

CrowdStrike Falcon Insight XDR and Devo are competitors in the cybersecurity solutions market, particularly in endpoint protection and data analytics, respectively. CrowdStrike Falcon Insight XDR appears to have an edge in rapid threat detection and isolation, while Devo offers extensive data analytics capabilities and customizable dashboards.
Features: CrowdStrike Falcon Insight XDR is equipped with endpoint detection and response, real-time threat alerts, and AI-driven threat detection while maintaining system performance with a lightweight agent. Devo distinguishes itself with comprehensive data analytics capabilities, real-time monitoring, and customizable dashboards, integrating with numerous data sources to enhance threat intelligence analysis.
Room for Improvement: CrowdStrike Falcon Insight XDR could enhance its dashboard and reporting capabilities to improve compliance reporting and reduce false positives. Users also call for more flexible dashboard customization and improved integration. Devo users suggest the need for better pre-built monitoring apps, integration with more cloud systems, and a streamlined interface for ease of use, as well as enhancements in service management and faster data ingestion processes.
Ease of Deployment and Customer Service: CrowdStrike offers versatile deployment options across on-premises and cloud environments, though some challenges with technical support responsiveness are reported. Devo, being cloud-based, ensures straightforward deployment and a clear licensing model, but users mention technical support responsiveness and onboarding as areas needing improvement.
Pricing and ROI: CrowdStrike Falcon Insight XDR, though efficient, is often considered costly, impacting accessibility for smaller businesses but is valued for reducing breach costs and resource allocation for maintenance. Devo offers competitive pricing based on data ingestion, emphasizing value for money with its analytics capabilities and extended data retention, providing a favorable return on investment according to users.
CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.
It's very easy to deploy without many IT admins, saving time.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
They could improve by initiating calls for high-priority cases instead of just opening tickets.
I rate the customer support a nine out of ten because of their timely technical guidance and responsiveness during the deployment and troubleshooting periods.
Both response time and support quality need attention.
It has adequate coverage and is easy to deploy.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.
Devo is a unified SIEM solution designed to handle growing log volumes and enterprise-scale monitoring requirements.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
The biggest issue occurred when every computer worldwide experienced a blue screen.
It is stable and reliable for our security operations.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Threat prevention should be their first priority.
This is particularly evident when dealing with failed login attempts and determining true versus false positives.
UI improvements, a simplified dashboard, or an easier reporting workflow could further improve analyst productivity.
I would appreciate more third-party integrations including Fortinet and others.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
The licensing cost and setup costs are affordable.
The solution is a bit expensive.
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Being an EDR solution, it helps us identify attacks in real-time.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
When the analyst uses queries to search, it pulls the data quickly, in a second, which aids us greatly with the investigation.
It utilizes 400 days of hot data, allowing queries to run very fast and yield results quicker than other tools in terms of security and SIEM capability.
| Product | Mindshare (%) |
|---|---|
| CrowdStrike Falcon | 2.7% |
| Devo | 1.2% |
| Other | 96.1% |


| Company Size | Count |
|---|---|
| Small Business | 54 |
| Midsize Enterprise | 34 |
| Large Enterprise | 63 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 5 |
| Large Enterprise | 12 |
CrowdStrike Falcon Insight XDR provides adversary-driven detection and response across endpoints and beyond. It combines AI-powered endpoint detection and response with integrated threat intelligence and expert context to deliver high-quality, context-rich detections that help security teams identify and prioritize sophisticated threats.
Automated leads and Charlotte AI, combined with attack-path visibility, adversary context and MITRE ATT&CK mappings, help analysts investigate incidents faster. Real Time Response and Falcon Fusion SOAR support direct and automated remediation at scale. Extend investigations with critical context from identity, cloud, mobile and data protection, while incorporating third-party data in the same console.
What are the key features of CrowdStrike Falcon?
What benefits and reported outcomes can organizations achieve?
In technology sectors, CrowdStrike Falcon commonly supports endpoint protection and threat response initiatives, allowing companies to replace traditional antivirus systems with more advanced solutions. In finance, it secures sensitive data across multiple platforms, ensuring compliance. In healthcare, real-time security analysis protects patient data on critical devices like servers and laptops, utilizing AI to enhance cybersecurity defenses.
Devo offers powerful visual analytics, real-time data querying, and log integration capabilities within a cloud-native, multi-tenant architecture, supporting extended data retention ideal for long-term analysis and compliance.
Devo is recognized for its Activeboards, which facilitate visual analytics. High-speed search capabilities and real-time analytics enable efficient data manipulation and querying. Its multi-tenant architecture supports effective data segregation and customization tailored to distinct business needs, enhancing its value for handling complex log integrations. With extended data retention of 400 days and a cloud-native architecture, Devo is a robust platform for long-term analysis and compliance requirements. Though opportunities exist to improve browser stability on large searches, SOAR integrations, and its parser capabilities, Devo remains essential for incident response and security monitoring, offering centralized data storage and analysis.
What are Devo's most important features?Devo is extensively used in industries focused on incident response and digital forensics, centralizing data for security monitoring across hybrid environments. Organizations benefit from its ability to store and analyze aggregated logs, creating alerts and dashboards to enhance visibility for network and endpoint activities in multi-domain settings.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.