What is our primary use case?
We are using CrowdStrike Observability now instead of Cisco or Dell. We are using the CrowdStrike EDR products. I'm working with CrowdStrike EDR. We are also using CrowdStrike Observability or Falcon LogScale.
What is most valuable?
The product provides complete hardware and software inventory. When we install the connector on one machine, it gives us all the details regarding hardware as well as software.
I use its predictive analytics.
In the logs and the trajectory, it shows detailed information about where the source of infection comes from, how it travels, and how to reach there. It gives us the complete trajectory.
I use the intuitive dashboard.
There are categories for mean, medium, high, and critical threats. If we determine something is a critical or high threat, we can investigate and follow up.
What needs improvement?
If they can provide us with the XDR features within the package with no extra cost, that would be beneficial for us.
In the whole CrowdStrike package regarding the XDR feature, we need the ability to integrate our other security products so we can get visibility on one platform.
For how long have I used the solution?
I have been using CrowdStrike Observability for almost one year.
What was my experience with deployment of the solution?
It was very straightforward to deploy CrowdStrike Observability products.
What do I think about the stability of the solution?
I didn't need technical support as the product is stable.
I don't have new ideas at the moment regarding CrowdStrike Observability because we have one security team monitoring it. I use it sometimes to view policies and other things. It is a very stable product and doesn't require much interference from the user end.
Every security product has false positives.
How are customer service and support?
We have not experienced any issues with technical support from CrowdStrike Observability, but I don't know the exact details.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We switched over from Trend Micro to CrowdStrike Observability last year, and we are satisfied at the moment and are continuing with it.
How was the initial setup?
I took part in the implementation of CrowdStrike Observability in my system.
What was our ROI?
Regarding the return on investment from CrowdStrike Observability, it's difficult to quantify. If it defends and protects us, we can say our money is not wasted. However, it is not easy to give a specific answer to that question.
What's my experience with pricing, setup cost, and licensing?
The cost price is a little bit high, but if you feel at ease, it's easy to use. The pricing is very high and small companies cannot afford it. They should reduce the price because the backend infrastructure is the same. Since it's a cloud-based solution and backend infrastructure does not require many changes, they should reduce the price to accommodate small to medium businesses.
What other advice do I have?
We have our security team monitoring our threats. I can log in with admin rights, but I don't use it very much.
I have not found anything disadvantageous in CrowdStrike Observability. They have all the features. In the legacy products, they are offering connectors and supporting Server 2012 or even earlier versions.
Sometimes the intelligent alerting shows false positives, but it's under our control and we can ignore those alerts.
Based on my experience with the consoles and alerts, it gives us complete detail alerts, and the documentation is very comprehensive. I would rate it seven out of ten.
The stability can be rated as nine out of ten.
I recommend it mostly to enterprise companies.
Overall rating: 7/10.