Try our new research platform with insights from 80,000+ expert users

Cribl vs Elastic Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 24, 2024
 

Categories and Ranking

Cribl
Ranking in Log Management
19th
Average Rating
8.2
Reviews Sentiment
8.0
Number of Reviews
9
Ranking in other categories
Application Performance Monitoring (APM) and Observability (24th), Data Integration (26th), Cloud Data Integration (15th), Data Preparation Tools (4th)
Elastic Security
Ranking in Log Management
5th
Average Rating
7.6
Number of Reviews
61
Ranking in other categories
Security Information and Event Management (SIEM) (5th), Endpoint Detection and Response (EDR) (16th), Security Orchestration Automation and Response (SOAR) (6th), Extended Detection and Response (XDR) (8th)
 

Mindshare comparison

As of November 2024, in the Log Management category, the mindshare of Cribl is 0.8%, up from 0.1% compared to the previous year. The mindshare of Elastic Security is 5.0%, down from 8.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Hariram G - PeerSpot reviewer
Aug 27, 2024
Collects logs from various cloud sources with reduced costs and improved efficiency
Cribl has simplified many aspects of the onboarding process, but there's still room for improvement. Currently, no other tools in the market truly compete with Cribl in its niche. Splunk is trying to retain customers by developing ingest actions to reduce licensing costs, hoping to prevent them from switching to Cribl. There is no alerting mechanism for the leader/worker nodes status. Since Cribl plays a major role in the mid-layer between the source and destination, there's a slight risk of losing data at some points while receiving real time data. It would be helpful if Cribl could temporarily store or index the data for a specific time range. This would prevent data loss during downtime. Additionally, there's room for improvement in how Cribl handles historical data. Currently, I can't view trends beyond a week, and even then, it’s often limited to just 24 hours. Since Cribl doesn’t index the data but only forwards it, extending the period for viewing statistics and monitoring trends would be a valuable enhancement.
Gajewski Marek - PeerSpot reviewer
Aug 13, 2024
Provides good anomaly detection and connectivity reporting
I use Elastic Security to aggregate all logs from different devices in one place. It works pretty well and provides one overview of everything The solution's most valuable features are anomaly detection and connectivity reporting. Elastic Security also has many automation capabilities, which can…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product's most valuable features include the internal management of events, coding perspective, data processing, and serialization."
"The capability to reduce logs in a user-friendly manner is a standout feature. Cribl allows us to view logs live as they are being processed, giving us quick feedback on the changes made."
"Cribl offers easy plugin configurations and source collection settings, allowing us to collect logs from any source."
"The platform's most valuable feature is the ability to transform data in real-time within the pipeline without sending it to a destination."
"Cribl offers other valuable features. For instance, you can replay data from an edge device, store your daily data in a stream, and replay specific event data into Splunk if a security incident occurs"
"Features such as Cribl Stream, Cribl LogStream, and Cribl Edge have been the most beneficial. The Cribl LogStream, in particular, is valuable for routing data, creating firewalls on pipelines, and putting security measures in place to ensure data reaches its destination without issues."
"When it comes to the product's installation phase, it is not tough for people who have good knowledge...The tool is worth the investment."
"The support team was very helpful and managed to get everything production-ready."
"Elastic Security makes data communication easier."
"It is very quick to react. I can set it to check anomalies or suspicious behavior every 30 seconds. It is very fast."
"Enables monitoring of application performance and the ability to predict behaviors."
"It's a good platform and the very best in the current market. We looked at the Forester report from December 2022 where it was said to be a leader."
"The solution has a good community surrounding it for lots of helpful documentation for troubleshooting purposes."
"We chose the product based on the ability to scan for malware using a malware behavioral model as opposed to just a traditional hash-based antivirus. Therefore, it's not as intensive."
"The intelligence of the system has been very impressive. It's not quite AI, but the technical bit where it correlates information, based on the seen attacks within an organization is good."
"The most valuable feature is the scalability. We are in Indonesia, more engineers understand Elastic Security here. So it is easier to scale and also develop. In features, the discovery to query all the logs is very important to us. It is very easy, especially with the query function and the feature to generate alerts and create tools. Sometimes we use the alert security dashboard to monitor our clients."
 

Cons

"There is room for improvement in the documentation and knowledge base, particularly regarding configurations like sources where logs are being ingested"
"There is no alerting mechanism for the leader/worker nodes status."
"Cribl could improve by offering easier integrations with enterprise products, similar to what Splunk provides."
"Cribl doesn't have as many packs available"
"Cribl could have developed some version that can give backward compatibility."
"The sys logging could be enhanced to make it easier to identify errors, especially when dealing with multiple functions."
"Cribl should consider adding more features that are applicable to smaller firms, allowing broader access to their data migration through Cribl."
"There have been several administrative issues. Another point is that the browsing functions aren't very intuitive."
"The interface could be more user friendly because it is sometimes hard to deal with."
"It is difficult to anticipate and understand the space utilization, so more clarity there would be great."
"Email notification should be done the same way as Logentries does it."
"It's a little bit of a learning curve to understand the logic of searching for things and trying to find what you're looking for in Elastic Security."
"The tool needs to integrate with legacy servers. Big companies can have legacy servers that may not always be updated."
"The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming."
"There are connectors to gather logs for Windows PCs and Linux PCs, but if we have to get the logs from Syslog then we have to do it manually, and this should be automated."
"Elastic Security has a steep learning curve, so it takes some time to tune it and set it up for your environment. There are some costs associated with logging things that don't have value. So you need to be cautious to only log things that make sense and keep them around for as long as you need. You shouldn't hold onto things just because you think you might need them."
 

Pricing and Cost Advice

"The product pricing is reasonable compared to other solutions."
"I would not say it is a cheaply priced tool as it has been doing wonders in the market. The tool has been budget-friendly for organizations."
"Elastic Stack is an open-source tool. You don't have to pay anything for the components."
"The tool's pricing is flexible and comes at unit cost. You don't have to pay for everything."
"The licensing cost of Elastic Security is based on the daily ingestion rate. I can't recall the exact figure, but for 10GB of log action daily, it would cost around $20,000."
"The product offers an amazing pricing structure. Price-wise, the product is very competitive."
"We use the open-source version, so there is no charge for this solution."
"When compared to other products, the price is average or on the low side."
"The price is reasonable. It probably costs the same as ArcSight and LogRhythm SIEM. FortiSIEM might cost less than Elastic Security. There are no hidden or additional costs."
"I can say that the product is cheaply priced."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
814,528 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
12%
Healthcare Company
9%
Government
9%
Computer Software Company
17%
Financial Services Firm
10%
Government
10%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Cribl?
I would not say it is a cheaply priced tool as it has been doing wonders in the market. The tool has been budget-friendly for organizations. It would be good if people get into that data analytics ...
What needs improvement with Cribl?
The documentation part could be better. Their documentation could be updated, as new features often outdated existing information. Additionally, there are inconsistencies between the documentation ...
What is your primary use case for Cribl?
We use Cribl for data normalization, which involves standardizing data from various sources before sending it to a SIEM. This helps reduce costs associated with SIEM ingestion. Additionally, we use...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it contains critical information. The reverse index allows fast data indexing because ...
What is your experience regarding pricing and costs for Elastic Security?
Compared to other tools, Elastic Security is a cheaper solution.
 

Comparisons

 

Also Known As

No data available
Elastic SIEM, ELK Logstash
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Find out what your peers are saying about Cribl vs. Elastic Security and other solutions. Updated: October 2024.
814,528 professionals have used our research since 2012.