Try our new research platform with insights from 80,000+ expert users

Devo vs Palantir Foundry comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Devo
Ranking in IT Operations Analytics
3rd
Average Rating
8.4
Number of Reviews
22
Ranking in other categories
Log Management (28th), Security Information and Event Management (SIEM) (27th), AIOps (16th)
Palantir Foundry
Ranking in IT Operations Analytics
4th
Average Rating
7.6
Number of Reviews
15
Ranking in other categories
Data Integration (12th), Supply Chain Analytics (1st), Cloud Data Integration (10th), Data Migration Appliances (3rd), Data Management Platforms (DMP) (1st), Data and Analytics Service Providers (1st)
 

Mindshare comparison

As of November 2024, in the IT Operations Analytics category, the mindshare of Devo is 9.2%, down from 9.9% compared to the previous year. The mindshare of Palantir Foundry is 4.2%, down from 6.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Operations Analytics
 

Featured Reviews

Michael Wenn - PeerSpot reviewer
Aug 2, 2024
Has cloud-first architecture with SIEM technology to run security operations
When it comes to scale, they're architected quite well. They handle some of the biggest customers globally, with significant throughput on their platform, managing thousands of customers. One of the most impressive aspects of Devo is its customer community. A large majority, over 80 percent of their customers, actively participate on a Devo-specific community page. They're contributing to product development and support, events, and user group information, helping each other out. This high level of engagement is rare and demonstrates both the loyalty of their customer base and the quality of their product. They offer a range of small, medium, and large options to cater to everyone. I sold Devo products while working with them, focusing on enterprise solutions. However, as a small reseller, my customers were typically smaller businesses. I rate the solution's scalability a nine out of ten.
Manilal Kasera - PeerSpot reviewer
Nov 22, 2022
Transparent with good reliability and good data visibility
The initial setup had a medium level of difficulty. If we go through the documentation, we can learn about what to do. In Palantir, they had a section called Academy, and that Academy was quite useful. If you go through that as a new user, it makes the process easier as you learn what to do. Initially, we didn't have many sources that would help us learn things, so we struggled a bit. In contrast, with Azure and Amazon Cloud, you have many sources from where you would be easily able to learn. You could just Google what you needed with them, as there's so much available documentation online. What was easy was the fact that everything was in one place. With AWS Cloud, there are many applications to support. You can use Glue or Athena, and you have all these other applications. However, with Palantir, everything is easy due to the fact that it is centralized. It's drag and drop and everything is very transparent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Devo helps us to unlock the full power of our data because they have more than 450 parsers, which means that we can ingest pretty much any type of log data."
"Scalability is one of Devo's strengths."
"The thing that Devo does better than other solutions is to give me the ability to write queries that look at multiple data sources and run fast. Most SIEMs don't do that. And I can do that by creating entity-based queries. Let's say I have a table which has Okta, a table which has G Suite, a table which has endpoint telemetry, and I have a table which has DNS telemetry. I can write a query that says, 'Join all these things together on IP, and where the IP matches in all these tables, return to me that subset of data, within these time windows.' I can break it down that way."
"Even if it's a relatively technical tool or platform, it's very intuitive and graphical. It's very appealing in terms of the user interface. The UI has a graphically interface with the raw data in a table. The table can be as big as you want it, depending on your use case. You can easily get a report combining your data, along with calculations and graphical dashboards. You don't need a lot of training, because the UI is relatively very intuitive."
"The querying and the log-retention capabilities are pretty powerful. Those provide some of the biggest value-add for us."
"The most useful feature for us, because of some of the issues we had previously, was the simplicity of log integrations. It's much easier with this platform to integrate log sources that might not have standard logging and things like that."
"In traditional BI solutions, you need to wait a lot of time to have the ability to create visualizations with the data and to do searches. With this kind of platform, you have that information in real-time."
"The ability to have high performance, high-speed search capability is incredibly important for us. When it comes to doing security analysis, you don't want to be doing is sitting around waiting to get data back while an attacker is sitting on a network, actively attacking it. You need to be able to answer questions quickly. If I see an indicator of attack, I need to be able to rapidly pivot and find data, then analyze it and find more data to answer more questions. You need to be able to do that quickly. If I'm sitting around just waiting to get my first response, then it ends up moving too slow to keep up with the attacker. Devo's speed and performance allows us to query in real-time and keep up with what is actually happening on the network, then respond effectively to events."
"Great features available in one tool."
"The security is also excellent. It's highly granular, so the admins have a high degree of control, and there are many levels of security. That worked well. You won't have an EDC unless you put everything onto the platform because it is its own isolated thing."
"The ease of use is my favorite feature. We're able to build different models and projects or combine different projects to build one use case."
"It is easy to map out a workflow and run trigger-based scripts without having to deploy to another server."
"The solution offers very good end-to-end capabilities."
"The solution provides an end-to-end integrated tech stack that takes care of all utility/infrastructure topics for you."
"Encapsulates all the components without the requirement to integrate or check compatibility."
"I like the data onboarding to Palantir Foundry and ETL creation."
 

