No more typing reviews! Try our Samantha, our new voice AI agent.

Anvilogic vs Devo comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.7
Organizations using Anvilogic gained efficiency, reduced staffing needs, and rapid cyber threat response, though alert volume required tuning.
Sentiment score
6.5
Devo enhances data analysis and threat detection cost-effectively, offering scalability, customization, and efficiency in resource allocation.
We're taking these things that executives see on the news, cyber threats falling from the sky, and we're taking the timeline that would take weeks or sometimes even months to address, depending on what's required for the detection, and bringing that timeline down to hours and days.
Director, Cybersecurity Operations at Labcorp
We rolled out approximately 1,500 Armory alerts in three months, which would not have been possible with Splunk.
Vice President, Information & Cyber Security at St. George's University
If we were not doing more and did not have Anvilogic, we would need one dedicated person to do this detection engineering.
Head of Information Security at a tech vendor with 1,001-5,000 employees
 

Customer Service

Sentiment score
7.1
Anvilogic's customer service is praised for responsiveness and expertise, despite occasional delays and lacking a clear tracking system.
Sentiment score
6.7
Devo's customer service is praised for responsiveness and effectiveness, but some seek better documentation and clarity in ticket handling.
The product management and the product engineering team are available to us if we need to review something with them.
Director, Cybersecurity at a financial services firm with 10,001+ employees
One of the best things about Anvilogic is the partnership, their knowledge, the depth of technical understanding, and the speed at which they respond.
Head of Information Security at a tech vendor with 1,001-5,000 employees
I would evaluate their customer service and tech support as fantastic.
Senior Director | Detection Response at a tech vendor with 1,001-5,000 employees
I rate the customer support a nine out of ten because of their timely technical guidance and responsiveness during the deployment and troubleshooting periods.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
Both response time and support quality need attention.
Team Lead SOC at a tech services company with 51-200 employees
 

Scalability Issues

Sentiment score
6.8
Anvilogic is highly scalable and cost-effective, integrating seamlessly with platforms like Snowflake, enhancing performance and stakeholder adoption.
Sentiment score
7.0
Devo's cloud-based architecture ensures impressive scalability, efficiently managing large data volumes and integrating users across regions without limitations.
We started with about 55 detections and scaled up to about 980 odd detections so far.
Head of Information Security at a tech vendor with 1,001-5,000 employees
Anvilogic scales effectively with the growing needs of my organization.
Senior Director | Detection Response at a tech vendor with 1,001-5,000 employees
Anvilogic is helping us identify what the needs of the business are, where in many cases, business processes just run off on their own.
Director, Cybersecurity Operations at Labcorp
Devo is a unified SIEM solution designed to handle growing log volumes and enterprise-scale monitoring requirements.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
 

Stability Issues

Sentiment score
6.7
Anvilogic is highly reliable with minimal issues, occasional slowness, and responsive support enhancing user trust in its stability.
Sentiment score
7.3
Devo is praised for its stability, reliable uptime, proactive support, and effective management of large deployments despite minor issues.
I have never experienced a serious outage.
Vice President, Information & Cyber Security at St. George's University
I would assess the stability and reliability of Anvilogic as very good.
Senior Director | Detection Response at a tech vendor with 1,001-5,000 employees
The biggest instability has been with the AI agent, which the team is not using fully due to inconsistent results.
Senior Manager, Threat Prevention Engineering at a tech vendor with 5,001-10,000 employees
It is stable and reliable for our security operations.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
 

Room For Improvement

Anvilogic users desire enhancements in integration, case management, and detection logic while facing challenges with input limits and documentation.
Devo's Activeboards need better customization, integration, UI, and AI capabilities, while cost and usability require attention.
Flexibility is key for any enterprise platform to meet our unique business requirements.
Senior Manager, Threat Prevention Engineering at a tech vendor with 5,001-10,000 employees
It lacked a robust CI/CD pipeline, which is crucial for comprehensive testing before changes go into production.
Threat Researcher 2 at a tech vendor with 1,001-5,000 employees
It seems that it requires more growth in how you can navigate through it and see the overall maturity of it clearly for a specific actor versus the enterprise-wide visibility of the whole maturity of the program.
Manager, Threat Intel & Detection Operations at Zendesk
This is particularly evident when dealing with failed login attempts and determining true versus false positives.
Strategic Account Executive at a computer software company with 51-200 employees
UI improvements, a simplified dashboard, or an easier reporting workflow could further improve analyst productivity.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
I would appreciate more third-party integrations including Fortinet and others.
Team Lead SOC at a tech services company with 51-200 employees
 

Setup Cost

Anvilogic provides competitive, straightforward pricing and support, though some note it doesn't fully replace a SIEM solution.
Devo offers transparent pricing per gigabyte, with potential metadata charges, including 400-day storage and additional feature benefits.
Because they do not completely replace a SIEM, their pricing is slowly edging towards being a little too much for a smaller organization like ours.
Head of Information Security at a tech vendor with 1,001-5,000 employees
Licensing is reasonably affordable and should be evaluated over time concerning the platform's value.
Senior Manager, Threat Prevention Engineering at a tech vendor with 5,001-10,000 employees
They provide estimates because obviously every business is different, but they provided reasonable estimates that were fairly accurate based on other customers from a similar type of background or size.
Manager, Threat Intel & Detection Operations at Zendesk
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps.
Team Lead SOC at a tech services company with 51-200 employees
 

