# Best Security Information and Event Management (SIEM) Software Solutions

## How Many Security Information and Event Management (SIEM) Software Products Does G2 Track?

**Total Products under this Category:** 141

### Category Stats (Aug 2026)

- **Average Rating:** 4.46/5 (↑0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+21.43%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: August 21, 2026_

## How Does G2 Rank Security Information and Event Management (SIEM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 6,000+ Authentic Reviews
- 141+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Security Information and Event Management (SIEM) Software
 ![G2 Grid® for Security Information and Event Management (SIEM) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/security-information-and-event-management-siem/grids.png?focus%5B%5D=30500&focus%5B%5D=68606&focus%5B%5D=1430041&focus%5B%5D=5691&focus%5B%5D=10436&focus%5B%5D=53174&focus%5B%5D=1408626&focus%5B%5D=122123)

Highlighted products: Google Security Operations, CrowdStrike Falcon Endpoint Protection Platform, Palo Alto Cortex XSIAM, ManageEngine ADAudit Plus, Sumo Logic, Todyl Security Platform, Huntress Managed SIEM, and Microsoft Sentinel.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-information-and-event-management-siem/grids.json?focus%5B%5D=google-security-operations&focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=manageengine-adaudit-plus&focus%5B%5D=sumo-logic&focus%5B%5D=todyl-security-platform&focus%5B%5D=huntress-managed-siem&focus%5B%5D=microsoft-sentinel)

**Sponsored**

### Graylog

Graylog is a log management and security information and event management (SIEM) solution designed to assist security and IT teams in detecting, investigating, and responding to potential threats with increased efficiency. By leveraging advanced technologies such as scalable log management, real-time data correlation, and explainable artificial intelligence (AI), Graylog transforms complex data sets into actionable insights, enabling organizations to make informed decisions swiftly. The platform caters to a diverse range of users, from small businesses to large enterprises, all of whom require enhanced visibility and control over their IT environments. Graylog is particularly beneficial for security analysts and IT professionals who need to sift through vast amounts of log data to identify anomalies, track incidents, and ensure compliance with various regulatory standards. Its user-friendly interface and powerful analytical tools streamline the process of threat detection and response, making it an essential asset for organizations aiming to bolster their cybersecurity posture. Key features of Graylog include automated workflows that simplify repetitive tasks, anomaly detection capabilities that flag unusual patterns in data, and guided investigations that assist users in navigating complex security incidents. The platform also offers AI-driven summaries that distill critical information, allowing analysts to focus on high-priority issues without getting bogged down by excessive data. These features collectively enhance the speed and accuracy of threat responses, ensuring that security teams remain in control of their environments. Graylog's versatility is evident in its range of products, which includes Graylog Security, Enterprise, API Security, and Open solutions. Each product is tailored to meet the specific needs of different organizations, providing clarity and context across various operational landscapes. With a user base of over 60,000 organizations globally, Graylog has established itself as a trusted partner in the realm of cybersecurity and log management, helping teams navigate the complexities of modern threats while maintaining a clear focus on their objectives.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=paid_promo&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1081&secure%5Bchosen_at%5D=2026-08-21T11%3A51%3A45Z&secure%5Bmedium%5D=sponsored&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=42017&secure%5Bresource_id%5D=1081&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-information-and-event-management-siem&secure%5Btoken%5D=5bd4800af93a4f98cee4f36866cda04309b33c6d4046d5ea0a4109fb92ca6814&secure%5Burl%5D=https%3A%2F%2Fwww.graylog.org%2Foverview&secure%5Burl_type%5D=paid_promos)

### [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)

Google Security Operations offers a unified experience across SIEM, SOAR, and threat intelligence to drive better detection, investigation, and response. Collect security telemetry data, apply threat intel to identify high priority threats, drive response with playbook automation, case management, and collaboration. It also provides Gemini-native agentic defense to help autonomously handle workflows like alert triage, threat hunting, and detection engineering. Google Security Operations also supports AI Threat Defense to monitor, detect, and respond to threats from code you do not own or cannot patch.

**Average Rating:** 4.4/5.0

**Total Reviews:** 100

#### How Do G2 Users Rate Google Security Operations?

- **Activity Monitoring:** 9.6/10 (Category avg: 9.1/10)
- **Data Examination:** 9.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **Log Management:** 9.6/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Google Security Operations?

- **Seller:** [Google](https://www.g2.com/sellers/google)
- **Year Founded:** 1998
- **HQ Location:** Mountain View, CA
- **Twitter:** @google  
31,899,995 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fe4a5936665c9702418dd53c477fef5a7baea08078bb117ed67e966fc581b9ec&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1441%2F&secure%5Burl_type%5D=linkedin_company_website)  
341,888 employees on LinkedIn®
- **Ownership:** NASDAQ:GOOG

#### Who Uses This Product?

- **Who Uses This:** Student
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 37% Medium, 33% Small

#### What Do G2 Reviewers Say About Google Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **centralized detection and investigation** of Google Security Operations, enhancing efficiency in threat management.
- Users value the **high-level threat detection** capabilities of Google Security Operations, enhancing their security response efficiency.
- Users find Google Security Operations very **easy to use** , allowing for quick incident analysis and efficient responses.
- Users value the **comprehensive security** of Google Security Operations for effectively detecting and responding to threats.
- Users appreciate the **seamless integrations** of Google Security Operations, enhancing threat detection and providing a unified security view.

##### Cons

- Users find the **costly upkeep** of Google Security Operations challenging, especially for large organizations.
- Users often face a **steep learning curve** with Google Security Operations, especially if unfamiliar with Google Cloud services.
- Users find the **implementation and configuration complex** , requiring more time and resources compared to other tools.
- Users find the **learning difficulty** of Google Security Operations challenging due to its complex features and setup.
- Users find **limited customization** in Google Security Operations hinders adaptability and user experience for specific security needs.

#### What Are Recent G2 Reviews of Google Security Operations?

**["Powerful Dashboard, Automation & AI Insights—But a Steep Learning Curve"](https://www.g2.com/survey_responses/google-security-operations-review-13239114)**

**Rating:** 4.5/5.0 stars

_— Parthik P._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13239114)

**["Unified SIEM/SOAR with Powerful AI Investigation in Google Security Operations"](https://www.g2.com/survey_responses/google-security-operations-review-13324284)**

**Rating:** 4.5/5.0 stars

_— Atharva S._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13324284)

### [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)

Organizations today face a serious challenge: managing numerous security vendors and tools while confronting an ever-evolving threat landscape. Sophisticated adversaries are becoming smarter, faster, and more evasive, launching complex attacks that can strike in minutes or even seconds. Traditional security approaches struggle to keep pace, leaving businesses vulnerable. The CrowdStrike Falcon Platform addresses this by offering a unified, cloud-native solution. It consolidates previously siloed security solutions and incorporates third-party data into a single platform with one efficient and resource-conscious agent, leveraging advanced AI and real-time threat intelligence. This approach simplifies security operations, speeds analyst decision making, and enhances protection to stop the breach, allowing organizations to reduce risk with less complexity and lower costs. CrowdStrike's Falcon Platform includes: - Endpoint Security: Secure the endpoint, stop the breach - Identify Protection: Identity is the front line, defend it - Next-Gen SIEM: The future of SIEM, today - Data Protection: Real-time data protection from endpoint to cloud - Exposure Management: Understand risk to stop breaches - Charlotte AI: Powering the next evolution of the SOC

**Average Rating:** 4.6/5.0

**Total Reviews:** 419

#### How Do G2 Users Rate CrowdStrike Falcon Endpoint Protection Platform?

- **Activity Monitoring:** 9.5/10 (Category avg: 9.1/10)
- **Data Examination:** 8.8/10 (Category avg: 8.6/10)
- **Ease of Use:** 9.0/10 (Category avg: 8.7/10)
- **Log Management:** 8.7/10 (Category avg: 9.1/10)

#### Who Is the Company Behind CrowdStrike Falcon Endpoint Protection Platform?

- **Seller:** [CrowdStrike](https://www.g2.com/sellers/crowdstrike)
- **Company Website:** www.crowdstrike.com
- **Year Founded:** 2011
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @CrowdStrike  
110,809 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f13dce0bc1628ccb762ed9d5acb4e0f0998a717639b903c3d3a271ef1da6ad7b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2497653%2F&secure%5Burl_type%5D=linkedin_company_website)  
11,343 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Analyst, Cyber Security Analyst
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 43% Large, 42% Medium

#### What Do G2 Reviewers Say About CrowdStrike Falcon Endpoint Protection Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **lightweight performance and powerful threat detection** of CrowdStrike Falcon, enhancing security without slowing down systems.
- Users commend the **effective threat detection** capabilities of CrowdStrike Falcon, ensuring robust security without system slowdowns.
- Users appreciate the **ease of use** of CrowdStrike Falcon, benefiting from its lightweight impact and efficient incident management.
- Users appreciate the **advanced real-time threat protection** of CrowdStrike Falcon, ensuring efficient security without system performance issues.
- Users praise the **exceptional threat detection** of CrowdStrike Falcon, noting its effectiveness against both known and unknown threats.

##### Cons

- Users find the **cost prohibitive** for smaller organizations, especially with additional modules increasing overall expenses.
- Users find the **complexity of the user interface** and additional costs challenging, complicating their overall experience.
- Users face a **steep learning curve** with CrowdStrike’s query language, making transitions from other platforms challenging.
- Users find the **limited features** challenging, especially concerning cost and technical accessibility for smaller businesses.
- Users find that **pricing can be a barrier** for smaller organizations, complicating access to advanced features.

