No more typing reviews! Try our Samantha, our new voice AI agent.

Chronosphere vs Devo comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Chronosphere
Ranking in Log Management
33rd
Ranking in AIOps
21st
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
3
Ranking in other categories
Application Performance Monitoring (APM) and Observability (35th)
Devo
Ranking in Log Management
17th
Ranking in AIOps
16th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
27
Ranking in other categories
Security Information and Event Management (SIEM) (17th), IT Operations Analytics (7th)
 

Mindshare comparison

As of September 2026, in the Log Management category, the mindshare of Chronosphere is 0.8%, up from 0.2% compared to the previous year. The mindshare of Devo is 1.4%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Devo1.4%
Chronosphere0.8%
Other97.8%
Log Management
 

Featured Reviews

Karthik Doreswamy - PeerSpot reviewer
Dev Ops Engineer at a tech services company with 11-50 employees
Centralized monitoring has unified alerts and dashboards for critical cloud applications
We can improve a bit of UI aspects. The UI could be made more user friendly. Sometimes when identifying the specific logs patterns and identifying what metrics and what logs are coming in, going to a specific log explorer and finding it there is a little difficult. It would be very useful if we could group according to projects and have that UI a little more user friendly. The user interface part was a bit confusing in the beginning. To make it better, I believe we would need some more open sourced or freely available courses on Chronosphere which would help us understand the platform a bit more. The team provides detailed walkthroughs whenever you get into that. However, it would be better if we could have proper video sessions or documentation which would help us understand the tool a bit more.
Usama Khan - PeerSpot reviewer
Team Lead Soc at a tech services company with 51-200 employees
Advanced threat hunting has improved SOC visibility and now supports faster incident response
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM is basically on the AWS cloud. There are specific ports which are enabled on the relay server, which are 514 and 13000, 13151, 152. However, when we talk about databases and custom integrations, there are not default ports in the relay server. No default ports are defined. For JDBC drivers, the port number is 1433, but it is not in the relay server. You have to add it manually. For Oracle RDBMS, the port is 1521, and it is also not there by default. I would appreciate more third-party integrations including Fortinet and others. Machine learning models can also be improved. Playbooks in the SOAR can also be improved. Regarding playbooks for automation, we utilize playbooks for automation in SOAR for automated IOC blocking on a firewall, on a web application firewall, on DNS security, etc. The only option for us to run the playbook is to schedule the job for it. However, if I want to manually run the playbook, there is no option for doing so. This needs improvement.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Integrating Chronosphere was pretty much easy coming from an open source tool and it helped us to streamline our monitoring and alerting setup across our organization, which directly impacted on the streamlining of the process as well as reducing errors and also keeping our environment uptime to a greater extent by those alerts and quick responses."
"Chronosphere has impacted my organization positively as for starters, we brought down the cost drastically since we completely moved to Chronosphere."
"The alerting features are good"
"Devo has a really good website for creating custom configurations."
"The ROI has been great as we could launch it in a few months instead of a couple of years, and when you put all the costs together, it is less to have done it than with the open source approach."
"The thing that Devo does better than other solutions is to give me the ability to write queries that look at multiple data sources and run fast. Most SIEMs don't do that. And I can do that by creating entity-based queries. Let's say I have a table which has Okta, a table which has G Suite, a table which has endpoint telemetry, and I have a table which has DNS telemetry. I can write a query that says, 'Join all these things together on IP, and where the IP matches in all these tables, return to me that subset of data, within these time windows.' I can break it down that way."
"The most valuable feature is that it has native MSSP capabilities and maintains perfect data separation. It does all of that in a very easy-to-manage cloud-based solution."
"But from a SaaS standpoint, if not best-in-breed, Devo is certainly in the top-two or top-three."
"Devo's speed and performance allows us to query in real-time and keep up with what is actually happening on the network, then respond effectively to events."
"The most valuable feature is definitely the ability that Devo has to ingest data. From the previous SIEM that I came from and helped my company administer, it really was the type of system where data was parsed on ingest. This meant that if you didn't build the parser efficiently or correctly, sometimes that would bring the system to its knees. You'd have a backlog of processing the logs as it was ingesting them."
"Being able to build and modify dashboards on the fly with Activeboards streamlines my analyst time because my analysts aren't doing it across spreadsheets or five different tools to try to build a timeline out themselves. They can just ingest it all, build a timeline out across all the logging, and all the different information sources in one dashboard. So, it's a huge time saver. It also has the accuracy of being able to look at all those data sources in one view. The log analysis, which would take 40 hours, we can probably get through it in about five to eight hours using Devo."
 

