This reviewer's identity has been verified by our review moderation team. They have asked not to show their name, job title, or picture.
Scanner is one of those products that makes you wonder why everyone else made this so complicated. Logs stay in your S3 buckets, Scanner indexes them and makes them searchable. No shipping data to a vendor's environment, no surprise ingestion bills, no waiting forever for a query to come back. The search speed is genuinely impressive and the full text search across schema-less data is a huge deal because in the real world your logs are messy and you don't always know what field you're looking for. Detection rules as code through GitHub is exactly how detection engineering should work in 2026 and that workflow alone puts it ahead of platforms where you're clicking through a UI to build rules one at a time. Review collected by and hosted on G2.com.
The biggest gap right now is that Scanner only supports AWS for its underlying infrastructure. If your organization runs on Google Cloud or Azure you're out of luck for the time being. They've indicated multi-cloud support is on the roadmap but as of today it's an AWS-only play. That's not a dealbreaker if you're already in AWS but it does limit who can realistically adopt it. Review collected by and hosted on G2.com.
The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.
Validated through Google using a business email account
Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.




