpoint response | "Crowdstrike Falcon: Proactive Security, Steep Learning Curve" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_bf8095de95175316574d734b1f2b2c48/sumo-logic.png "Product Avatar Image")](https://www.g2.com/products/sumo-logic/reviews)[Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)[4.3/5(404)](https://www.g2.com/products/sumo-logic/reviews) | Cloud-native SIEM with unified observability | "Centralized Logging with Intuitive Dashboards" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_f7c81a73a5adf5f83fb61d5a8f5f6a15/todyl-security-platform.png "Product Avatar Image")](https://www.g2.com/products/todyl-security-platform/reviews)[Todyl Security Platform](https://www.g2.com/products/todyl-security-platform/reviews)[4.7/5(106)](https://www.g2.com/products/todyl-security-platform/reviews) | Unified SIEM with embedded MXDR for MSPs | "Valuable Visibility with Room for Improvement" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8dedb235969bcb553f9e412b16e93d0a/check-point-infinity-platform.png "Product Avatar Image")](https://www.g2.com/products/check-point-infinity-platform/reviews)[Check Point Infinity Platform](https://www.g2.com/products/check-point-infinity-platform/reviews)[4.6/5(117)](https://www.g2.com/products/check-point-infinity-platform/reviews) | Unified threat prevention across hybrid security infrastructure | "Excellent option Harmony Platform for security central" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_4e2b08dd17397bdc99a5658447cbc589/microsoft-sentinel.jpg "Product Avatar Image")](https://www.g2.com/products/microsoft-sentinel/reviews)[Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)[4.4/5(298)](https://www.g2.com/products/microsoft-sentinel/reviews) | Cloud-native SIEM with Microsoft ecosystem integration | "Best Cloud native SIEM - Microsoft Sentinel" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_16dfa8129f7c019c451bdcef5de2a937/panther%282%29.jpg "Product Avatar Image")](https://www.g2.com/products/panther/reviews)[Panther](https://www.g2.com/products/panther/reviews)[4.7/5(49)](https://www.g2.com/products/panther/reviews) | Detection-as-code SIEM with Python-based alerting | "Panther’s SIEM + AI Makes Triage and Threat Hunting Fast and Seamless" |

* * *

Show More

### Security Information and Event Management (SIEM) Topics

- [What is security information and event management (SIEM) software?](#what-is-security-information-and-event-management-siem-software)
- [Types of SIEM solutions](#types-of-siem-solutions)
- [What are the common features of SIEM systems?](#what-are-the-common-features-of-siem-systems)
- [What are the benefits of using SIEM products?](#what-are-the-benefits-of-using-siem-products)
- [Software related to SIEM tools](#software-related-to-siem-tools)
- [Challenges with SIEM software](#challenges-with-siem-software)
- [Which companies should buy SIEM solutions?](#which-companies-should-buy-siem-solutions)
- [How to choose the best SIEM software](#how-to-choose-the-best-siem-software)
- [How much does SIEM software cost?](#how-much-does-siem-software-cost)

[
### Security Information and Event Management (SIEM) Topics
Expand/Collapse ](#)
- [What is security information and event management (SIEM) software?](#what-is-security-information-and-event-management-siem-software)
- [Types of SIEM solutions](#types-of-siem-solutions)
- [What are the common features of SIEM systems?](#what-are-the-common-features-of-siem-systems)
- [What are the benefits of using SIEM products?](#what-are-the-benefits-of-using-siem-products)
- [Software related to SIEM tools](#software-related-to-siem-tools)
- [Challenges with SIEM software](#challenges-with-siem-software)
- [Which companies should buy SIEM solutions?](#which-companies-should-buy-siem-solutions)
- [How to choose the best SIEM software](#how-to-choose-the-best-siem-software)
- [How much does SIEM software cost?](#how-much-does-siem-software-cost)

## Learn More About Security Information and Event Management (SIEM) Software

### What is security information and event management (SIEM) software?

Security Information and Event Management (SIEM) is a centralized system for threat detection that aggregates security alerts from multiple sources, simplifying threat response and compliance reporting. SIEM software is one of the most commonly used tools for security administrators and security incident response professionals. They provide a single platform capable of facilitating event and threat protection, log analysis and investigation, and threat remediation. Some cutting-edge tools provide additional functionality for creating response workflows, data normalization, and advanced threat protection.