#### What Are Recent G2 Reviews of CrowdStrike Falcon Endpoint Protection Platform?

**["Crowdstrike Falcon: Proactive Security, Steep Learning Curve"](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)**

**Rating:** 5.0/5.0 stars

_— Ansh B._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)

**["“Powerful and Reliable Endpoint Protection”"](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-13240446)**

**Rating:** 4.5/5.0 stars

_— gautam p._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-13240446)

#### What Are G2 Users Discussing About CrowdStrike Falcon Endpoint Protection Platform?

- [How does Falcon prevent work?](https://www.g2.com/discussions/how-does-falcon-prevent-work) - 2 comments
- [Does CrowdStrike offer MFA?](https://www.g2.com/discussions/does-crowdstrike-offer-mfa) - 1 comment
- [What is OverWatch in CrowdStrike?](https://www.g2.com/discussions/what-is-overwatch-in-crowdstrike) - 1 comment
- [How much does CrowdStrike Falcon X cost?](https://www.g2.com/discussions/how-much-does-crowdstrike-falcon-x-cost)
- [What is MDR detection?](https://www.g2.com/discussions/what-is-mdr-detection)

### [Palo Alto Cortex XSIAM](https://www.g2.com/products/palo-alto-cortex-xsiam/reviews)

Product Description: Palo Alto Networks' Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.

**Average Rating:** 4.5/5.0

**Total Reviews:** 88

#### How Do G2 Users Rate Palo Alto Cortex XSIAM?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.6/10 (Category avg: 8.7/10)
- **Log Management:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Palo Alto Cortex XSIAM?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Company Website:** www.paloaltonetworks.com
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 43% Large, 37% Medium

#### What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **best-in-class log management** of Palo Alto Cortex XSIAM, benefiting from its effective alerting and integration features.
- Users find the **user-friendly dashboard** of Palo Alto Cortex XSIAM essential for monitoring and understanding alerts effectively.
- Users value the **real-time monitoring** capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
- Users value the **simple and user-friendly interface** of Palo Alto Cortex XSIAM, making monitoring effortless.
- Users value the **good dashboard creation tools** in Palo Alto Cortex XSIAM, enhancing ease of use and implementation.

##### Cons

- Users note that Palo Alto Cortex XSIAM requires **significant resources** , impacting implementation time and increasing infrastructure costs.
- Users find the **complexity of implementation** for Palo Alto Cortex XSIAM to be time-consuming and resource-intensive.
- Users find the **cost** of Palo Alto Cortex XSIAM to be high, especially for smaller businesses.
- Users face **dashboard issues** with XSIAM, finding it difficult to monitor assets and navigate the interface.
- Users face **difficult setup** issues with Palo Alto Cortex XSIAM, requiring expertise and extensive time for initial implementation.

#### What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

**["Powerful, Unified Security Operations with AI-Driven Threat Detection"](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13276789)**

**Rating:** 4.5/5.0 stars

_— Rahul S._

[Read full review](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13276789)

**["Cortex XSIAM Streamlines Threat Detection and Security Monitoring"](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13245886)**

**Rating:** 4.5/5.0 stars

_— Jacob Karthigayan V._

[Read full review](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-13245886)

#### What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

- [What is IBM Security ReaQta used for?](https://www.g2.com/discussions/what-is-ibm-security-reaqta-used-for) - 1 comment
- [What does QRadar stand for?](https://www.g2.com/discussions/what-does-qradar-stand-for) - 1 comment, 1 upvote
- [How do I use IBM QRadar?](https://www.g2.com/discussions/how-do-i-use-ibm-qradar) - 1 comment
- [What are the key component of IBM QRadar?](https://www.g2.com/discussions/what-are-the-key-component-of-ibm-qradar) - 1 comment
- [What is IBM QRadar Siem?](https://www.g2.com/discussions/what-is-ibm-qradar-siem) - 1 comment

### [ManageEngine ADAudit Plus](https://www.g2.com/products/manageengine-adaudit-plus/reviews)

ADAudit Plus is a UBA-driven auditor that helps keep your AD, Azure AD, file systems (including Windows, NetApp, EMC, Synology, Hitachi, and Huawei), Windows servers, and workstations secure and compliant. ADAudit Plus transforms raw and noisy event log data into real-time reports and alerts, enabling you to get full visibility into activities happening across your Windows Server ecosystem in just a few clicks. More than 10,000 organizations across the world trust ADAudit Plus to: 1. Instantly notify them about changes in their Windows Server environments. 2. Continuously track Windows user logon activity. 3. Monitor the active and idle time spent by employees at their workstations. 4. Detect and troubleshoot AD account lockouts. 5. Provide a consolidated audit trail of privileged user activities across their domains. 6. Track changes and sign-ins in Azure AD. 7. Audit file accesses across Windows, NetApp, EMC, Synology, Hitachi, and Huawei file systems. 8. Monitor file integrity across local files residing on Windows systems. 9. Mitigate insider threats by leveraging UBA and response automation. 10. Generate audit-ready compliance reports for SOX, the GDPR, and other IT mandates.

**Average Rating:** 4.6/5.0

**Total Reviews:** 59

#### How Do G2 Users Rate ManageEngine ADAudit Plus?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.8/10 (Category avg: 8.7/10)
- **Log Management:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind ManageEngine ADAudit Plus?

- **Seller:** [Zoho](https://www.g2.com/sellers/zoho-b00ca9d5-bca8-41b5-a8ad-275480841704)
- **Year Founded:** 1996
- **HQ Location:** Austin, TX
- **Twitter:** @Zoho  
137,880 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9c8e45ddb296c32c6c5597ef9ba945c94562c57624f7bd1dcf1a9e9931f71578&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F38373%2F&secure%5Burl_type%5D=linkedin_company_website)  
30,766 employees on LinkedIn®
- **Phone:** +1 (888) 900-9646 

#### Who Uses This Product?

- **Top Industries:** Hospital & Health Care, Information Technology and Services
- **Company Size:** 59% Medium, 32% Large

#### What Do G2 Reviewers Say About ManageEngine ADAudit Plus?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **depth of visibility and reporting options** provided by ManageEngine ADAudit Plus for Active Directory.
- Users appreciate the **user-friendly dashboard** of ManageEngine ADAudit Plus, enhancing navigation and providing valuable insights.
- Users appreciate the **easy setup and extensive reporting options** of ManageEngine ADAudit Plus for efficient Active Directory management.
- Users appreciate the **intuitive overview** provided by ADAudit Plus's dashboard, enhancing their Active Directory management experience.
- Users value the **insightful dashboard** of ADAudit Plus, which offers extensive reporting options and useful auditing features.

##### Cons

- Users find the limited **alert levels** in ADAudit Plus restricting, wishing for more options to fine-tune notifications.
- Users find the **data overload** challenge due to many reporting options, though a search feature helps alleviate this issue.
- Users note the **high cost** of ManageEngine ADAudit Plus, which some feel isn't justified by its support quality.
- Users find that **false positives** can be overwhelming, but a search feature helps manage report navigation.
- Users are concerned about the **high resource usage** of ManageEngine ADAudit Plus, impacting overall system performance.

#### What Are Recent G2 Reviews of ManageEngine ADAudit Plus?

**["Easy Setup, Powerful Reporting, and Great Value"](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-12999020)**

**Rating:** 4.5/5.0 stars

_— Ryan A._

[Read full review](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-12999020)

**["Great Tool for Active Directory Auditing and Investigations"](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-13001820)**

**Rating:** 5.0/5.0 stars

_— Jose R._

[Read full review](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-13001820)

#### What Are G2 Users Discussing About ManageEngine ADAudit Plus?

- [What does AD audit do?](https://www.g2.com/discussions/what-does-ad-audit-do)
- [Is Ad audit plus a SIEM?](https://www.g2.com/discussions/is-ad-audit-plus-a-siem)
- [What is ManageEngine Audit Plus?](https://www.g2.com/discussions/what-is-manageengine-audit-plus)
- [What does ADAudit plus do?](https://www.g2.com/discussions/what-does-adaudit-plus-do)

### [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)

Sumo Logic, Inc. unifies and analyzes enterprise data, translating it into actionable insights through one AI-powered cloud-native log analytics platform. This single source of truth enables Dev, Sec and Ops teams to simplify complexity, collaborate efficiently and accelerate data-driven decisions that drive business value. Customers around the world rely on the Sumo Logic SaaS Log Analytics Platform for trusted insights to ensure application reliability, secure and protect against modern security threats, and gain insights into their cloud infrastructures. For more information, visit: SUMOLOGIC.COM

**Average Rating:** 4.3/5.0

**Total Reviews:** 394

#### How Do G2 Users Rate Sumo Logic?

- **Activity Monitoring:** 9.1/10 (Category avg: 9.1/10)
- **Data Examination:** 9.0/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **Log Management:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Sumo Logic?

- **Seller:** [Sumo Logic](https://www.g2.com/sellers/sumo-logic)
- **Company Website:** www.sumologic.com
- **Year Founded:** 2010
- **HQ Location:** Redwood City, CA
- **Twitter:** @SumoLogic  
6,542 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=405f2514b57035d31a9696f673d9692138c137173787398caeba6974c512d779&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1037816%2F&secure%5Burl_type%5D=linkedin_company_website)  
838 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 48% Medium, 37% Large

#### What Do G2 Reviewers Say About Sumo Logic?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** in Sumo Logic, citing its simple query language and intuitive configurations.
- Users value the **ease of searching and configuring logs** with Sumo Logic, enhancing their monitoring and tracing efficiency.
- Users appreciate the **Comprehensive Continuous Intelligence feature** of Sumo Logic for transforming data into actionable insights quickly.
- Users value the **powerful visual insights** and efficient log management capabilities of Sumo Logic for fast resolution.
- Users value the **real-time monitoring capabilities** of Sumo Logic, enjoying swift insights and effective data management.

