Share your experience using Amazon Detective

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 83,000+ reviews on PeerSpot:

Security Engineer at a venture capital & private equity firm with 1,001-5,000 employees
Real User
Top 5
Provides real-time alerts and has efficient features for incident management
Pros and Cons
  • "Numerous data monitoring tools are available, but Coralogix somehow fine-tunes our policies and effectively supports our teams."
  • "It would be helpful if Coralogix could integrate the main modules that any organization requires into a single subscription."

What is our primary use case?

We use Coralogix to analyze our log metrics. We were looking for an enhanced tool to help us secure our real-time data.

How has it helped my organization?

We have integrated Coralogix with Slack and other tools, which has helped us receive real-time alerts. We don't have to constantly monitor the tool because it generates alerts and pushes them to us, providing notifications on Slack. This enhancement has strengthened our security, fulfilling our need when searching for such a tool. 

Numerous data monitoring tools are available, but Coralogix somehow fine-tunes our policies and effectively supports our teams. This SaaS platform utilizes machine learning for behavioral analysis of logs, yielding the results we need. For instance, there was a scenario where we received extension logs that were difficult to interpret. However, we obtained the analysis with the help of the product.

What is most valuable?

Almost all the features we currently use in our product subscription are important to us. Regarding alerting or incident management, incident alert mapping, and suppression rules, we utilize almost all the features available on Coralogix. Additionally, we are sending all the logs, such as app logs, EPC flow logs, etcetera.

What needs improvement?

Nowadays, tools are often divided into modules. It would be helpful if Coralogix could integrate the main modules that any organization requires into a single subscription. It would streamline the process for organizations like ours.

Merging some of the modules into a single subscription would be beneficial. Nowadays, modules are often separated, so if an organization needs additional modules after subscribing to one, they may have to purchase another subscription. Combining the availability module with tracing metrics or other relevant modules would be beneficial.

What do I think about the stability of the solution?

I rate the platform's stability a nine out of ten.

What do I think about the scalability of the solution?

I rate the platform's scalability an eight.

How are customer service and support?

We did contact the technical support team when we encountered a deployment issue with Cloudflare. They assisted us promptly and provided helpful answers within the expected time frame.

Which solution did I use previously and why did I switch?

Before adopting Coralogix, we relied on open-source solutions, but they needed to meet our needs effectively. It led us to explore and eventually invest in a commercial product.

What's my experience with pricing, setup cost, and licensing?

The platform has a reasonable cost. I rate the pricing a three out of ten.

Which other solutions did I evaluate?

We also evaluated Palo Alto and other Palo Alto products as potential solutions. We opted for Coralogix over Palo Alto because its subscription plan offered better visibility and more features.

What other advice do I have?

The alerting feature in Coralogix, integrated with Slack, has helped your team respond to incidents more quickly and effectively. We haven't experienced any incidents since implementation. Still, during the POC phase, the alerting feature proved to be prompt and reliable, assisting your team in promptly addressing potential issues.

It provides visualization tools that facilitate data analysis. These tools are available directly on the dashboard.

I recommend analyzing their organization's use case and scenario for new users. They should compare it with other tools to see if it suits their needs. If they find it suitable, then they should proceed with it. However, they should be prepared for the possibility that the tool may only suit some organizations. In our case, it worked well in pricing, scenario, and overall performance, so we opted to use it.


I rate it a nine out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Flag as inappropriate
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Real User
Top 5Leaderboard
Quickly identifies threats, secures our environment faster, and reduces alert volumes
Pros and Cons
  • "The Splunk queries are valuable."
  • "I would like the ability to view logs for specific instances and not have to pull the logs for the entire Cloud environment in Splunk."

What is our primary use case?

We use Splunk Enterprise Security to teach our students about security awareness in a more positive way. We can show them how these tools work and the benefits they bring. This will help them understand the importance of using Splunk Enterprise Security, not just for our clients, but for ourselves as well.

How has it helped my organization?

The Splunk dashboards are user-friendly.

I would rate Splunk's threat topology an eight out of ten. The threat topology provides a complete map so we can investigate security incidents quickly.

To effectively utilize Splunk for malicious activity analysis, a comprehensive understanding of the different event types and their functionalities is crucial. This involves examining specific events associated with potential malware, such as changes in system behavior. By gaining clear visibility into these events, we can identify the malware's goals within our environment and stop it.

Splunk helps us detect threats within three minutes.

We realized the benefits of Splunk within eight months. Splunk Enterprise Security helped secure our environment faster than other security solutions.

Splunk has helped reduce our alert volume.

What is most valuable?

The Splunk queries are valuable. There are a lot of query options available in Splunk compared to Sumo Logic.

What needs improvement?

It is difficult to monitor multiple cloud environments using Splunk.

I would like the ability to view logs for specific instances and not have to pull the logs for the entire Cloud environment in Splunk.

As the number of environments monitored by Splunk increases, the resource demands also grow, potentially slowing down the system.

Splunk's threat intelligence system gets a seven out of ten. There are frequent delays in updates, which can take up to three months for Splunk to make available.

For how long have I used the solution?

I have been using Splunk Enterprise Security for one year.

What do I think about the stability of the solution?

I would rate the stability of Splunk Enterprise Security ten out of ten.

The resilience is good. I have not faced any issues.

What do I think about the scalability of the solution?

I would rate the stability of Splunk Enterprise Security nine out of ten.

How are customer service and support?

The technical support team is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. Splunk provides wonderful documentation to help with the deployment.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Security is priced lower than competitors.

Splunk Enterprise Security is a good choice for startup companies because of the lower cost.

What other advice do I have?

I would rate Splunk Enterprise Security nine out of ten.

Maintenance is required to address the false positive alerts.

I recommend Splunk Enterprise Security to others.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate