Try our new research platform with insights from 80,000+ expert users

Cribl vs Panther comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cribl
Ranking in Security Information and Event Management (SIEM)
10th
Average Rating
8.4
Reviews Sentiment
6.4
Number of Reviews
17
Ranking in other categories
Application Performance Monitoring (APM) and Observability (13th), Log Management (7th), Observability Pipeline Software (1st)
Panther
Ranking in Security Information and Event Management (SIEM)
46th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cribl is 1.1%, up from 0.2% compared to the previous year. The mindshare of Panther is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Cribl1.1%
Panther0.4%
Other98.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

Abdullah Zubair - PeerSpot reviewer
Enables seamless SIEM/Data Migration and Log Filtration across the enterprise estate
They've already done many good things with the product, but perhaps they could implement a temporary SIEM solution where we could store logs and display them as a SIEM, though I think that's not the space that Cribl is actually looking into. Based on my experience, this product is brilliant and there isn't much or anything important lacking in the product. We encountered some occasional issues with the syslog data stream, particularly when handling large data volume, and getting it to parse and field extracted correctly, but no major alarms that would halt the days operation. There were few source vendor specific challenges, but overall, I didn't notice anything major beyond that. Most of the process went smoothly. However, we did need to carry some troubleshooting to resolve the issues we faced while connecting with other platforms and few data stream miss-behaving, which wasn't a straightforward task for us. In terms of large datasets—whether they originated from network inputs, virtual machines, or cloud instances—ingesting the data into the destination was relatively easy. In summary, aside from the usual difficulties or issues that someone could face with any project, everything else went well.
RT
Detection capabilities and helpful support team enhance log analysis and integration flexibility
I find Panther's detection capabilities and integrations to be highly valuable. It allows integration with anything as long as I am willing to write detections, and their team is very helpful. I find its log analysis capabilities valuable. It enables me to filter down to individual roles in AWS, and if I am skilled at SQL queries, I can query anything. The infrastructure as code feature allows me to use Git repositories to manage detections and import detections from other Git repositories.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cribl offers easy plugin configurations and source collection settings, allowing us to collect logs from any source."
"Cribl offers other valuable features. For instance, you can replay data from an edge device, store your daily data in a stream, and replay specific event data into Splunk if a security incident occurs"
"The support team was very helpful and managed to get everything production-ready."
"I'd rate the solution ten out of ten."
"My favorite option in Cribl is the Stream product."
"Cribl definitely helps with the complexity because you don't have to push for deployment—they provide the interface where you can mimic what the output will look like, and you can see that in real time when setting up the Cribl configuration, which definitely helps considerably."
"The product's most valuable features include the internal management of events, coding perspective, data processing, and serialization."
"Features such as Cribl Stream, Cribl LogStream, and Cribl Edge have been the most beneficial. The Cribl LogStream, in particular, is valuable for routing data, creating firewalls on pipelines, and putting security measures in place to ensure data reaches its destination without issues."
"I find Panther's detection capabilities and integrations to be highly valuable."
 

Cons

"We encountered some issues with the syslog data stream, particularly with handling large databases and extensive data logs."
"There have been several administrative issues. Another point is that the browsing functions aren't very intuitive."
"Cribl could improve by offering easier integrations with enterprise products, similar to what Splunk provides."
"Cribl could have developed some version that can give backward compatibility."
"Perhaps more flexibility in terms of metrics would be helpful."
"There is room for improvement in the documentation and knowledge base, particularly regarding configurations like sources where logs are being ingested"
"There is no alerting mechanism for the leader/worker nodes status."
"Cribl doesn't have as many packs available"
"The solution could be improved by providing more built-in integrations, which would reduce the need for me to build them myself."
 

Pricing and Cost Advice

"The product pricing is reasonable compared to other solutions."
"I would not say it is a cheaply priced tool as it has been doing wonders in the market. The tool has been budget-friendly for organizations."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
867,445 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
9%
Healthcare Company
7%
Manufacturing Company
7%
Manufacturing Company
16%
Computer Software Company
15%
University
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise6
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cribl?
I think the pricing for Cribl is reasonable. For large usage, but I heard the calculation of those credits is a bit complicated.
What needs improvement with Cribl?
So since we’re handling a ton of data, I think we could really benefit from a more integrated or connected way to manage it all. Like, if there is a way to better track data lineage, metadata, thos...
What is your primary use case for Cribl?
We use Cribl Stream to collect logs from multiple sources, transform and enrich them, filter out unnecessary data before sending them to SIEM. We also use Cribl to route logging to data lake.
What is your experience regarding pricing and costs for Panther?
I find the pricing to be reasonable, although I can't recall the exact cost.
What needs improvement with Panther?
The solution could be improved by providing more built-in integrations, which would reduce the need for me to build them myself.
What is your primary use case for Panther?
We use Panther ( /products/panther-reviews ) for our SIEM ( /categories/security-information-and-event-management-siem ) solution. It is used for aggregating logs and analyzing user activities. We ...
 

Comparisons

 

Overview

 

Sample Customers

Information Not Available
Docker, Loom, Discord, Dropbox, HubSpot, Asana, GoFundMe, Zapier, Benchling, JupiterOne, Jumio, Bitstamp, Intercom, Randori, and Cedar
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: August 2025.
867,445 professionals have used our research since 2012.