We are one of the five partners of Google Chronicle Suite in the world. We resell the solution, and we implement it for Google.
Security engineer at a tech services company with 51-200 employees
A highly scalable solution with good threat intelligence capabilities, but its GUI should be more user-friendly
Pros and Cons
- "Google Chronicle Suite is a highly scalable solution with good search capabilities."
- "The solution's graphical user interface (GUI) should be more user-friendly."
What is our primary use case?
What is most valuable?
Google Chronicle Suite is a highly scalable solution with good search capabilities. The enterprise version comes with one of the best threat intelligence capabilities in the world.
What needs improvement?
The solution's graphical user interface (GUI) should be more user-friendly.
For how long have I used the solution?
I have been using Google Chronicle Suite for more than two years.
Buyer's Guide
Security Information and Event Management (SIEM)
January 2025

Find out what your peers are saying about Google, Splunk, Microsoft and others in Security Information and Event Management (SIEM). Updated: January 2025.
838,640 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the solution eight and a half out of ten for stability.
What do I think about the scalability of the solution?
I rate Google Chronicle Suite nine and a half out of ten for scalability.
How are customer service and support?
The solution's technical support is good but not great. Recently, Google has started hiring people for the technical support team. We never needed their support unless it was something to be done to which we did not have access.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup is not that easy.
What about the implementation team?
We have done multiple implementations, and the solution's deployment time depends on the organization.
What's my experience with pricing, setup cost, and licensing?
Compared to other solutions, Google Chronicle Suite's pricing is fine.
What other advice do I have?
We are using the latest version of Google Chronicle Suite.
Scalability is one of the requirements in enterprise-level organizations. They need a flexible solution that can be scaled easily. An enterprise-level organization will have huge amounts of data. If you want to do threat hunting for one year for such an organization, you don't want a system that goes down if you search for more than 30 days. You need a solution that will give you good search results.
Google Chronicle Suite is one of the best products in the market if you are looking for incident response and threat-hunting use cases. It is not a recommended solution for compliance, reporting, or dashboarding.
Overall, I rate the solution a seven or seven and a half out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:

Security Consultant at a tech consulting company with 1,001-5,000 employees
A highly scalable tool that performs well and has premade dashboards that provide information on errors in the system
Pros and Cons
- "The log folder is fairly simple."
- "The configuration is not optimal."
What is our primary use case?
I've been using the solution as a consultant while working for a client who has chosen Google Chronicle as their SIEM solution. We are using the product as a centralized log management solution and as a solution for threat intelligence. We use it to analyze incoming log information and automatically generate alerts from indicators that have been compromised.
What is most valuable?
The search feature is quite performant. The log folder is fairly simple. It is easy to get it up and running and to use for log management and forwarding. I found it quite useful that the solution has premade dashboards, which provide information on errors in the system and general monitoring functionality.
What needs improvement?
The configuration is not optimal. It requires copy and paste of configuration files. Generally, the ingest of logs could be done in simpler and more streamlined ways. The exporting of log information also has room for improvement.
For how long have I used the solution?
I am using the solution currently.
What do I think about the stability of the solution?
I rate the tool’s stability a ten out of ten. I have not encountered any issues.
What do I think about the scalability of the solution?
I rate the tool’s scalability a ten out of ten. Around 12 people use the product in our organization. The usage will increase as it's gaining traction on the market, and more people will have to work in consulting.
Which solution did I use previously and why did I switch?
I'm working as a SIEM consultant. I've worked with several SIEM systems over time.
How was the initial setup?
The initial setup is very easy. As a cloud-native tool, it includes provisioning an instance and connecting it to a single sign-on. I rate the ease of setup a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is not dependent on the volume of information ingested, which most competitors do. In many cases, that makes it less pricey than the competition, but not in all cases.
What other advice do I have?
The solution has room for improvement. People who want to use the tool must get a Google partner to work with them and outsource the whole thing. The product is a great choice. Organizations must ensure they have competent people who can use the tool to its full potential. A lot of it may be wasted if they don't have the right people or the right partner. Overall, I rate the product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Security Information and Event Management (SIEM)
January 2025

Find out what your peers are saying about Google, Splunk, Microsoft and others in Security Information and Event Management (SIEM). Updated: January 2025.
838,640 professionals have used our research since 2012.
Security | SIEM Engineer at a tech services company with 51-200 employees
Stable product with efficient data retrieval and security features
Pros and Cons
- "The product's most valuable feature is threat hunting. We can detect the threats directly from the console from the past data as well."
- "The product's default dashboard feature has a few limitations regarding availability."
What is our primary use case?
We use the product for search engine integration and its ability to monitor and address network attention or login issues 24/7.
How has it helped my organization?
The product helps us with data retrieval and security features.
What is most valuable?
The product's most valuable feature is threat hunting. We can detect the threats directly from the console from the past data as well.
What needs improvement?
The product's default dashboard feature has a few limitations regarding availability.
For how long have I used the solution?
We have been using Google Chronicle Suite for two years as an integrator.
What do I think about the stability of the solution?
We encountered platform downtime once or twice.
What do I think about the scalability of the solution?
It is a scalable product. We manage accounts for Google Chronicle Suite seven to eight customers.
How are customer service and support?
We have limited technical support services. However, they provide good support, understand the queries, and respond.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup process is easy. The deployment involves checking default requirements for installing the product and configuring the log source. It requires five to ten minutes to complete. It doesn't need any maintenance. We have to make sure the forwarder is not switched off.
What other advice do I have?
I rate Google Chronicle Suite a nine out of ten. It helps connect to the log sources rapidly. However, it has limited IAM access and dashboarding features.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator

Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Google, Splunk, Microsoft, and more!
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Sumo Logic Security
Fortinet FortiSIEM
Cortex XSIAM
AlienVault OSSIM
Securonix Next-Gen SIEM
Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Google, Splunk, Microsoft, and more!
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?