SIEM platforms help security programs operate by collecting security data for future analysis, storing these data points, correlating them to security events, and facilitating analysis of those events.

Security teams can define rules for typical and suspicious activities with SIEM tools. Advanced Next-Gen SIEM solutions leverage [machine learning](https://www.g2.com/articles/what-is-machine-learning) and [AI](https://www.g2.com/articles/what-is-artificial-intelligence) to refine behavior models continuously, enhancing [User and Entity Behavior Analytics (UEBA)](https://www.g2.com/categories/user-and-entity-behavior-analytics-ueba) and reducing false positives. These systems analyze data against set rules and behavioral patterns, flagging notable events when anomalies are detected.

Companies using SIEM solutions deploy sensors across digital assets to automate data collection. Sensors relay information back to the SIEM’s log and event database. When additional security incidents arise, the SIEM platform detects anomalies. It correlates similar logs to provide context and threat information for security teams as they attempt to remediate any existing threats or vulnerabilities.

#### **What does SIEM stand for?**

SIEM stands for security information and event management (SIEM), which is a combination of two different acronyms for security technology: security information monitoring (SIM) and security event management (SEM).

SIM is the practice of collecting, aggregating, and analyzing security data, typically in the form of logs. SIM tools automate this process and document security information for other sources, such as [intrusion detection systems](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps), [firewalls](https://www.g2.com/categories/firewall-software), or [routers](https://www.g2.com/categories/routers). Event logs and their associated informational components are recorded and stored for long periods for either retrospective analysis or compliance requirements.

SEM is a family of security software for discovering, analyzing, visualizing, and responding to threats as they arise. SEM is a core component of a security operations system. While SIM tools are designed for log collection and storage, SEM tools typically rely on SQL databases to store specific logs and other event data as they are generated in real time by security devices and IT systems. They usually also provide the functionality to correlate and analyze event data, monitor systems in real time, and alert security teams of abnormal activity.

SIEM combines the functionality of SIM and SEM to centralize control over log storage, event management, and real-time analysis. SIM and SEM have become defunct technologies, as SIEM’s rise has provided dual-purpose functionality. SIEM vendors offer a single tool capable of performing data aggregation, information correlation, and event management.

### Types of SIEM solutions

#### **Traditional SIEM**

Traditional SIEM tools are deployed on-premises with sensors placed on IT assets to analyze events and collect system logs. The data is used to develop baseline references and identify indicators of compromise. The SIEM product alerts security teams for intervention when a system becomes compromised.&nbsp;

#### **Cloud or virtual SIEM**

Cloud-based and virtualized SIEM software are tools typically used to secure cloud infrastructure and services a cloud provider delivers. These tools are often less expensive than on-premises solutions and more accessible to implement, as no physical labor is required. They are ideal for companies without local IT infrastructure.

#### [**Managed SIEM services**](https://www.g2.com/categories/managed-siem-services)

Companies that do not have a full-fledged security program may choose managed SIEM services to aid in management and reduce work for internal employees. These SIEM services are delivered by managed service providers who provide the customer data and dashboards with security information and activity, but the provider handles implementation and remediation.&nbsp;

### What are the common features of SIEM systems?

The following are some core features within SIEM software that can help users collect security data, analyze logs, and detect threats:

**Activity monitoring:** SIEM systems document the actions from endpoints within a network. The system alerts users of incidents and abnormal activities and documents the access point. Real-time tracking will document these for analysis as an event takes place.

**Asset management:** These SIEM features keep records of each network asset and its activity. The feature may also refer to the discovery of new assets accessing the network.

**Log management:** This functionality documents and stores event logs in a secure repository for reference, analysis, or compliance reasons.

**Event management:** As events occur in real time, the SIEM software alerts users of incidents. This allows security teams to intervene manually or trigger an automated response to resolve the issue.