Cons

"It's not easy for everyone."
"In logging, I would prefer if Chronosphere could do something in the way of a dictionary or a JSON lookup kind of logging, which would be much easier in terms of directly searching for a particular keyword rather than a string match."
"Sometimes when identifying the specific logs patterns and identifying what metrics and what logs are coming in, going to a specific log explorer and finding it there is a little difficult."
"Where Devo has room for improvement is the data ingestion and parsing. We tend to have to work with the Devo support team to bring on and ingest new sources of data."
"One improvement area for Devo could be simplifying some configuration and improving the onboarding for new analysts because it is quite complex for fresher or new analysts who are handling Devo."
"There's always room to reduce the learning curve over how to deal with events and machine data. They could make the machine data simpler."
"From our experience, the Devo agent needs some work. They built it on top of OS Query's open-source framework. It seems like it wasn't tuned properly to handle a large volume of Windows event logs. In our experience, there would definitely be some room for improvement. A lot of SIEMs on the market have their own agent infrastructure. I think Devo's working towards that, but I think that it needs some improvement as far as keeping up with high-volume environments."
"The Activeboards feature is not as mature regarding the look and feel."
"We only use the core functionality and one of the reasons for this is that their security operation center needs improvement."
"An admin who is trying to audit user activity usually cannot go beyond a day in the UI. I would like to have access to pages and pages of that data, going back as far as the storage we have, so I could look at every command or search or deletion or anything that a user has run. As an admin, that would really help. Going back just a day in the UI is not going to help, and that means I have to find a different way to do that."
"Technical support could be better."
 

Pricing and Cost Advice

Information not available
"Devo is definitely cheaper than Splunk. There's no doubt about that. The value from Devo is good. It's definitely more valuable to me than QRadar or LogRhythm or any of the old, traditional SIEMs."
"Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
"[Devo was] in the ballpark with at least a couple of the other front-runners that we were looking at. Devo is a good value and, given the quality of the product, I would expect to pay more."
"Pricing is based on the number of gigabytes of ingestion by volume, and it's on a 30-day average. If you go over one day, that's not a big deal as long as the average is what you expected it to be."
"We have an OEM agreement with Devo. It is very similar to the standard licensing agreement because we are charged in the same way as any other customer, e.g., we use the backroom."
"I rate the pricing a four on a scale of one to ten, where one is cheap, and ten is expensive."
"I like the pricing very much. They keep it simple. It is a single price based on data ingested, and they do it on an average. If you get a spike of data that flows in, they will not stick it to you or charge you for that. They are very fair about that."
"Be cautious of metadata inclusion for log types in pricing, as there are some "gotchas" with that."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
914,322 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Transportation Company
12%
Outsourcing Company
9%
Financial Services Firm
9%
Financial Services Firm
13%
Outsourcing Company
11%
Construction Company
10%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise6
Large Enterprise12
 

Questions from the Community

What needs improvement with Chronosphere?
In logging, I would prefer if Chronosphere could do something in the way of a dictionary or a JSON lookup kind of logging, which would be much easier in terms of directly searching for a particular...
What is your primary use case for Chronosphere?
My main use case for Chronosphere is logging, metrics, traceability, and raising alerts. A specific example of how I use Chronosphere for logging metrics or raising alerts is that we had a free int...
What advice do you have for others considering Chronosphere?
My advice to others looking into using Chronosphere is to go ahead for it. I gave Chronosphere a rating of 8 out of 10.
What needs improvement with Devo?
Perhaps Devo could add some features in the future on the network part. Specifically, I think they could improve network traffic analysis capabilities.
What is your primary use case for Devo?
I have been using Devo as a partner and system integrator for three years. For log monitoring, the clients' use cases can utilize Devo perfectly. Compliance and security operation monitoring are th...
 

Comparisons

 

Overview

 

Sample Customers

Information Not Available
United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Find out what your peers are saying about Chronosphere vs. Devo and other solutions. Updated: September 2026.
914,322 professionals have used our research since 2012.