Try our new research platform with insights from 80,000+ expert users

Cribl vs Securonix Next-Gen SIEM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
Cribl enhanced data management efficiency, delivering cost savings, improved processing speed, system performance, and operational flexibility for users.
Sentiment score
5.2
Users saw enhanced security and efficiency with Securonix Next-Gen SIEM, experiencing quick implementation and notable returns on investment.
The solution is time-saving, particularly in the long run after it is deployed, enabling us to get value promptly.
 

Customer Service

Sentiment score
6.8
Cribl customer service is praised for prompt responses, effective support, and community assistance, with a high satisfaction rating.
Sentiment score
7.3
Securonix Next-Gen SIEM offers responsive, knowledgeable support, though occasional delays and escalations may occur in urgent situations.
The community, including the engineering and sales teams, is available on Slack and is very supportive.
If I raise a ticket, it initially goes to the L1 team, but the next level of escalation is really effective.
There is no UK-based support, which leads to delays in waiting for US support.
 

Scalability Issues

Sentiment score
7.9
Cribl is scalable and easily integrates with CI/CD pipelines, receiving praise for efficient deployment and seamless cloud management.
Sentiment score
7.9
Securonix Next-Gen SIEM offers scalable cloud-based architecture, seamless data integration, and efficient management for large organizations with multiple log sources.
The solution is scalable as it is cloud-based and cloud-native.
 

Stability Issues

Sentiment score
7.3
Cribl is generally rated 7-8 for stability, with minor bugs quickly addressed and continuous development enhancing reliability.
Sentiment score
8.0
Securonix Next-Gen SIEM is stable and reliable, with high ratings despite minor integration issues and occasional slowness.
 

Room For Improvement

Cribl needs better legacy compatibility, intuitive logging, enhanced documentation, improved onboarding, and desktop server functionality for developers.
Securonix Next-Gen SIEM struggles with complexity, limited customization, and integration issues, impacting usability and customer satisfaction.
Perhaps more flexibility in terms of metrics would be helpful.
The passing and setup are quite complex at the beginning, making onboarding not smooth.
When dealing with a large amount of data, such as when firewall logs increase, queries sometimes crash or get stuck.
SIEM could have better integration with other technologies.
 

Setup Cost

Cribl offers a cost-effective, scalable pricing model with up to 30% cost reductions, appealing to mid-level and large enterprises.
Securonix Next-Gen SIEM offers competitive and predictable pricing based on user numbers, ideal for large enterprises.
Licensing is based on events per second (EPS), costing between $50 to $60 per EPS.
The pricing has similar ingestion charges compared to other solutions, such as Splunk.
 

Valuable Features

Cribl streamlines real-time data transformation, log collection, and routing with user-friendly features, security, and extensive integration support.
Securonix Next-Gen SIEM provides advanced threat detection and management with machine learning, automation, and user behavior analytics.
The community on Slack is excellent for solving questions and getting ideas.
The software includes user behavior interactions, dashboards, and training capabilities.
Now, the process is automatic, reducing our workload.
 

Categories and Ranking

Cribl
Ranking in Security Information and Event Management (SIEM)
13th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
10
Ranking in other categories
Application Performance Monitoring (APM) and Observability (14th), Log Management (13th), Observability Pipeline Software (1st)
Securonix Next-Gen SIEM
Ranking in Security Information and Event Management (SIEM)
14th
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
33
Ranking in other categories
Identity Threat Detection and Response (ITDR) (8th)
 

Mindshare comparison

As of April 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cribl is 0.5%, up from 0.1% compared to the previous year. The mindshare of Securonix Next-Gen SIEM is 1.0%, down from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Phanindra Ponnada - PeerSpot reviewer
Provides good documentation and worth the investment
As of now, there are some environments where some organizations are still on legacy infrastructure, so they are still in virtual environments and are using old versions of devices. Some companies bought Splunk, while others bought Cribl for a very low-priced license. There are some protocols to connect from Cribl to Splunk. I understand Cribl has come into the market very recently, but the tool might have had a picture in its mind where organizations might also have some legacy infrastructure. In the future, with our protocols or our level of architecture, Cribl should not come and say that it is not compatible with them. If Cribl is the reason because I have to change my environment, then I will have to end up investing more. There are some organizations where the end machines have forwarders that forward the data to Cribl, and from it, the data is forwarded to Splunk. This is how general architecture works. There are two methods of connection between Cribl and Splunk. One is the S2S protocol, which collects logs from Cribl or sends data between Cribl and Splunk. There is another method called HTTP Event Collector (HEC) and HTTPS protocol. With Cribl, connecting to Splunk mostly uses the S2S protocol. The tool supports all the latest devices and platform devices, like all the latest operating systems. There are some organizations where there is legacy infrastructure or if they are still on the old platforms. Companies using old platforms have to consider HTTP Event Collector (HEC), and then they have to change their infrastructure setup in order to fulfill that setup. In order to have Google and Splunk set up in my organization, if I have to change my existing infrastructure connectivity or setup, that might incur more cost or more investment for me to have Cribl and Splunk. Cribl should provide compatibility, or else the tool's developers should speak to the people of such organizations and understand the challenges. Cribl could have developed some version that can give backward compatibility.
Ibrahim Albalawi - PeerSpot reviewer
Less false positives, good detection and integration capabilities, and good pricing
The incident response area should be improved. It is more difficult than other products, but overall, it is good. The platform has a lot of options and functionality. So, you need to check almost everything. For new engineers or people who don’t have much experience with this kind of platform, it is a bit difficult, but for experienced engineers, it is not that difficult. When you have been doing a lot of work for about one or two hours, and you have a lot of tabs open, it slows down or gets stuck. There is a delay of 10 to 15 seconds in opening tabs or dashboards. I don't know why this happens, but for me, it is not a big issue. I just wait, and that's all.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
847,772 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
10%
Healthcare Company
8%
Government
7%
Computer Software Company
20%
Financial Services Firm
12%
Government
6%
Manufacturing Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Cribl?
I am not aware of the pricing details, however, I know they use a credit format for billing.
What needs improvement with Cribl?
At the moment, I don't have specific feedback on what can be improved as I do not work with Cribl daily. Perhaps more flexibility in terms of metrics would be helpful.
What is your primary use case for Cribl?
I am using Cribl to have everything centralized in one tool in terms of data collection. We were working with different Splunk customers, and Cribl helps collect data and then send it to an S3 buck...
Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was pretty good. Now a lot of them are looking for a more effective solution due to ...
What is your primary use case for Securonix Security Analytics?
I use this solution for security monitoring and user behavior analytics. Banks, governments, and the oil and gas sector utilize it.
What do you like most about Securonix Next-Gen SIEM?
The two major features of this product we extensively use are the UEBA capability and the multi-tenant approach with the centralized data logs system. Customers are very happy with these features.
 

Also Known As

No data available
Securonix Security Analytics
 

Overview

 

Sample Customers

Information Not Available
Dtex Systems, Pfizer, Western Union, Harris, ITG
Find out what your peers are saying about Cribl vs. Securonix Next-Gen SIEM and other solutions. Updated: April 2025.
847,772 professionals have used our research since 2012.