##### Cons

- Users find Sumo Logic **expensive** , prompting concerns about whether its value justifies the high pricing.
- Users find the **difficult learning** curve of Sumo Logic challenging, requiring significant time to become proficient.
- Users face a **steep learning curve** with Sumo Logic, requiring significant time to master its features and query language.
- Users face a **steep learning curve** with Sumo Logic, requiring significant time to master complex features and queries.
- Users experience **slow performance** with Sumo Logic, facing delays in alerting and a cumbersome user interface.

#### What Are Recent G2 Reviews of Sumo Logic?

**["Secure, Privacy-First AI Logging That Helps Reduce Data Breach Risk"](https://www.g2.com/survey_responses/sumo-logic-review-13156334)**

**Rating:** 4.5/5.0 stars

_— Aiyappa Baleyada B._

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-13156334)

**["Sumo Logic Makes Multi-Cloud Observability Scale with an API-First, Search-Centric Workflow"](https://www.g2.com/survey_responses/sumo-logic-review-13324396)**

**Rating:** 5.0/5.0 stars

_— Ssherie C._

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-13324396)

#### What Are G2 Users Discussing About Sumo Logic?

- [What is Cloud SOAR used for?](https://www.g2.com/discussions/what-is-cloud-soar-used-for) - 1 comment, 1 upvote
- [Is Sumo Logic a SIEM?](https://www.g2.com/discussions/is-sumo-logic-a-siem)
- [What is Sumo Logic used for?](https://www.g2.com/discussions/what-is-sumo-logic-used-for)
- [Who are Sumo Logic competitors?](https://www.g2.com/discussions/who-are-sumo-logic-competitors) - 1 comment
- [How much does Sumo Logic cost?](https://www.g2.com/discussions/how-much-does-sumo-logic-cost)

### [Todyl Security Platform](https://www.g2.com/products/todyl-security-platform/reviews)

Todyl is an AI-powered Cybersecurity and Assurance Platform for threat, risk, and compliance management delivered through a single agent and a single portal. Our platform defends against modern, advanced threats spanning identity, endpoint, network, cloud, SaaS, and more. We also simplify meeting and demonstrating extensive compliance and insurance requirements with centralized data collection and reporting, easy-to-use assessment tools, a built-in risk register, and dashboards to cut back on manual reporting and spreadsheet sprawl. Our platform delivers a layered approach to cybersecurity, spanning SASE, Micro-Segmentation (LZT), Endpoint Security, SIEM, MXDR, and GRC all delivered through the same agent, in a cloud native platform. It’s easy to implement as a cost effective, fully integrated single solution that can consolidate and simplify your security and compliance programs. You can also deploy individual modules to meet your current needs, with a simple toggle within the UI to add or trial new modules when you need them. And an integrated Assurance Marketplace helps you complete your security program with additional services like incident response and penetration testing, and streamlined access to cyber insurance providers.

**Average Rating:** 4.7/5.0

**Total Reviews:** 106

#### How Do G2 Users Rate Todyl Security Platform?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.9/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.7/10 (Category avg: 8.7/10)
- **Log Management:** 9.4/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Todyl Security Platform?

- **Seller:** [Todyl](https://www.g2.com/sellers/todyl)
- **Company Website:** www.todyl.com
- **Year Founded:** 2015
- **HQ Location:** Denver, CO
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=05d7ce90e9975077322588a582ff9aca56286ea0270706e601aa212b6ec71ed8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftodylprotection&secure%5Burl_type%5D=linkedin_company_website)  
122 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Owner, President
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 75% Small, 8% Medium

#### What Do G2 Reviewers Say About Todyl Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **ease of use** of Todyl, highlighting its intuitive interface and seamless integration capabilities.
- Users highlight the **responsive and accessible customer support** of Todyl, enhancing their overall experience and efficiency.
- Users praise the **convenient deployment** and comprehensive integration features of Todyl Security Platform for enhanced security.
- Users value the **comprehensive security** offered by Todyl, appreciating its ease of installation and cost-effectiveness.
- Users praise the **deployment ease** of Todyl, appreciating its intuitive interface and seamless integration across platforms.

##### Cons

- Users find there are **improvements needed** in customization, integrations, and the steep learning curve for Todyl's platform.
- Users report **integration issues** with Todyl, noting limited API capabilities and inconsistencies with third-party connections.
- Users find the **reporting options inadequate** , lacking ease of access and integration for strategic reviews.
- Users notice the **limited features** in Todyl, particularly in customization, API, and reporting capabilities.
- Users find the **reporting tools inadequate** , making it hard to extract useful insights for strategic reviews.

#### What Are Recent G2 Reviews of Todyl Security Platform?

**["Todyl Simplified Our Stack with Enterprise-Level Security at a Great Price"](https://www.g2.com/survey_responses/todyl-security-platform-review-12841444)**

**Rating:** 5.0/5.0 stars

_— Nahjee M._

[Read full review](https://www.g2.com/survey_responses/todyl-security-platform-review-12841444)

**["Valuable Visibility with Room for Improvement"](https://www.g2.com/survey_responses/todyl-security-platform-review-9155307)**

**Rating:** 4.0/5.0 stars

_— Ethan D._

[Read full review](https://www.g2.com/survey_responses/todyl-security-platform-review-9155307)

### [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)

Microsoft Sentinel lets you see and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can: - Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds - Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft - Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft -Respond to incidents rapidly with built-in orchestration and automation of common tasks

**Average Rating:** 4.4/5.0

**Total Reviews:** 275

#### How Do G2 Users Rate Microsoft Sentinel?

- **Activity Monitoring:** 8.9/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **Log Management:** 8.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Microsoft Sentinel?

- **Seller:** [Microsoft](https://www.g2.com/sellers/microsoft)
- **Year Founded:** 1975
- **HQ Location:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 employees on LinkedIn®
- **Ownership:** MSFT

#### Who Uses This Product?

- **Who Uses This:** Senior Software Engineer, Security Analyst
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 42% Large, 31% Medium

#### What Do G2 Reviewers Say About Microsoft Sentinel?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **advanced threat detection** of Microsoft Sentinel, enhancing security and proactive threat management.
- Users value the **seamless integration** of Microsoft Sentinel with various third-party and Microsoft products, enhancing functionality and management.
- Users appreciate the **seamless integration** with third-party software and Microsoft products, enhancing their overall experience.
- Users praise Microsoft Sentinel for its **robust threat detection** , ensuring a secure environment in hybrid and multicloud settings.
- Users value the **seamless cloud integration** of Microsoft Sentinel, appreciating its simplicity and flexibility in deployment.

##### Cons

- Users express concerns over **cloud dependency** , which can complicate usage, especially for those with low-speed internet.
- Users find the **setup and configuration complex** , requiring high technical expertise and time investment for effective use.
- Users find the **configuration issues** of Microsoft Sentinel challenging, often requiring significant time and technical expertise.
- Users find the **difficult setup** of Microsoft Sentinel challenging, especially without dedicated security experts and proper training.
- Users find **third-party integration challenging** , complicating the implementation and configuration of Microsoft Sentinel.

#### What Are Recent G2 Reviews of Microsoft Sentinel?

**["Easy Log Ingestion Across Formats with Seamless Sentinel Integrations"](https://www.g2.com/survey_responses/microsoft-sentinel-review-13073395)**

**Rating:** 4.5/5.0 stars

_— Sandip K._

[Read full review](https://www.g2.com/survey_responses/microsoft-sentinel-review-13073395)

**["Best Cloud native SIEM - Microsoft Sentinel"](https://www.g2.com/survey_responses/microsoft-sentinel-review-13250215)**

**Rating:** 4.5/5.0 stars

_— vimal p._

[Read full review](https://www.g2.com/survey_responses/microsoft-sentinel-review-13250215)

#### What Are G2 Users Discussing About Microsoft Sentinel?

- [What is Microsoft Sentinel used for?](https://www.g2.com/discussions/what-is-microsoft-sentinel-used-for) - 3 comments, 2 upvotes
- [Why should I use Azure Sentinel?](https://www.g2.com/discussions/why-should-i-use-azure-sentinel) - 1 comment
- [Which feature provides the extended detection and response capabilities of Azure Sentinel?](https://www.g2.com/discussions/which-feature-provides-the-extended-detection-and-response-capabilities-of-azure-sentinel)
- [What is the difference between Azure security Center and Azure Sentinel?](https://www.g2.com/discussions/what-is-the-difference-between-azure-security-center-and-azure-sentinel)
- [What does Azure Sentinel provide?](https://www.g2.com/discussions/what-does-azure-sentinel-provide)

### [Huntress Managed SIEM](https://www.g2.com/products/huntress-managed-siem/reviews)

Huntress is a comprehensive cybersecurity solution designed specifically for the Fortune 5,000 and the managed service providers (MSPs) that support them. This platform combines advanced technology with a fully staffed 24/7 Security Operations Center (SOC) to deliver a robust defense against an ever-evolving landscape of cyber threats. By integrating cutting-edge tools, services, and expert knowledge, Huntress empowers businesses to effectively tackle their cybersecurity challenges and safeguard their critical business assets. The target audience for Huntress includes internal IT teams that may lack the resources or expertise to manage cybersecurity independently, as well as MSPs looking for reliable solutions to enhance their service offerings. These businesses often face unique challenges, such as budget constraints and limited IT staff, making it essential for them to adopt a cybersecurity strategy that is both effective and affordable. Huntress addresses these needs by providing a suite of purpose-built solutions tailored to these specific requirements, ensuring they can defend against cyber threats without compromising their operational efficiency. Key features of Huntress include its Managed Security Platform, which offers real-time threat detection and response capabilities. The platform continuously monitors for malicious activity, enabling rapid identification and remediation of potential threats. Additionally, the 24/7 SOC staffed by cybersecurity experts ensures that any incidents are promptly addressed, providing peace of mind to businesses that may not have in-house security teams. Huntress also emphasizes education, offering resources and training to help users understand cybersecurity best practices and stay informed about the latest threats. By delivering a combination of technology, services, and expertise, Huntress stands out in the cybersecurity landscape. The proactive approach of Huntress not only helps businesses defend against current threats but also prepares them for future challenges, making it a valuable partner in the ongoing fight against cybercrime.

