I've been using the solution as a consultant while working for a client who has chosen Google Chronicle as their SIEM solution. We are using the product as a centralized log management solution and as a solution for threat intelligence. We use it to analyze incoming log information and automatically generate alerts from indicators that have been compromised.
Security Consultant at a tech consulting company with 1,001-5,000 employees
A highly scalable tool that performs well and has premade dashboards that provide information on errors in the system
Pros and Cons
- "The log folder is fairly simple."
- "The configuration is not optimal."
What is our primary use case?
What is most valuable?
The search feature is quite performant. The log folder is fairly simple. It is easy to get it up and running and to use for log management and forwarding. I found it quite useful that the solution has premade dashboards, which provide information on errors in the system and general monitoring functionality.
What needs improvement?
The configuration is not optimal. It requires copy and paste of configuration files. Generally, the ingest of logs could be done in simpler and more streamlined ways. The exporting of log information also has room for improvement.
For how long have I used the solution?
I am using the solution currently.
Buyer's Guide
Security Information and Event Management (SIEM)
December 2024
Find out what your peers are saying about Google, Splunk, Microsoft and others in Security Information and Event Management (SIEM). Updated: December 2024.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the tool’s stability a ten out of ten. I have not encountered any issues.
What do I think about the scalability of the solution?
I rate the tool’s scalability a ten out of ten. Around 12 people use the product in our organization. The usage will increase as it's gaining traction on the market, and more people will have to work in consulting.
Which solution did I use previously and why did I switch?
I'm working as a SIEM consultant. I've worked with several SIEM systems over time.
How was the initial setup?
The initial setup is very easy. As a cloud-native tool, it includes provisioning an instance and connecting it to a single sign-on. I rate the ease of setup a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is not dependent on the volume of information ingested, which most competitors do. In many cases, that makes it less pricey than the competition, but not in all cases.
What other advice do I have?
The solution has room for improvement. People who want to use the tool must get a Google partner to work with them and outsource the whole thing. The product is a great choice. Organizations must ensure they have competent people who can use the tool to its full potential. A lot of it may be wasted if they don't have the right people or the right partner. Overall, I rate the product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security | SIEM Engineer at a tech services company with 51-200 employees
Stable product with efficient data retrieval and security features
Pros and Cons
- "The product's most valuable feature is threat hunting. We can detect the threats directly from the console from the past data as well."
- "The product's default dashboard feature has a few limitations regarding availability."
What is our primary use case?
We use the product for search engine integration and its ability to monitor and address network attention or login issues 24/7.
How has it helped my organization?
The product helps us with data retrieval and security features.
What is most valuable?
The product's most valuable feature is threat hunting. We can detect the threats directly from the console from the past data as well.
What needs improvement?
The product's default dashboard feature has a few limitations regarding availability.
For how long have I used the solution?
We have been using Google Chronicle Suite for two years as an integrator.
What do I think about the stability of the solution?
We encountered platform downtime once or twice.
What do I think about the scalability of the solution?
It is a scalable product. We manage accounts for Google Chronicle Suite seven to eight customers.
How are customer service and support?
We have limited technical support services. However, they provide good support, understand the queries, and respond.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup process is easy. The deployment involves checking default requirements for installing the product and configuring the log source. It requires five to ten minutes to complete. It doesn't need any maintenance. We have to make sure the forwarder is not switched off.
What other advice do I have?
I rate Google Chronicle Suite a nine out of ten. It helps connect to the log sources rapidly. However, it has limited IAM access and dashboarding features.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Google, Splunk, Microsoft, and more!
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
ArcSight Enterprise Security Manager (ESM)
Stellar Cyber Open XDR
Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Google, Splunk, Microsoft, and more!
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?