
Correlates logs across our multi-tenant environment really well, especially with custom analytics rules. Integration with Log Analytics and the automation rules (like auto-ticket creation) saves a lot of manual triage time. Threat hunting queries in KQL are powerful once you get the hang of them, way more flexible than our old SIEM. Liked the overall UI-UX. performance compared to other SIEM tools and and they now also provide inbuilt AI agent integration work even more faster and smarter. Review collected by and hosted on G2.com.
Cost can spiral fast once log ingestion volume goes up, especially with verbose data connectors like firewall logs.
Some out-of-the-box analytics rules generate noisy alerts, needed a lot of tuning before they were actually useful. Review collected by and hosted on G2.com.