**Average Rating:** 4.7/5.0

**Total Reviews:** 49

#### Who Is the Company Behind Huntress Managed SIEM?

- **Seller:** [Huntress Labs](https://www.g2.com/sellers/huntress-labs)
- **Company Website:** huntress.com
- **Year Founded:** 2015
- **HQ Location:** Ellicott City, US
- **Twitter:** @HuntressLabs  
40,338 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=570d57c2d792bb0f1dd9c97cb05ee13cfd2e93a1546d6d3c5c11e8ce22e14a55&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10172550%2F&secure%5Burl_type%5D=linkedin_company_website)  
978 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 64% Small, 24% Medium

#### What Are Recent G2 Reviews of Huntress Managed SIEM?

**["Centralized Logging and Investigation Powerhouse"](https://www.g2.com/survey_responses/huntress-managed-siem-review-12729137)**

**Rating:** 4.5/5.0 stars

_— Paul A._

[Read full review](https://www.g2.com/survey_responses/huntress-managed-siem-review-12729137)

**["Exemplary SIEM Service with Unmatched Support"](https://www.g2.com/survey_responses/huntress-managed-siem-review-12676229)**

**Rating:** 5.0/5.0 stars

_— Skylar P._

[Read full review](https://www.g2.com/survey_responses/huntress-managed-siem-review-12676229)

### [Check Point Infinity Platform](https://www.g2.com/products/check-point-infinity-platform/reviews)

Check Point Infinity is the only fully consolidated cyber security architecture that provides unprecedented protection against Gen V mega-cyber attacks as well as future cyber threats across all networks, endpoint, cloud and mobile. The architecture is designed to resolve the complexities of growing connectivity and inefficient security.

**Average Rating:** 4.6/5.0

**Total Reviews:** 109

#### How Do G2 Users Rate Check Point Infinity Platform?

- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Check Point Infinity Platform?

- **Seller:** [Check Point Software Technologies](https://www.g2.com/sellers/check-point-software-technologies)
- **Year Founded:** 1993
- **HQ Location:** Redwood City, CA
- **Twitter:** @CheckPointSW  
70,955 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d885813f6605ba84238ae4a21d169e0c9ade054cf0c99ff53e72483b54a8b521&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheck-point-software-technologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
8,554 employees on LinkedIn®
- **Ownership:** NASDAQ:CHKP

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 44% Large, 37% Medium

#### What Do G2 Reviewers Say About Check Point Infinity Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **advanced security features** of Check Point Infinity Platform, effectively preventing future attacks on cloud infrastructures.
- Users value the **cloud security features** of Check Point Infinity Platform for efficient audits and infrastructure evaluations.
- Users commend the **proactive threat detection** of Check Point Infinity Platform, enhancing security for cloud applications.
- Users highlight the **comprehensive security** features of Check Point Infinity Platform, effectively shielding against future attacks.
- Users value the **advanced security features** of Check Point Infinity for effectively safeguarding their cloud infrastructure.

##### Cons

- Users find the **steep learning curve** of Check Point Infinity Platform challenging due to its complexity and extensive features.
- Users find the **complex setup process** for Check Point Infinity Platform can be time-consuming and confusing at times.
- Users feel that **improvement is needed** in real-time support and custom ruleset creation for better functionality.
- Users express concerns about **poor support services** , indicating a need for improvement in customer assistance and log visibility.
- Users find the **limited customization** options challenging, affecting their ability to tailor the platform to their needs.

#### What Are Recent G2 Reviews of Check Point Infinity Platform?

**["Excellent option Harmony Platform for security central"](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11868343)**

**Rating:** 4.5/5.0 stars

_— Tania V._

[Read full review](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11868343)

**["Seamless Hybrid Security Integration Across All Environments"](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11954684)**

**Rating:** 4.5/5.0 stars

_— Sonu S._

[Read full review](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11954684)

#### What Are G2 Users Discussing About Check Point Infinity Platform?

- [How does Check Point Infinity help customers?](https://www.g2.com/discussions/how-does-check-point-infinity-help-customers)
- [What are the benefits of Check Point unified security architecture?](https://www.g2.com/discussions/what-are-the-benefits-of-check-point-unified-security-architecture)
- [What are the 4 components of the Infinity architecture?](https://www.g2.com/discussions/what-are-the-4-components-of-the-infinity-architecture)
- [What is Infinity Total protection?](https://www.g2.com/discussions/what-is-infinity-total-protection)

### [Panther](https://www.g2.com/products/panther/reviews)

Panther is the AI SOC Platform that scales security expertise by embedding AI agents across your security operations with native access to your data lake, detection logic, and organizational knowledge. Unlike bolt-on tools, Panther's closed-loop architecture turns every alert into compounding intelligence that makes the system smarter over time. Request a demo today at: https://panther.com/product/request-a-demo/

**Average Rating:** 4.7/5.0

**Total Reviews:** 49

#### How Do G2 Users Rate Panther?

- **Activity Monitoring:** 9.3/10 (Category avg: 9.1/10)
- **Data Examination:** 9.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.9/10 (Category avg: 8.7/10)
- **Log Management:** 9.7/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Panther?

- **Seller:** [Panther Labs](https://www.g2.com/sellers/panther-labs)
- **Year Founded:** 2018
- **HQ Location:** San Francisco, CA
- **Twitter:** @runpanther  
4,437 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5e833e3ee9905da8ffc2168b1d7db4af5d6a4643d77358f095ebefb033c5103a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Frunpanther%2F&secure%5Burl_type%5D=linkedin_company_website)  
269 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Senior Security Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 53% Medium, 29% Large

#### What Do G2 Reviewers Say About Panther?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise Panther's **responsive customer support** , which delivers expert assistance and resolves issues quickly and efficiently.
- Users laud Panther's **detection efficiency** , appreciating its swift JSON parsing and robust, adaptable detection capabilities.
- Users value Panther's **ease of use** , noting its intuitive interface and efficient operation for small teams.
- Users praise Panther's **intuitive interface and responsive support** , enhancing ease of use and effectiveness for security teams.
- Users praise the **easy log source integration** in Panther, simplifying onboarding and enhancing their security monitoring efforts.

##### Cons

- Users find the **raw log view limited** due to lack of summaries, customization options, and cumbersome configuration for alerts.
- Users face **complex configuration** challenges with Panther's setup, needing significant custom workflow adjustments and improvements.
- Users find the **dashboard issues** overwhelming, highlighting limitations in customization and functionality that hinder effective use.
- Users find Panther's **limited access** cumbersome, with challenges in integration, dashboards, and customizable alert features.
- Users note a **difficult learning curve** for Panther, especially for those not familiar with programming languages.

#### What Are Recent G2 Reviews of Panther?

**["Panther’s SIEM + AI Makes Triage and Threat Hunting Fast and Seamless"](https://www.g2.com/survey_responses/panther-review-12919421)**

**Rating:** 5.0/5.0 stars

_— Richard E._

[Read full review](https://www.g2.com/survey_responses/panther-review-12919421)

**["Panther Makes Security Operations Simpler and Faster"](https://www.g2.com/survey_responses/panther-review-12890548)**

**Rating:** 5.0/5.0 stars

_— Busra K._

[Read full review](https://www.g2.com/survey_responses/panther-review-12890548)

#### What Are G2 Users Discussing About Panther?

- [What is Panther used for?](https://www.g2.com/discussions/what-is-panther-used-for) - 1 comment

### [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)

Find out what is happening in your business and take meaningful action quickly with Splunk Enterprise. Automate the collection, indexing and alerting of machine data that's critical to your operations. Uncover the actionable insights from all your data — no matter the source or format. Leverage artificial intelligence and machine learning for predictive and proactive business decisions.

**Average Rating:** 4.3/5.0

**Total Reviews:** 415

#### How Do G2 Users Rate Splunk Enterprise?

- **Activity Monitoring:** 9.1/10 (Category avg: 9.1/10)
- **Data Examination:** 8.4/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.1/10 (Category avg: 8.7/10)
- **Log Management:** 9.3/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Splunk Enterprise?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 64% Large, 27% Medium

#### What Do G2 Reviewers Say About Splunk Enterprise?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Splunk Enterprise's **ease of use** remarkable, enabling quick access and seamless integration of large datasets.
- Users value the **robust data ingestion** capabilities of Splunk Enterprise, efficiently managing diverse data sources.
- Users commend the **great integration capabilities** of Splunk Enterprise, facilitating seamless implementation across various networks and systems.
- Users value the **flexibility and visualization capabilities** of Splunk Enterprise, enabling effective data analysis and troubleshooting.
- Users praise the **visualization capabilities** of Splunk Enterprise dashboards for effective data analysis and decision-making.

##### Cons

- Users find Splunk Enterprise to be **expensive** , with high renewal costs and limitations that affect large organizations.
- Users find the **learning curve steep** , struggling to quickly grasp Splunk Enterprise's many features and functionalities.
- Users experience **slow performance** with Splunk Enterprise, noting occasional crashes and delays in processing saved searches.
- Users find the **complex configuration** of Splunk Enterprise challenging, impacting performance optimization and overall user experience.
- Users find the **pricing issues** with Splunk Enterprise burdensome, especially regarding storage costs and data limits.