[**Automated response**](https://www.g2.com/categories/security-information-and-event-management-siem/f/automated-response) **:** Response automation reduces the time spent diagnosing and resolving issues manually. The features are typically capable of quickly resolving common network security incidents.

**Incident reporting:** Incident reports document cases of abnormal activity and compromised systems. These can be used for forensic analysis or as a reference point for future incidents.

**Threat intelligence:** Threat intelligence feeds integrate information to train SIEM systems to detect emerging and existing threats. These threat feeds store information related to potential threats and vulnerabilities to ensure issues are discovered and teams are provided with the information necessary to resolve the problems as they occur.

[**Vulnerability assessment**](https://www.g2.com/categories/security-information-and-event-management-siem/f/vulnerability-assessment) **:** Vulnerability assessment tools may scan networks for potential vulnerabilities or audit data to discover non-compliant practices. Mainly, they’re used to analyze an existing network and IT infrastructure to outline access points that can be easily compromised.

[**Advanced analytics**](https://www.g2.com/categories/security-information-and-event-management-siem/f/advanced-analytics) **:** Advanced analytics features allow users to customize analysis with granular or individually specific metrics pertinent to the business’ resources.

[**Data examination**](https://www.g2.com/categories/security-information-and-event-management-siem/f/data-examination) **:** Data examination features typically facilitate the forensic analysis of incident data and event logs. These features allow users to search databases and incident logs to gain insights into vulnerabilities and incidents.

### What are the benefits of using SIEM products?

Below are a few of the main reasons SIEM software is commonly used to protect businesses of all sizes:

**Data aggregation and correlation:** SIEM systems and companies collect vast amounts of information from an entire network environment. This information is gathered from virtually anything interacting with a network, from endpoints and servers to firewalls and antivirus tools. It is either given directly to the SIEM or using agents (decision-making programs designed to identify irregular information). The platform is set up to deploy agents and collect and store similar information together according to security policies set in place by administrators.

**Incident alerting:** As information comes in from a network’s various connected components, the SIEM system correlates it using rule-based policies. These policies inform agents of normal behavior and threats. If any action violates these policies or malware or intrusion is discovered. At the same time, the SIEM platform monitors network activity; it is labeled as suspicious, security controls restrict access, and administrators are alerted.

**Security analysis:** Retrospective analysis may be performed by searching log data during specific periods or based on specific criteria. Security teams may suspect a certain misconfiguration or kind of malware caused an event. They may also suspect an unapproved party went undetected at a specific time. Teams will analyze the logs and look for specific characteristics in the data to determine whether their suspicion was right. They may also discover vulnerabilities or misconfigurations that leave them susceptible to attack and remediate them.

### Software related to SIEM tools

Many network and system security solutions involve collecting and analyzing event logs and security information. SIEM systems are typically the most all-encompassing solutions available, but many other security solutions may integrate with them for added functionality or complementary use. These are a few different technology categories related to SIEM software.

[Threat intelligence software](https://www.g2.com/categories/threat-intelligence) **:** Threat intelligence software is an informational service that provides SIEM tools and other information security systems with up-to-date information on web-based threats. They can inform the system of zero-day threats, new forms of malware, potential exploits, and different kinds of vulnerabilities.

[Incident response software](https://www.g2.com/categories/incident-response) **:** SIEM systems may facilitate incident response, but these tools are specifically designed to streamline the remediation process or add investigative capabilities during security workflow processes. Incident response solutions will not provide the same compliance maintenance or log storage capabilities. Still, they can be used to increase a team’s ability to tackle threats as they emerge.

[Network security policy management (NSPM) software](https://www.g2.com/categories/network-security-policy-management-nspm) **:** NSPM software has some overlapping functionality to ensure security hardware and IT systems are correctly configured but cannot detect and resolve threats. They are typically used to ensure devices like firewalls or DNS filters are functioning correctly and in alignment with the security rules put in place by security teams.