Cons

"Their documentation could be better. They are growing quickly and need to have someone focused on tech writing to ensure that all the different updates, how to use them, and all the new features and functionality are properly documented."
"There's room for improvement within the GUI. There is also some room for improvement within the native parsers they support. But I can say that about pretty much any solution in this space."
"We only use the core functionality and one of the reasons for this is that their security operation center needs improvement."
"One major area for improvement for Devo... is to provide more capabilities around pre-built monitoring. They're working on integrations with different types of systems, but that integration needs to go beyond just onboarding to the platform. It needs to include applications, out-of-the-box, that immediately help people to start monitoring their systems. Such applications would include dashboards and alerts, and then people could customize them for their own needs so that they aren't starting from a blank slate."
"The Activeboards feature is not as mature regarding the look and feel. Its functionality is mature, but the look and feel is not there. For example, if you have some data sets and are trying to get some graphics, you cannot change anything. There's just one format for the graphics. You cannot change the size of the font, the font itself, etc."
"Some basic reporting mechanisms have room for improvement. Customers can do analysis by building Activeboards, Devo’s name for interactive dashboards. This capability is quite nice, but it is not a reporting engine. Devo does provide mechanisms to allow third-party tools to query data via their API, which is great. However, a lot of folks like or want a reporting engine, per se, and Devo simply doesn't have that. This may or may not be by design."
"There is room for improvement in the ability to parse different log types. I would go as far as to say the product is deficient in its ability to parse multiple, different log types, including logs from major vendors that are supported by competitors. Additionally, the time that it takes to turn around a supported parser for customers and common log source types, which are generally accepted standards in the industry, is not acceptable. This has impacted customer onboarding and customer relationships for us on multiple fronts."
"From our experience, the Devo agent needs some work. They built it on top of OS Query's open-source framework. It seems like it wasn't tuned properly to handle a large volume of Windows event logs. In our experience, there would definitely be some room for improvement. A lot of SIEMs on the market have their own agent infrastructure. I think Devo's working towards that, but I think that it needs some improvement as far as keeping up with high-volume environments."
"It requires a lot of manual work and is very time-consuming to get to a functional point."
"Some error messages can be very cryptic."
"The workflow could be improved."
"The solution’s data security could be improved."
"The data lineage was challenging. It's hard to track data from the sources as it moves through stages. Informatica EDC can easily capture and report it because it talks to the metadata. This is generated across those various staging points."
"The solution's visualization and analysis could be improved."
"If you want to create new models on specific data sets, computing that is quite costly."
"Compared to other hyperscalers, Palantir Foundry is complex and not so user-intuitive."
 

Pricing and Cost Advice

"I rate the pricing a four on a scale of one to ten, where one is cheap, and ten is expensive."
"I like the pricing very much. They keep it simple. It is a single price based on data ingested, and they do it on an average. If you get a spike of data that flows in, they will not stick it to you or charge you for that. They are very fair about that."
"It's very competitive. That was also a primary draw for us. Some of the licensing models with solutions like Splunk and Sentinel were attractive upfront, but there were so many micro-charges and services we would've had to add on to make them what we wanted. We had to include things like SOAR and extended capabilities, whereas all those capabilities are completely included with the Devo platform. I haven't seen any additional fee."
"[Devo was] in the ballpark with at least a couple of the other front-runners that we were looking at. Devo is a good value and, given the quality of the product, I would expect to pay more."
"Be cautious of metadata inclusion for log types in pricing, as there are some "gotchas" with that."
"The way Devo prices things is based on the amount of data, and I wish the tiers had more granularity. Maybe at this point they do, but when we first negotiated with them, there were only three or four tiers."
"Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
"Devo is a hosted or subscription-based solution, whereas before, we purchased QRadar, so we owned it and just had to pay a maintenance fee. We've encountered this with some other products, too, where we went over to subscription-based. Our thought process is that with subscription based, the provider hosts and maintains the tool, and it's offsite. That comes with some additional fees, but we were able to convince our upper management it was worth the price. We used to pay under 10k a year for maintenance, and now we're paying ten times that. It was a relatively tough sell to our management, but I wonder if we have a choice anymore; this is where the market is."
"The solution’s pricing is high."
"Palantir Foundry is an expensive solution."
"Palantir Foundry has different pricing models that can be negotiated."
"It's expensive."
report
Use our free recommendation engine to learn which IT Operations Analytics solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
11%
Government
11%
Manufacturing Company
6%
Manufacturing Company
14%
Financial Services Firm
11%
Computer Software Company
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Devo?
Devo has a really good website for creating custom configurations.
What is your experience regarding pricing and costs for Devo?
Compared to Splunk or SentinelOne, it is really expensive. I rate the product’s pricing a nine out of ten, where one is cheap and ten is expensive.
What needs improvement with Devo?
They can improve their AI capabilities. If you look at some integrations like XDR or AI, which add to the platform to correlate situations in events, there are areas for enhancement. For instance, ...
What do you like most about Palantir Foundry?
Palantir Foundry is a robust platform that has really strong plugin connectors and provides features for real-time integration.
What needs improvement with Palantir Foundry?
The solution’s data security could be improved. We cannot use many Python packages with the solution. We were able to use only a few compatible Python packages.
What is your primary use case for Palantir Foundry?
Our use cases are mostly related to data analytics. We are building some dashboards and ETL pipelines on the Palantir side. Palantir Foundry is a low-code/no-code platform with a user-friendly UI. ...
 

Comparisons

 

Learn More

 

Overview

 

Sample Customers

United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Merck KGaA, Airbus, Ferrari,United States Intelligence Community, United States Department of Defense
Find out what your peers are saying about Devo vs. Palantir Foundry and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.