#### What Are Recent G2 Reviews of Splunk Enterprise?

**["SPL search and dashboards are really useful"](https://www.g2.com/survey_responses/splunk-enterprise-review-12547655)**

**Rating:** 4.0/5.0 stars

_— Nishith J._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-review-12547655)

**["Excellent Enterprise Observability and Log Management Solution for Hybrid Cloud Infrastructure"](https://www.g2.com/survey_responses/splunk-enterprise-review-12045230)**

**Rating:** 4.5/5.0 stars

_— RaviShankar S._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-review-12045230)

#### What Are G2 Users Discussing About Splunk Enterprise?

- [What is Splunk Enterprise used for?](https://www.g2.com/discussions/what-is-splunk-enterprise-used-for) - 1 comment
- [What is the difference between Splunk Enterprise and Splunk Enterprise Security?](https://www.g2.com/discussions/splunk-enterprise-what-is-the-difference-between-splunk-enterprise-and-splunk-enterprise-security) - 1 comment
- [What are Splunk Enterprise components?](https://www.g2.com/discussions/what-are-splunk-enterprise-components) - 1 comment
- [Which apps ship with Splunk Enterprise?](https://www.g2.com/discussions/which-apps-ship-with-splunk-enterprise) - 1 comment
- [What does Splunk Enterprise do?](https://www.g2.com/discussions/what-does-splunk-enterprise-do) - 1 comment

### [Cynet](https://www.g2.com/products/cynet/reviews)

Cynet is the unified, AI-powered cybersecurity platform that delivers robust and comprehensive protection for security teams while maximizing operational efficiency for managed service providers (MSPs). This platform consolidates a wide array of security capabilities into a single, user-friendly interface, ensuring that organizations can effectively safeguard their digital assets without the complexity often associated with multi-solution environments. Cynet’s platform simplifies security management by integrating various functionalities, such as endpoint protection, threat detection, and incident response, into one cohesive system. This integration not only streamlines operations but also allows organizations to allocate their resources more effectively, ultimately enhancing their overall security posture. One of the standout features of Cynet’s platform is its remarkable performance in the MITRE ATT&CK Evaluations. Cynet delivered 100% visibility and 100% analytic coverage without requiring any configuration changes three years in a row. This capability ensures that organizations can monitor their environments comprehensively and respond to threats with precision. The platform’s built-in analytics and reporting tools provide actionable insights, enabling users to make informed decisions about their cybersecurity strategies. Additionally, Cynet offers 24/7 expert support, which is crucial for organizations that may not have in-house cybersecurity expertise. This round-the-clock assistance ensures that users can quickly address any security incidents or concerns, minimizing potential downtime and damage. The combination of advanced technology and dedicated support positions Cynet as a valuable partner for SMEs and service providers looking to enhance their cybersecurity measures. In summary, Cynet’s unified, AI-powered cybersecurity platform stands out in the crowded cybersecurity market by offering a unified solution tailored to the needs of MSPs. Its comprehensive features, exceptional performance in industry evaluations, and continuous expert support make it a compelling choice for organizations seeking to bolster their cybersecurity defenses while maintaining operational efficiency.

**Average Rating:** 4.7/5.0

**Total Reviews:** 216

#### How Do G2 Users Rate Cynet?

- **Activity Monitoring:** 9.4/10 (Category avg: 9.1/10)
- **Data Examination:** 8.8/10 (Category avg: 8.6/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **Log Management:** 8.9/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Cynet?

- **Seller:** [Cynet](https://www.g2.com/sellers/cynet)
- **Company Website:** www.cynet.com
- **Year Founded:** 2014
- **HQ Location:** Boston, MA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5a5ebaacd6a1a812a193b2886c91aa7e64aeee7fb30bb25e658549d729d68178&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcynet-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
332 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** SOC Analyst, Technical Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 58% Medium, 31% Small

#### What Do G2 Reviewers Say About Cynet?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Cynet, appreciating its straightforward yet comprehensive functionalities for effective protection.
- Users value the **unified platform** of Cynet, which offers effective security through streamlined endpoint protection and detection.
- Users praise Cynet for its **effective threat detection** and seamless monitoring, enhancing overall cybersecurity effortlessly.
- Users commend Cynet for its **exceptional customer support** , ensuring a smooth and efficient deployment experience.
- Users praise Cynet for its **flawless threat monitoring and detection** , enhancing overall cybersecurity effectiveness effortlessly.

##### Cons

- Users find **limited customization** options in reporting and dashboards, affecting their ability to present necessary data.
- Users find **feature limitations** in Cynet, with a desire for more customization options and broader integrations.
- Users note a **lack of customization** in reports, wishing for more options to tailor data presentation.
- Users note **limited features** , such as basic reporting and few third-party integrations, impacting customization and deeper controls.
- Users note a **lack of essential features** like web filtering and security policies compared to other vendors.

#### What Are Recent G2 Reviews of Cynet?

**["Outstanding Product"](https://www.g2.com/survey_responses/cynet-review-9063334)**

**Rating:** 5.0/5.0 stars

_— David W._

[Read full review](https://www.g2.com/survey_responses/cynet-review-9063334)

**["One platform to manage centralized Endpoint Security"](https://www.g2.com/survey_responses/cynet-review-10264337)**

**Rating:** 4.5/5.0 stars

_— Guido I._

[Read full review](https://www.g2.com/survey_responses/cynet-review-10264337)

#### What Are G2 Users Discussing About Cynet?

- [What is Cynet 360 AutoXDR™ used for?](https://www.g2.com/discussions/what-is-cynet-360-autoxdr-used-for)
- [What is cynet XDR?](https://www.g2.com/discussions/what-is-cynet-xdr) - 1 comment
- [What is cynet used for?](https://www.g2.com/discussions/what-is-cynet-used-for) - 1 comment
- [Is cynet 360 good?](https://www.g2.com/discussions/is-cynet-360-good) - 3 comments
- [How much does cynet cost?](https://www.g2.com/discussions/how-much-does-cynet-cost) - 1 comment

### [Elastic Security](https://www.g2.com/products/elastic-elastic-security/reviews)

Modernize your SOC with AI Security is a data problem. Your team needs to detect, investigate, and respond to threats quickly. Elastic Security unifies next-gen SIEM and XDR with native automation, with AI built into every step. Built on Elasticsearch, the open-source search platform trusted by millions, Elastic provides complete visibility across your environment. Our data mesh architecture streamlines analysis to raise team productivity and reduce attacker dwell time. Bolster your defenses - Detect threats faster by analyzing data from across your attack surface - Stop attacks with the industry's best-rated XDR protection - Close the loop faster with Elastic Workflows, blending scripted automation with agentic AI reasoning - Get more accurate AI assistance, grounded in your data using Elasticsearch's leading relevance capabilities With Elastic Security, your SOC team can use generative AI to distill alerts, automate repetitive tasks, and get tailored guidance, all with your choice of LLM and full transparency into reasoning and sources. SOC leaders choose Elastic Security when they need a unified, open platform ready to run on any cloud, on-prem, or air-gapped.

**Average Rating:** 4.5/5.0

**Total Reviews:** 23

#### How Do G2 Users Rate Elastic Security?

- **Activity Monitoring:** 9.7/10 (Category avg: 9.1/10)
- **Data Examination:** 8.3/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.8/10 (Category avg: 8.7/10)
- **Log Management:** 9.8/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Elastic Security?

- **Seller:** [Elastic](https://www.g2.com/sellers/elastic)
- **Company Website:** www.elastic.co
- **Year Founded:** 2012
- **HQ Location:** San Francisco, CA
- **Twitter:** @elastic  
65,200 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=bc8e533876f16af617380aaa3922cb6a39a1d6233f0b32a0fa987a5fdffd799e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F814025%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,079 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 61% Medium, 52% Small

#### What Do G2 Reviewers Say About Elastic Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **flexible integrations** of Elastic Security, enhancing deep visibility and streamlining threat detection workflows.
- Users appreciate the **ease of use** in managing alerts and navigating workflows within Elastic Security.
- Users appreciate the **powerful detection capabilities** and **flexibility** of Elastic Security for effective threat management.
- Users appreciate the **easy integrations** with existing tools, enhancing the overall functionality of Elastic Security.
- Users value the **efficiency in investigations** provided by Elastic Security, enhancing their threat detection and response capabilities.

##### Cons

- Users struggle with the **steep learning curve and operational overhead** of Elastic Security, complicating effective usage and maintenance.
- Users find the **complex implementation** of Elastic Security challenging, requiring significant expertise and ongoing administrative effort.
- Users struggle with the **complexity** of Elastic Security, citing high administrative demands and a steep learning curve.
- Users struggle with the **complex setup** of Elastic Security, facing a steep learning curve and heavy administrative overhead.
- Users experience **integration issues** with Elastic Security, facing challenges in correlating log sources effectively.

#### What Are Recent G2 Reviews of Elastic Security?

**["Powerful, Customisable Security Platform for Complex Environments"](https://www.g2.com/survey_responses/elastic-security-review-12341245)**

**Rating:** 4.5/5.0 stars

_— Jennifer S._

[Read full review](https://www.g2.com/survey_responses/elastic-security-review-12341245)

**["Seamless SIEM Solution with AI and Outstanding Support"](https://www.g2.com/survey_responses/elastic-security-review-12438374)**

**Rating:** 5.0/5.0 stars

_— Jordan J._

[Read full review](https://www.g2.com/survey_responses/elastic-security-review-12438374)

### [Splunk Enterprise Security](https://www.g2.com/products/splunk-enterprise-security/reviews)

Splunk Enterprise Security (ES) is a data-centric, modern security information and event management (SIEM) solution that delivers data-driven insights for full breadth visibility into your security posture so you can protect your business and mitigate risk at scale. With unparalleled search and reporting, advanced analytics, integrated intelligence, and prepackaged security content, Splunk ES accelerates threat detection and investigation, letting you determine the scope of high-priority threats to your environment so you can quickly take action. Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Our extensive ecosystem of Splunk, partner, and community-built integrations as well as flexible deployment options ensure your technology investments are working in tandem with Splunk ES whilst meeting you wherever you are on your cloud, multi-cloud, or hybrid journey.

**Average Rating:** 4.3/5.0

**Total Reviews:** 224

#### How Do G2 Users Rate Splunk Enterprise Security?

- **Activity Monitoring:** 8.8/10 (Category avg: 9.1/10)
- **Data Examination:** 8.5/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **Log Management:** 9.3/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Splunk Enterprise Security?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 59% Large, 30% Medium

#### What Do G2 Reviewers Say About Splunk Enterprise Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **powerful log analytics** of Splunk Enterprise Security, enhancing their ability to analyze and correlate logs effectively.
- Users benefit from the **smart threat detection** of Splunk Enterprise Security, enabling early identification of security issues.
- Users value the **extensive integration options** of Splunk Enterprise Security, enhancing their existing Splunk investments and workflows.
- Users value the **versatility in data handling** of Splunk Enterprise Security, enhancing insights and decision-making across domains.
- Users appreciate the **real-time monitoring capabilities** of Splunk Enterprise Security, enhancing their cybersecurity responsiveness and decision-making.

##### Cons

- Users find the **complex setup** of Splunk Enterprise Security time-consuming and challenging, impacting initial deployment effectiveness.
- Users find the **difficult learning curve** of Splunk Enterprise Security challenging, especially for those new to data analysis.
- Users find the **high costs associated with data ingestion** to be a significant drawback of Splunk Enterprise Security.
- Users express concerns about **poor customer support** , highlighting the need for more responsive assistance and resources.
- Users often face **setup difficulties** with Splunk Enterprise Security, requiring significant time and resources for configuration.

#### What Are Recent G2 Reviews of Splunk Enterprise Security?

**["Powerful Threat Detection and Investigation with Splunk Enterprise Security"](https://www.g2.com/survey_responses/splunk-enterprise-security-review-12982814)**

**Rating:** 5.0/5.0 stars

_— Priyanshu S._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-security-review-12982814)

**["Simple, Easy-to-Use UI That Brings Everything Together in One Place"](https://www.g2.com/survey_responses/splunk-enterprise-security-review-13233919)**

**Rating:** 4.5/5.0 stars

_— Yashwant S._

[Read full review](https://www.g2.com/survey_responses/splunk-enterprise-security-review-13233919)

#### What Are G2 Users Discussing About Splunk Enterprise Security?

- [What is Splunk User Behavior Analytics used for?](https://www.g2.com/discussions/what-is-splunk-user-behavior-analytics-used-for)
- [What does Splunk Enterprise do?](https://www.g2.com/discussions/splunk-enterprise-security-what-does-splunk-enterprise-do)
- [What is the difference between Splunk Enterprise and Splunk Enterprise Security?](https://www.g2.com/discussions/what-is-the-difference-between-splunk-enterprise-and-splunk-enterprise-security) - 1 comment
- [Which Splunk app is used for enterprise security?](https://www.g2.com/discussions/which-splunk-app-is-used-for-enterprise-security)
- [What is Splunk Enterprise Security?](https://www.g2.com/discussions/what-is-splunk-enterprise-security)

### [Datadog](https://www.g2.com/products/datadog/reviews)

Datadog is the monitoring, security and analytics platform for developers, IT operations teams, security engineers and business users in the cloud age. The SaaS platform integrates and automates infrastructure monitoring, application performance monitoring and log management to provide unified, real-time observability of our customers' entire technology stack. Datadog is used by organizations of all sizes and across a wide range of industries to enable digital transformation and cloud migration, drive collaboration among development, operations, security and business teams, accelerate time to market for applications, reduce time to problem resolution, secure applications and infrastructure, understand user behavior and track key business metrics.

**Average Rating:** 4.4/5.0

**Total Reviews:** 715

#### How Do G2 Users Rate Datadog?

- **Activity Monitoring:** 8.9/10 (Category avg: 9.1/10)
- **Data Examination:** 8.6/10 (Category avg: 8.6/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **Log Management:** 9.5/10 (Category avg: 9.1/10)

#### Who Is the Company Behind Datadog?

- **Seller:** [Datadog](https://www.g2.com/sellers/datadog)
- **Company Website:** www.datadoghq.com
- **Year Founded:** 2010
- **HQ Location:** New York
- **Twitter:** @datadoghq  
51,207 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1b0942496e12618acadaab3a1601417c9f0d1941be094e2cefb0d89c606e73b5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1066442%2F&secure%5Burl_type%5D=linkedin_company_website)  
9,386 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 47% Medium, 34% Large

#### What Do G2 Reviewers Say About Datadog?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Datadog, enjoying intuitive dashboard creation and straightforward implementation.
- Users appreciate the **intuitive monitoring features** of Datadog, enabling easy integration and insightful data analysis.
- Users value the **real-time monitoring capabilities** of Datadog, enhancing oversight across various applications and infrastructures.
- Users appreciate the **user-friendly interface** and **robust integration capabilities** of Datadog for effective monitoring.
- Users value the **intuitive dashboard creation** in Datadog, which enhances monitoring and analysis efficiency.

##### Cons

- Users find Datadog's pricing to be **expensive** , suggesting it should be more affordable given its features.
- Users find **pricing issues** with Datadog, citing rapidly escalating costs and high subscription fees as concerns.
- Users find the **steep learning curve** challenging, especially with rapidly evolving features and required knowledge.
- Users find the **costs to be unpredictable and excessively high** , especially with data storage and additional features.
- Users find **learning difficulty** in Datadog, noting that new users may require training to understand its complexities.

#### What Are Recent G2 Reviews of Datadog?

**["Datadog: Unified Logs, Metrics & Traces for Real-Time Visibility and Faster Debugging"](https://www.g2.com/survey_responses/datadog-review-13049319)**

**Rating:** 4.5/5.0 stars

_— Anshul S._

[Read full review](https://www.g2.com/survey_responses/datadog-review-13049319)

**["Faster incident detection and root-cause analysis, leading to better customer experience."](https://www.g2.com/survey_responses/datadog-review-12850013)**

**Rating:** 4.5/5.0 stars

_— Bertrand P._

[Read full review](https://www.g2.com/survey_responses/datadog-review-12850013)

#### What Are G2 Users Discussing About Datadog?

- [How good is Datadog?](https://www.g2.com/discussions/how-good-is-datadog)
- [Does Datadog use AWS?](https://www.g2.com/discussions/does-datadog-use-aws) - 2 comments
- [What can Datadog monitor?](https://www.g2.com/discussions/what-can-datadog-monitor)
- [What is the use of Datadog?](https://www.g2.com/discussions/what-is-the-use-of-datadog) - 3 comments

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/security-information-and-event-management-siem?order=g2_score&page=2#product-list)
- [3](/categories/security-information-and-event-management-siem?order=g2_score&page=3#product-list)
- [4](/categories/security-information-and-event-management-siem?order=g2_score&page=4#product-list)
- [5](/categories/security-information-and-event-management-siem?order=g2_score&page=5#product-list)
- …
- [9](/categories/security-information-and-event-management-siem?order=g2_score&page=9#product-list)
- [10](/categories/security-information-and-event-management-siem?order=g2_score&page=10#product-list)
- [Next &rsaquo; Next ›](/categories/security-information-and-event-management-siem?order=g2_score&page=2#product-list)

Spotlight Categories

[Security Compliance Software](https://www.g2.com/categories/security-compliance)

[Electronic Data Interchange (EDI) Software](https://www.g2.com/categories/electronic-data-interchange-edi)

[Social Media Management Tools](https://www.g2.com/categories/social-media-mgmt)

[Travel Management Solutions](https://www.g2.com/categories/travel-management)

[Video Editing Software](https://www.g2.com/categories/video-editing)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)
- [Deception Technology](/categories/deception-technology)

- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)
- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)

- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)
- [Security Orchestration, Automation, and Response (SOAR)](/categories/security-orchestration-automation-and-response-soar)

[Browse Security Information and Event Management (SIEM) Themes](/categories/security-information-and-event-management-siem/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 31, 2024

Security information and event management (SIEM) software combines a variety of security software components into one platform. Companies use SIEM solutions to centralize security operations into a single location. IT and security operations teams can gain access to the same information and alerts for more effective communication and planning. These products provide capabilities to identify and alert IT operations teams of anomalies detected in their systems. The anomalies may be new malware, unapproved access, or newly discovered vulnerabilities. SIEM tools provide live analysis of functionality and security, storing logs and records for retrospective reporting. They also have products for identity and access management to ensure only approved parties have access to sensitive systems. Forensic analysis tools help teams navigate historical logs, identify trends, and better fortify their networks.

SIEM systems may be confused with [incident response](https://www.g2.com/categories/incident-response) software, but SIEM products provide a larger scope of security and IT management features. Most also do not have the ability to automate security remediation practices.