Valuable Features

Anvilogic optimizes SOC operations with AI-driven detection, no-code efficiency, and integration across platforms like Snowflake and Splunk.
Devo impresses with real-time analytics, intuitive UI, customization, advanced alerting, cloud-native architecture, and 400 days of data retention.
Detection insights help us easily identify the most noisy ones, the effective ones, and what needs to be fixed to move the noisy ones to effective ones.
Head of Information Security at a tech vendor with 1,001-5,000 employees
The learning curve is not steep, allowing even those with basic knowledge in writing detection rules to adapt quickly.
Threat Researcher 2 at a tech vendor with 1,001-5,000 employees
Anvilogic plus Snowflake has vastly improved our total cost of ownership for the SIM platform; we went from a pretty expensive platform in Splunk that was not vertically scalable due to budget limitations to a platform now that is far more efficient per terabyte of data ingested and processed per day.
Senior Manager, Threat Prevention Engineering at a tech vendor with 5,001-10,000 employees
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
Strategic Account Executive at a computer software company with 51-200 employees
When the analyst uses queries to search, it pulls the data quickly, in a second, which aids us greatly with the investigation.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
It utilizes 400 days of hot data, allowing queries to run very fast and yield results quicker than other tools in terms of security and SIEM capability.
Senior Cloud Engineer at a tech services company with 201-500 employees
 

Categories and Ranking

Anvilogic
Ranking in Security Information and Event Management (SIEM)
11th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
13
Ranking in other categories
AI-SOC (2nd)
Devo
Ranking in Security Information and Event Management (SIEM)
18th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
26
Ranking in other categories
Log Management (18th), IT Operations Analytics (7th), AIOps (13th)
 

Mindshare comparison

As of August 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Anvilogic is 0.6%, up from 0.3% compared to the previous year. The mindshare of Devo is 1.2%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Anvilogic0.6%
Devo1.2%
Other98.2%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2800338 - PeerSpot reviewer
Senior Manager, Threat Prevention Engineering at a tech vendor with 5,001-10,000 employees
Modern threat detection has improved coverage and reduced costs but still needs better UX and flexibility
There is room for growth in the product platform; our detection engineers using Anvilogic every day encounter some frustrating UX experience issues where buttons are not logically placed, and workflows are not working as expected. There is also room for growth in integrating the platform with third parties, as we have encountered limitations in what can be executed via API and what is documented. We are a heavy automation integration team, so having this well documented is important for us. The enterprise capabilities within the platform also seem somewhat limited, as we run into limitations in managing detections at scale and making changes to those detections at scale. Especially at an enterprise level, if we need to add enrichment logic to every single detection deployed, it can be quite onerous; we had to develop custom scripts to manage that. Thus, enhancing enterprise-type features for managing the platform at scale rather than clicking through the GUI is important as we continue to grow. Additionally, the AI capabilities have been somewhat unstable and unintuitive to use, which is key for increasing adoption. One other thing is that the detection logic builder today is somewhat limited in flexibility regarding implementing detections, grouping detections together, and handling alerts when they fire. This might be partly due to our need to adjust to a different platform, but flexibility is key for any enterprise platform to meet our unique business requirements. Having the capability to build custom detection logic not tied to a specific structure would be helpful; although a lot can be done, it often requires working with our account team which is time-consuming and less intuitive.
Usama Khan - PeerSpot reviewer
Team Lead SOC at a tech services company with 51-200 employees
Advanced threat hunting has improved SOC visibility and now supports faster incident response
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM is basically on the AWS cloud. There are specific ports which are enabled on the relay server, which are 514 and 13000, 13151, 152. However, when we talk about databases and custom integrations, there are not default ports in the relay server. No default ports are defined. For JDBC drivers, the port number is 1433, but it is not in the relay server. You have to add it manually. For Oracle RDBMS, the port is 1521, and it is also not there by default. I would appreciate more third-party integrations including Fortinet and others. Machine learning models can also be improved. Playbooks in the SOAR can also be improved. Regarding playbooks for automation, we utilize playbooks for automation in SOAR for automated IOC blocking on a firewall, on a web application firewall, on DNS security, etc. The only option for us to run the playbook is to schedule the job for it. However, if I want to manually run the playbook, there is no option for doing so. This needs improvement.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Outsourcing Company
8%
Healthcare Company
8%
Comms Service Provider
7%
Financial Services Firm
15%
Construction Company
10%
Outsourcing Company
9%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Large Enterprise12
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise5
Large Enterprise12
 

Questions from the Community

What is your experience regarding pricing and costs for Anvilogic?
I am from the technical department, so I do not have details about pricing, setup cost, or licensing, as that was handled by my management team.
What needs improvement with Anvilogic?
I would not say there is anything I would like to add regarding how Anvilogic can be improved, as they are probably working on many improvements already. I do not think there is anything that could...
What is your primary use case for Anvilogic?
My main use case for Anvilogic is for detection engineering, and I manage all of my use cases and alerts in the AVLs through Anvilogic. A specific example of how I use Anvilogic for detection engin...
What is your experience regarding pricing and costs for Devo?
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps. Its licensing model is basically on per-day ...
What needs improvement with Devo?
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM ...
What is your primary use case for Devo?
I am using Devo myself. Basically, I work at an MSSP, and we provide services to the organization for Security Operation Centers. In our Security Operation Center, we provide the service of SIEM vi...
 

Comparisons

 

Overview

 

Sample Customers

Information Not Available
United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Find out what your peers are saying about Anvilogic vs. Devo and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.