[Intrusion detection and prevention systems (IDPS)](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps) **:** While SIEM systems specialize in log management, alerting, and correlation, IDPS provide additional detection and protection features to prevent unapproved parties from accessing sensitive systems and network breaches. However, they will not facilitate the analysis and forensic investigation of logs with the same level of detail as an SIEM system.

[Managed security services providers](https://www.g2.com/categories/managed-security-services) **:** Various managed security services are available for businesses without the resources or staff necessary to operate a full-fledged security administration and operations team. Managed services are a viable option and will provide companies with skilled staff to protect their customers’ systems and keep their sensitive information protected.

### Challenges with SIEM software

**Staffing:** There is an existing shortage of skilled security professionals. Managing SIEM products and maintaining a well-rounded security posture requires dedicated personnel with highly specialized skills. Some smaller or growing companies may not have the means to recruit, hire, and retain qualified security pros. In such cases, businesses can consider managed services to outsource the labor.&nbsp;

**Compliance:** Some industries have specific compliance requirements determined by various governing bodies, but SIEM software can be used across several industries to maintain compliance standards. Many industry-specific compliance requirements exist, but most require security teams to protect sensitive data, restrict access to unapproved parties, and monitor changes made to identities, information, or privileges. For example, SIEM systems can maintain GDPR compliance by verifying security controls and data access, facilitating long-term storage of log data, and notifying security staff of security incidents, as GDPR requires.

### Which companies should buy SIEM solutions?

**Vertical industries:** Vertical industries, such as healthcare and financial services, often have additional compliance requirements related to data protection and privacy. SIEM is an ideal solution for outlining requirements, mapping threats, and remediating vulnerabilities.&nbsp;

**SaaS business:** SaaS businesses utilizing resources from a cloud service provider are still responsible for a significant portion of the security efforts required to protect a cloud-native business. These companies may jump for cloud-native SIEM tools but will benefit from any SIEM to prevent, detect, and respond to threats.&nbsp;

### How to choose the best SIEM software

#### Requirements Gathering (RFI/RFP) for Security Information and Event Management (SIEM) Software

The first step to purchasing a SIEM solution is to outline the options. Companies should be sure whether they need a cloud-based or on-premises solution. They should also outline the number of interconnected devices they need and whether they want physical or virtual sensors to secure them. Additional and possibly obvious requirements should include budgetary considerations, staffing limitations, and required integrations_.&nbsp;_

#### **Compare Security Information and Event Management (SIEM) Software Products**

##### **Create a long list**

Once the requirements are outlined, buyers should prioritize the tools and identify the ones with as many features as possible that fit the budget window. It is recommended to restrict the list to products with desired features, pricing, and deployment methods to identify a dozen or so options. For example, if the business needs a cloud-native SIEM for less than $10k a year, half of the SIEM options will be eliminated.&nbsp;

When choosing a SIEM provider, focus on the vendor’s experience, reputation, and specific functionality relevant to your security needs. Core capabilities ensure essential threat detection, while next-gen features add advanced intelligence and automation, allowing for a more proactive security posture. Here’s a breakdown to guide your selection:

**Core SIEM capabilities**

- Threat detection: Look for SIEMs with robust threat detection, which uses rules and behavioral analytics, along with threat feed integration, to accurately identify potential threats.
- Threat intelligence and security alerting: Leading SIEMs incorporate threat intelligence feeds, aggregate security data, and alert you when suspicious activities are detected, ensuring real-time updates on evolving threats.
- Compliance reporting: Compliance support is crucial, especially for meeting standards like HIPAA, PCI, and FFIEC. SIEMs streamline compliance assessment and reporting, helping prevent costly non-compliance.
- Real-time notifications: Swift alerts are vital; SIEMs that notify you of breaches immediately enable faster responses to potential threats.
- Data aggregation: A centralized view of all network activities ensures no area is left unmonitored, which is crucial for comprehensive threat visibility as your organization scales.
- Data normalization: SIEMs that normalize incoming data make it easier to analyze security events and extract actionable insights from disparate sources.

