

Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
We rolled out approximately 1,500 Armory alerts in three months, which would not have been possible with Splunk.
We're taking these things that executives see on the news, cyber threats falling from the sky, and we're taking the timeline that would take weeks or sometimes even months to address, depending on what's required for the detection, and bringing that timeline down to hours and days.
If we were not doing more and did not have Anvilogic, we would need one dedicated person to do this detection engineering.
The product management and the product engineering team are available to us if we need to review something with them.
I would evaluate their customer service and tech support as fantastic.
One of the best things about Anvilogic is the partnership, their knowledge, the depth of technical understanding, and the speed at which they respond.
Anvilogic scales effectively with the growing needs of my organization.
We started with about 55 detections and scaled up to about 980 odd detections so far.
They can institute all the things they wish they had when they were SOC operators.
I have never experienced a serious outage.
I would assess the stability and reliability of Anvilogic as very good.
There is sometimes a bit of slowness and Splunk-related issues.
Anvilogic requires three clicks to get the full set of information.
The hunting insight needs integrable capability with different platforms to gather all of that insight and show it on a single canvas on Anvilogic.
Integrations with other sandboxes could be improved to better interpret data using AI and machine learning models.
Because they do not completely replace a SIEM, their pricing is slowly edging towards being a little too much for a smaller organization like ours.
My experience with pricing, setup costs, and licensing of Anvilogic was the easiest experience I have ever had.
Detection insights help us easily identify the most noisy ones, the effective ones, and what needs to be fixed to move the noisy ones to effective ones.
Being able to generate detections and map them back to MITRE, not as a 'we've accomplished security' type of metric, but at least showing that you have some form of adequate coverage across all of those different domains.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
| Product | Market Share (%) |
|---|---|
| Anvilogic | 0.4% |
| Devo | 1.1% |
| Other | 98.5% |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 4 |
| Large Enterprise | 11 |
Anvilogic breaks the SIEM lock-in that drives detection gaps and high costs for enterprise SOCs. It enables detection engineers and threat hunters to keep using their existing SIEM while seamlessly adopting a scalable and cost-effective data lake for high-volume data sources and advanced analytics use cases.
By eliminating the need for rip-and-replace, Anvilogic allows security leaders to confidently join the rest of the enterprise on the modern data stack without disrupting existing processes. Security operations teams at banks, airlines, and large tech companies use Anvilogic’s modular detection engine, thousands of curated threat scenarios, and AI security copilot to improve detection coverage and save millions of dollars.
Devo is the only cloud-native logging and security analytics platform that releases the full potential of all your data to empower bold, confident action when it matters most. Only the Devo platform delivers the powerful combination of real-time visibility, high-performance analytics, scalability, multitenancy, and low TCO crucial for monitoring and securing business operations as enterprises accelerate their shift to the cloud.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.