To qualify for inclusion in the SIEM category, a product must:

- Aggregate and store IT security data
- Assist in user provisioning and governance 
- Identify vulnerabilities in systems and endpoints
- Monitor for anomalies within an IT system

Top Tools at a Glance

| Product | Best for | User Review |
| --- | --- | --- |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_56db399f44b6fabb7c667f09bc770579/crowdstrike-falcon-endpoint-protection-platform.png "Product Avatar Image")](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)[CrowdStrike Falcon Endpoint...](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)[4.6/5(444)](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) | Behavioral threat detection with real-time endpoint response | "Crowdstrike Falcon: Proactive Security, Steep Learning Curve" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_bf8095de95175316574d734b1f2b2c48/sumo-logic.png "Product Avatar Image")](https://www.g2.com/products/sumo-logic/reviews)[Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)[4.3/5(406)](https://www.g2.com/products/sumo-logic/reviews) | Cloud-native SIEM with unified observability | "Secure, Privacy-First AI Logging That Helps Reduce Data Breach Risk" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_f7c81a73a5adf5f83fb61d5a8f5f6a15/todyl-security-platform.png "Product Avatar Image")](https://www.g2.com/products/todyl-security-platform/reviews)[Todyl Security Platform](https://www.g2.com/products/todyl-security-platform/reviews)[4.7/5(106)](https://www.g2.com/products/todyl-security-platform/reviews) | Unified SIEM with embedded MXDR for MSPs | "Valuable Visibility with Room for Improvement" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_4e2b08dd17397bdc99a5658447cbc589/microsoft-sentinel.jpg "Product Avatar Image")](https://www.g2.com/products/microsoft-sentinel/reviews)[Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)[4.4/5(298)](https://www.g2.com/products/microsoft-sentinel/reviews) | Cloud-native SIEM with Microsoft ecosystem integration | "Best Cloud native SIEM - Microsoft Sentinel" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8dedb235969bcb553f9e412b16e93d0a/check-point-infinity-platform.png "Product Avatar Image")](https://www.g2.com/products/check-point-infinity-platform/reviews)[Check Point Infinity Platform](https://www.g2.com/products/check-point-infinity-platform/reviews)[4.6/5(117)](https://www.g2.com/products/check-point-infinity-platform/reviews) | Unified threat prevention across hybrid security infrastructure | "Excellent option Harmony Platform for security central" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_16dfa8129f7c019c451bdcef5de2a937/panther%282%29.jpg "Product Avatar Image")](https://www.g2.com/products/panther/reviews)[Panther](https://www.g2.com/products/panther/reviews)[4.7/5(49)](https://www.g2.com/products/panther/reviews) | Detection-as-code SIEM with Python-based alerting | "Panther’s SIEM + AI Makes Triage and Threat Hunting Fast and Seamless" |

* * *

Show More

### Security Information and Event Management (SIEM) Topics

- [What is security information and event management (SIEM) software?](#what-is-security-information-and-event-management-siem-software)
- [Types of SIEM solutions](#types-of-siem-solutions)
- [What are the common features of SIEM systems?](#what-are-the-common-features-of-siem-systems)
- [What are the benefits of using SIEM products?](#what-are-the-benefits-of-using-siem-products)
- [Software related to SIEM tools](#software-related-to-siem-tools)
- [Challenges with SIEM software](#challenges-with-siem-software)
- [Which companies should buy SIEM solutions?](#which-companies-should-buy-siem-solutions)
- [How to choose the best SIEM software](#how-to-choose-the-best-siem-software)
- [How much does SIEM software cost?](#how-much-does-siem-software-cost)

[
### Security Information and Event Management (SIEM) Topics
 Expand/Collapse ](#)
- [What is security information and event management (SIEM) software?](#what-is-security-information-and-event-management-siem-software)
- [Types of SIEM solutions](#types-of-siem-solutions)
- [What are the common features of SIEM systems?](#what-are-the-common-features-of-siem-systems)
- [What are the benefits of using SIEM products?](#what-are-the-benefits-of-using-siem-products)
- [Software related to SIEM tools](#software-related-to-siem-tools)
- [Challenges with SIEM software](#challenges-with-siem-software)
- [Which companies should buy SIEM solutions?](#which-companies-should-buy-siem-solutions)
- [How to choose the best SIEM software](#how-to-choose-the-best-siem-software)
- [How much does SIEM software cost?](#how-much-does-siem-software-cost)

## Learn More About Security Information and Event Management (SIEM) Software

### What is security information and event management (SIEM) software?
 

Security Information and Event Management (SIEM) is a centralized system for threat detection that aggregates security alerts from multiple sources, simplifying threat response and compliance reporting. SIEM software is one of the most commonly used tools for security administrators and security incident response professionals. They provide a single platform capable of facilitating event and threat protection, log analysis and investigation, and threat remediation. Some cutting-edge tools provide additional functionality for creating response workflows, data normalization, and advanced threat protection.

 

SIEM platforms help security programs operate by collecting security data for future analysis, storing these data points, correlating them to security events, and facilitating analysis of those events.

 

Security teams can define rules for typical and suspicious activities with SIEM tools. Advanced Next-Gen SIEM solutions leverage [machine learning](https://www.g2.com/articles/what-is-machine-learning) and [AI](https://www.g2.com/articles/what-is-artificial-intelligence) to refine behavior models continuously, enhancing [User and Entity Behavior Analytics (UEBA)](https://www.g2.com/categories/user-and-entity-behavior-analytics-ueba) and reducing false positives. These systems analyze data against set rules and behavioral patterns, flagging notable events when anomalies are detected.

 

Companies using SIEM solutions deploy sensors across digital assets to automate data collection. Sensors relay information back to the SIEM’s log and event database. When additional security incidents arise, the SIEM platform detects anomalies. It correlates similar logs to provide context and threat information for security teams as they attempt to remediate any existing threats or vulnerabilities.

 
#### **What does SIEM stand for?**
 

SIEM stands for security information and event management (SIEM), which is a combination of two different acronyms for security technology: security information monitoring (SIM) and security event management (SEM).

 

SIM is the practice of collecting, aggregating, and analyzing security data, typically in the form of logs. SIM tools automate this process and document security information for other sources, such as [intrusion detection systems](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps), [firewalls](https://www.g2.com/categories/firewall-software), or [routers](https://www.g2.com/categories/routers). Event logs and their associated informational components are recorded and stored for long periods for either retrospective analysis or compliance requirements.

 

SEM is a family of security software for discovering, analyzing, visualizing, and responding to threats as they arise. SEM is a core component of a security operations system. While SIM tools are designed for log collection and storage, SEM tools typically rely on SQL databases to store specific logs and other event data as they are generated in real time by security devices and IT systems. They usually also provide the functionality to correlate and analyze event data, monitor systems in real time, and alert security teams of abnormal activity.

 

SIEM combines the functionality of SIM and SEM to centralize control over log storage, event management, and real-time analysis. SIM and SEM have become defunct technologies, as SIEM’s rise has provided dual-purpose functionality. SIEM vendors offer a single tool capable of performing data aggregation, information correlation, and event management.

 

### Types of SIEM solutions
 
#### **Traditional SIEM**
 

Traditional SIEM tools are deployed on-premises with sensors placed on IT assets to analyze events and collect system logs. The data is used to develop baseline references and identify indicators of compromise. The SIEM product alerts security teams for intervention when a system becomes compromised.&nbsp;

 
#### **Cloud or virtual SIEM**
 

Cloud-based and virtualized SIEM software are tools typically used to secure cloud infrastructure and services a cloud provider delivers. These tools are often less expensive than on-premises solutions and more accessible to implement, as no physical labor is required. They are ideal for companies without local IT infrastructure.

 
#### [**Managed SIEM services**](https://www.g2.com/categories/managed-siem-services)
 

Companies that do not have a full-fledged security program may choose managed SIEM services to aid in management and reduce work for internal employees. These SIEM services are delivered by managed service providers who provide the customer data and dashboards with security information and activity, but the provider handles implementation and remediation.&nbsp;

 

### What are the common features of SIEM systems?
 

The following are some core features within SIEM software that can help users collect security data, analyze logs, and detect threats:

 

**Activity monitoring:** SIEM systems document the actions from endpoints within a network. The system alerts users of incidents and abnormal activities and documents the access point. Real-time tracking will document these for analysis as an event takes place.

 

**Asset management:** These SIEM features keep records of each network asset and its activity. The feature may also refer to the discovery of new assets accessing the network.

 

**Log management:** This functionality documents and stores event logs in a secure repository for reference, analysis, or compliance reasons.

 

**Event management:** As events occur in real time, the SIEM software alerts users of incidents. This allows security teams to intervene manually or trigger an automated response to resolve the issue.

 

[**Automated response**](https://www.g2.com/categories/security-information-and-event-management-siem/f/automated-response) **:** Response automation reduces the time spent diagnosing and resolving issues manually. The features are typically capable of quickly resolving common network security incidents.

 

**Incident reporting:** Incident reports document cases of abnormal activity and compromised systems. These can be used for forensic analysis or as a reference point for future incidents.

 

**Threat intelligence:** Threat intelligence feeds integrate information to train SIEM systems to detect emerging and existing threats. These threat feeds store information related to potential threats and vulnerabilities to ensure issues are discovered and teams are provided with the information necessary to resolve the problems as they occur.

 

[**Vulnerability assessment**](https://www.g2.com/categories/security-information-and-event-management-siem/f/vulnerability-assessment) **:** Vulnerability assessment tools may scan networks for potential vulnerabilities or audit data to discover non-compliant practices. Mainly, they’re used to analyze an existing network and IT infrastructure to outline access points that can be easily compromised.

 

[**Advanced analytics**](https://www.g2.com/categories/security-information-and-event-management-siem/f/advanced-analytics) **:** Advanced analytics features allow users to customize analysis with granular or individually specific metrics pertinent to the business’ resources.

 

[**Data examination**](https://www.g2.com/categories/security-information-and-event-management-siem/f/data-examination) **:** Data examination features typically facilitate the forensic analysis of incident data and event logs. These features allow users to search databases and incident logs to gain insights into vulnerabilities and incidents.

 

### What are the benefits of using SIEM products?

Below are a few of the main reasons SIEM software is commonly used to protect businesses of all sizes:

**Data aggregation and correlation:** SIEM systems and companies collect vast amounts of information from an entire network environment. This information is gathered from virtually anything interacting with a network, from endpoints and servers to firewalls and antivirus tools. It is either given directly to the SIEM or using agents (decision-making programs designed to identify irregular information). The platform is set up to deploy agents and collect and store similar information together according to security policies set in place by administrators.

**Incident alerting:** As information comes in from a network’s various connected components, the SIEM system correlates it using rule-based policies. These policies inform agents of normal behavior and threats. If any action violates these policies or malware or intrusion is discovered. At the same time, the SIEM platform monitors network activity; it is labeled as suspicious, security controls restrict access, and administrators are alerted.

**Security analysis:** Retrospective analysis may be performed by searching log data during specific periods or based on specific criteria. Security teams may suspect a certain misconfiguration or kind of malware caused an event. They may also suspect an unapproved party went undetected at a specific time. Teams will analyze the logs and look for specific characteristics in the data to determine whether their suspicion was right. They may also discover vulnerabilities or misconfigurations that leave them susceptible to attack and remediate them.

### Software related to SIEM tools

Many network and system security solutions involve collecting and analyzing event logs and security information. SIEM systems are typically the most all-encompassing solutions available, but many other security solutions may integrate with them for added functionality or complementary use. These are a few different technology categories related to SIEM software.

[Threat intelligence software](https://www.g2.com/categories/threat-intelligence) **:** Threat intelligence software is an informational service that provides SIEM tools and other information security systems with up-to-date information on web-based threats. They can inform the system of zero-day threats, new forms of malware, potential exploits, and different kinds of vulnerabilities.

[Incident response software](https://www.g2.com/categories/incident-response) **:** SIEM systems may facilitate incident response, but these tools are specifically designed to streamline the remediation process or add investigative capabilities during security workflow processes. Incident response solutions will not provide the same compliance maintenance or log storage capabilities. Still, they can be used to increase a team’s ability to tackle threats as they emerge.

[Network security policy management (NSPM) software](https://www.g2.com/categories/network-security-policy-management-nspm) **:** NSPM software has some overlapping functionality to ensure security hardware and IT systems are correctly configured but cannot detect and resolve threats. They are typically used to ensure devices like firewalls or DNS filters are functioning correctly and in alignment with the security rules put in place by security teams.

[Intrusion detection and prevention systems (IDPS)](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps) **:** While SIEM systems specialize in log management, alerting, and correlation, IDPS provide additional detection and protection features to prevent unapproved parties from accessing sensitive systems and network breaches. However, they will not facilitate the analysis and forensic investigation of logs with the same level of detail as an SIEM system.

[Managed security services providers](https://www.g2.com/categories/managed-security-services) **:** Various managed security services are available for businesses without the resources or staff necessary to operate a full-fledged security administration and operations team. Managed services are a viable option and will provide companies with skilled staff to protect their customers’ systems and keep their sensitive information protected.

### Challenges with SIEM software

**Staffing:** There is an existing shortage of skilled security professionals. Managing SIEM products and maintaining a well-rounded security posture requires dedicated personnel with highly specialized skills. Some smaller or growing companies may not have the means to recruit, hire, and retain qualified security pros. In such cases, businesses can consider managed services to outsource the labor.&nbsp;

**Compliance:** Some industries have specific compliance requirements determined by various governing bodies, but SIEM software can be used across several industries to maintain compliance standards. Many industry-specific compliance requirements exist, but most require security teams to protect sensitive data, restrict access to unapproved parties, and monitor changes made to identities, information, or privileges. For example, SIEM systems can maintain GDPR compliance by verifying security controls and data access, facilitating long-term storage of log data, and notifying security staff of security incidents, as GDPR requires.

### Which companies should buy SIEM solutions?

**Vertical industries:** Vertical industries, such as healthcare and financial services, often have additional compliance requirements related to data protection and privacy. SIEM is an ideal solution for outlining requirements, mapping threats, and remediating vulnerabilities.&nbsp;

**SaaS business:** SaaS businesses utilizing resources from a cloud service provider are still responsible for a significant portion of the security efforts required to protect a cloud-native business. These companies may jump for cloud-native SIEM tools but will benefit from any SIEM to prevent, detect, and respond to threats.&nbsp;

### How to choose the best SIEM software

#### Requirements Gathering (RFI/RFP) for Security Information and Event Management (SIEM) Software

The first step to purchasing a SIEM solution is to outline the options. Companies should be sure whether they need a cloud-based or on-premises solution. They should also outline the number of interconnected devices they need and whether they want physical or virtual sensors to secure them. Additional and possibly obvious requirements should include budgetary considerations, staffing limitations, and required integrations_.&nbsp;_

#### **Compare Security Information and Event Management (SIEM) Software Products**

##### **Create a long list**

Once the requirements are outlined, buyers should prioritize the tools and identify the ones with as many features as possible that fit the budget window. It is recommended to restrict the list to products with desired features, pricing, and deployment methods to identify a dozen or so options. For example, if the business needs a cloud-native SIEM for less than $10k a year, half of the SIEM options will be eliminated.&nbsp;

When choosing a SIEM provider, focus on the vendor’s experience, reputation, and specific functionality relevant to your security needs. Core capabilities ensure essential threat detection, while next-gen features add advanced intelligence and automation, allowing for a more proactive security posture. Here’s a breakdown to guide your selection:

**Core SIEM capabilities**

- Threat detection: Look for SIEMs with robust threat detection, which uses rules and behavioral analytics, along with threat feed integration, to accurately identify potential threats.
- Threat intelligence and security alerting: Leading SIEMs incorporate threat intelligence feeds, aggregate security data, and alert you when suspicious activities are detected, ensuring real-time updates on evolving threats.
- Compliance reporting: Compliance support is crucial, especially for meeting standards like HIPAA, PCI, and FFIEC. SIEMs streamline compliance assessment and reporting, helping prevent costly non-compliance.
- Real-time notifications: Swift alerts are vital; SIEMs that notify you of breaches immediately enable faster responses to potential threats.
- Data aggregation: A centralized view of all network activities ensures no area is left unmonitored, which is crucial for comprehensive threat visibility as your organization scales.
- Data normalization: SIEMs that normalize incoming data make it easier to analyze security events and extract actionable insights from disparate sources.

**Next-gen SIEM capabilities**

- Data collection and management: Next-gen SIEMs pull data from the cloud, on-premises, and external devices, consolidating insights across the entire IT environment.
- Cloud delivery: Cloud-based SIEMs use scalable storage, accommodating large data volumes without the limitations of on-premises hardware.
- User and entity behavior analytics (UEBA): By establishing normal user behavior and identifying deviations, UEBA helps detect insider threats and new, unknown threats.
- Security orchestration and automation response (SOAR): SOAR automates incident response, integrates with IT infrastructure, and enables coordinated responses across firewalls, email servers, and access controls.
- Automated attack timelines: Next-gen SIEMs automatically create visual attack timelines, simplifying investigation and triage, even for less experienced analysts.

Selecting an SIEM vendor with both core and next-gen capabilities offers your organization a comprehensive and agile approach to security, meeting both current and future requirements.

##### **Create a short list**

Narrowing down a short list can be tricky, especially for the indecisive, but these decisions must be made. Once the long list is limited to affordable products with the desired features, it’s time to search for third-party validation. For each tool, the buyer must analyze end-user reviews, analyst reports, and empirical security evaluations. Combining these specified factors should help rank options and eliminate poorly performing products. _&nbsp;_

##### **Conduct demos**

With the list narrowed down to three to five possible products, businesses can contact vendors and schedule demos. This will help them get first-hand experience with the product, ask targeted questions, and gauge the vendors' quality of service.&nbsp;

Here are some essential questions to guide your decision:

- Will the tool enhance log collection and management?: 

Effective log collection is foundational. Look for compatible software across systems and devices, offering a user-friendly dashboard for streamlined monitoring.

- Does the tool support compliance efforts?

Even if compliance isn't a priority, choosing an SIEM that facilitates auditing and reporting can future-proof your operations. Look for tools that simplify compliance processes and reporting.

- Can the tool leverage past security events in threat response?

One of SIEM’s strengths is using historical data to inform future threat detection. Ensure the tool offers in-depth analytics and drill-down capabilities to analyze and act on past incidents.

- Is the incident response fast and automated?

Timely, effective responses are critical. The tool should provide customizable alerts that notify your team immediately when needed so you can confidently leave the dashboard.&nbsp;

#### Selection of Security Information and Event Management (SIEM) Software

##### **Choose a selection team**

Decision-makers need to involve subject matter experts from all teams that will use the system in choosing a selection team. For backup software, this primarily involves product managers, developers, IT, and security staff. Any manager or department-level leader should also include individuals managing any solution the backup product will be integrating with.&nbsp;

##### **Negotiation**

The seniority of the negotiation team may vary depending on the maturity of the business. It is advisable to include relevant directors or managers from the security and IT departments as well as from any other cross-functional departments that may be impacted.

##### **Final decision**

If the company has a chief information security officer (CISO), that individual will likely decide.&nbsp;If not, companies must trust their security professionals’ ability to use and understand the product.&nbsp;

### How much does SIEM software cost?

Potential growth should be considered if the buyer chooses a cloud-based SIEM tool that offers pricing on the SaaS pay-as-you-use model. Some solutions are inexpensive at the start and offer affordable, low-tier pricing. Alternatively, some may rapidly increase pricing and fees as the company and storage need to scale. Some vendors provide permanently free backup products for individuals or small teams.

**Cloud SIEM_:_** SIEM as a service pricing may vary, but it traditionally scales as storage increases. Additional costs may come from increased features such as automated remediation, security orchestration, and integrated threat intelligence.&nbsp;

**On-premises SIEM:** On-premises solutions are typically more expensive and require more effort and resources. They will also be more costly to maintain and require dedicated staff. Still, companies with high compliance requirements should adopt on-premises security regardless.&nbsp;

#### Return on Investment (ROI)

Cloud-based SIEM solutions will provide a quicker ROI, similar to their lower average cost. The situation is pretty cut and dry since there is much lower initial investment and lower demand for dedicated staffing.&nbsp;

However, for on-premises systems, the ROI will depend on the scale and scope of business IT systems. Hundreds of servers will require hundreds of sensors, potentially more, as time wears on computing equipment. Once implemented, they must be operated and maintained by (expensive) security professionals.