**Next-gen SIEM capabilities**

- Data collection and management: Next-gen SIEMs pull data from the cloud, on-premises, and external devices, consolidating insights across the entire IT environment.
- Cloud delivery: Cloud-based SIEMs use scalable storage, accommodating large data volumes without the limitations of on-premises hardware.
- User and entity behavior analytics (UEBA): By establishing normal user behavior and identifying deviations, UEBA helps detect insider threats and new, unknown threats.
- Security orchestration and automation response (SOAR): SOAR automates incident response, integrates with IT infrastructure, and enables coordinated responses across firewalls, email servers, and access controls.
- Automated attack timelines: Next-gen SIEMs automatically create visual attack timelines, simplifying investigation and triage, even for less experienced analysts.

Selecting an SIEM vendor with both core and next-gen capabilities offers your organization a comprehensive and agile approach to security, meeting both current and future requirements.

##### **Create a short list**

Narrowing down a short list can be tricky, especially for the indecisive, but these decisions must be made. Once the long list is limited to affordable products with the desired features, it’s time to search for third-party validation. For each tool, the buyer must analyze end-user reviews, analyst reports, and empirical security evaluations. Combining these specified factors should help rank options and eliminate poorly performing products. _&nbsp;_

##### **Conduct demos**

With the list narrowed down to three to five possible products, businesses can contact vendors and schedule demos. This will help them get first-hand experience with the product, ask targeted questions, and gauge the vendors' quality of service.&nbsp;

Here are some essential questions to guide your decision:

- Will the tool enhance log collection and management?: 

Effective log collection is foundational. Look for compatible software across systems and devices, offering a user-friendly dashboard for streamlined monitoring.

- Does the tool support compliance efforts?

Even if compliance isn't a priority, choosing an SIEM that facilitates auditing and reporting can future-proof your operations. Look for tools that simplify compliance processes and reporting.

- Can the tool leverage past security events in threat response?

One of SIEM’s strengths is using historical data to inform future threat detection. Ensure the tool offers in-depth analytics and drill-down capabilities to analyze and act on past incidents.

- Is the incident response fast and automated?

Timely, effective responses are critical. The tool should provide customizable alerts that notify your team immediately when needed so you can confidently leave the dashboard.&nbsp;

#### Selection of Security Information and Event Management (SIEM) Software

##### **Choose a selection team**

Decision-makers need to involve subject matter experts from all teams that will use the system in choosing a selection team. For backup software, this primarily involves product managers, developers, IT, and security staff. Any manager or department-level leader should also include individuals managing any solution the backup product will be integrating with.&nbsp;

##### **Negotiation**

The seniority of the negotiation team may vary depending on the maturity of the business. It is advisable to include relevant directors or managers from the security and IT departments as well as from any other cross-functional departments that may be impacted.

##### **Final decision**

If the company has a chief information security officer (CISO), that individual will likely decide.&nbsp;If not, companies must trust their security professionals’ ability to use and understand the product.&nbsp;

### How much does SIEM software cost?

Potential growth should be considered if the buyer chooses a cloud-based SIEM tool that offers pricing on the SaaS pay-as-you-use model. Some solutions are inexpensive at the start and offer affordable, low-tier pricing. Alternatively, some may rapidly increase pricing and fees as the company and storage need to scale. Some vendors provide permanently free backup products for individuals or small teams.

**Cloud SIEM_:_** SIEM as a service pricing may vary, but it traditionally scales as storage increases. Additional costs may come from increased features such as automated remediation, security orchestration, and integrated threat intelligence.&nbsp;

**On-premises SIEM:** On-premises solutions are typically more expensive and require more effort and resources. They will also be more costly to maintain and require dedicated staff. Still, companies with high compliance requirements should adopt on-premises security regardless.&nbsp;

#### Return on Investment (ROI)

Cloud-based SIEM solutions will provide a quicker ROI, similar to their lower average cost. The situation is pretty cut and dry since there is much lower initial investment and lower demand for dedicated staffing.&nbsp;

However, for on-premises systems, the ROI will depend on the scale and scope of business IT systems. Hundreds of servers will require hundreds of sensors, potentially more, as time wears on computing equipment. Once implemented, they must be operated and maintained by (expensive) security professionals.