No more typing reviews! Try our Samantha, our new voice AI agent.

Devo vs Graylog Enterprise comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 15, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Devo
Ranking in Log Management
17th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
27
Ranking in other categories
Security Information and Event Management (SIEM) (17th), IT Operations Analytics (7th), AIOps (16th)
Graylog Enterprise
Ranking in Log Management
7th
Average Rating
8.0
Reviews Sentiment
5.8
Number of Reviews
25
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Log Management category, the mindshare of Devo is 1.4%, up from 0.7% compared to the previous year. The mindshare of Graylog Enterprise is 2.3%, down from 6.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Graylog Enterprise2.3%
Devo1.4%
Other96.3%
Log Management
 

Featured Reviews

Usama Khan - PeerSpot reviewer
Team Lead Soc at a tech services company with 51-200 employees
Advanced threat hunting has improved SOC visibility and now supports faster incident response
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM is basically on the AWS cloud. There are specific ports which are enabled on the relay server, which are 514 and 13000, 13151, 152. However, when we talk about databases and custom integrations, there are not default ports in the relay server. No default ports are defined. For JDBC drivers, the port number is 1433, but it is not in the relay server. You have to add it manually. For Oracle RDBMS, the port is 1521, and it is also not there by default. I would appreciate more third-party integrations including Fortinet and others. Machine learning models can also be improved. Playbooks in the SOAR can also be improved. Regarding playbooks for automation, we utilize playbooks for automation in SOAR for automated IOC blocking on a firewall, on a web application firewall, on DNS security, etc. The only option for us to run the playbook is to schedule the job for it. However, if I want to manually run the playbook, there is no option for doing so. This needs improvement.
NC
Security Officer at JSC "Moldtelecom" S.A.
Log analysis has become clearer and faster but visualization and extensibility still need work
The problem was with the complexity and the cost to add extensions. We found this very expensive to buy another version with additional features. I think that Graylog Enterprise does not have customizable dashboards. I did not see them in Graylog Enterprise because most of the time we used the open source free version, which is limited. I think Graylog Enterprise should improve some things that they have in the paid version and perhaps provide users with a menu that gives examples of parsing logs and draws graphics so that people do not need to improve another system such as Grafana. This would be interesting. When it comes to functionalities, I found the log management in Graylog Enterprise acceptable. It is very simple to use and to collect logs. It has support for different protocols and different ports, and the sidecar is easy to use. However, in visualization, I think it needs to be much better.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The alerting is much better than I anticipated. We don't get as many alerts as I thought we would, but that nobody's fault, it's just the way it is."
"The features I find most valuable in Devo are that it works on unstructured data."
"It's a core tool for us in looking at logs, because logs are the starting point in any investigation, so leveraging Devo from start to finish in any investigation is basically what we do."
"Having one integrated tool helped us by removing the multiple teams, multiple pieces of equipment, and multiple software solutions from the equation."
"It centralizes security management within a business, functioning as a core system for a SOC."
"The user interface is really modern. As an end-user, there are a lot of possibilities to tailor the platform to your needs, and that can be done without needing much support from Devo. It's really flexible and modular. The UI is very clean."
"Devo helps us to unlock the full power of our data because they have more than 450 parsers, which means that we can ingest pretty much any type of log data."
"It's very, very versatile."
"It has data adapters and lookup tables that utilize HTTP calls to APIs."
"The build is stable and requires little maintenance, even compared to some extremely expensive products."
"We're using the Community edition, but I know that it has really good dashboarding and alerts."
"Storing logs in Elasticsearch means log retrieval is extremely fast, and full text search is available by default."
"I like the correlation and the alerting."
"The product is scalable. The solution is stable."
"I know that there are other similar tools available, but I enjoy using Graylog the most."
"Open source and user friendly."
 

Cons

"Where Devo has room for improvement is the data ingestion and parsing. We tend to have to work with the Devo support team to bring on and ingest new sources of data."
"The Activeboards feature is not as mature regarding the look and feel. Its functionality is mature, but the look and feel is not there. For example, if you have some data sets and are trying to get some graphics, you cannot change anything. There's just one format for the graphics. You cannot change the size of the font, the font itself, etc."
"From our experience, the Devo agent needs some work. They built it on top of OS Query's open-source framework. It seems like it wasn't tuned properly to handle a large volume of Windows event logs. In our experience, there would definitely be some room for improvement. A lot of SIEMs on the market have their own agent infrastructure. I think Devo's working towards that, but I think that it needs some improvement as far as keeping up with high-volume environments."
"Some basic reporting mechanisms have room for improvement. Customers can do analysis by building Activeboards, Devo’s name for interactive dashboards. This capability is quite nice, but it is not a reporting engine. Devo does provide mechanisms to allow third-party tools to query data via their API, which is great. However, a lot of folks like or want a reporting engine, per se, and Devo simply doesn't have that. This may or may not be by design."
"Devo has a lot of cloud connectors, but they need to do a little bit of work there. They've got good integrations with the public cloud, but there are a lot of cloud SaaS systems that they still need to work with on integrations, such as Salesforce and other SaaS providers where we need to get access logs."
"I would like to have the ability to create more complex dashboards."
"Their documentation could be better. They are growing quickly and need to have someone focused on tech writing to ensure that all the different updates, how to use them, and all the new features and functionality are properly documented."
"However, the incident and threat detection is not what we had hoped for."
"The documentation for Graylog Enterprise can be improved, as this has been a pain point."
"The support from the Graylog community is helpful, but they can do better."
"The initial setup was really complex because I did it myself."
"I would rate them as a two out of 10. You are on your own without an enterprise license."
"I would like to see some kind of visualization included in Graylog. The report is plain, they could be improved."
"If you have a whole team trying to fix the Graylog instance for two days, that's a bit too much."
"Its scalability gets complicated when we have to update or edit multiple nodes."
"Graylog could improve the process of creating rules. We have to create them manually by doing parses and applying them. Other SIEM solutions have basic rules and you can create and get more events of interest."
 

Pricing and Cost Advice

"Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
"I like the pricing very much. They keep it simple. It is a single price based on data ingested, and they do it on an average. If you get a spike of data that flows in, they will not stick it to you or charge you for that. They are very fair about that."
"Devo is definitely cheaper than Splunk. There's no doubt about that. The value from Devo is good. It's definitely more valuable to me than QRadar or LogRhythm or any of the old, traditional SIEMs."
"Pricing is based on the number of gigabytes of ingestion by volume, and it's on a 30-day average. If you go over one day, that's not a big deal as long as the average is what you expected it to be."
"We have an OEM agreement with Devo. It is very similar to the standard licensing agreement because we are charged in the same way as any other customer, e.g., we use the backroom."
"Our licensing fees are billed annually and per terabyte."
"Devo is a hosted or subscription-based solution, whereas before, we purchased QRadar, so we owned it and just had to pay a maintenance fee. We've encountered this with some other products, too, where we went over to subscription-based. Our thought process is that with subscription based, the provider hosts and maintains the tool, and it's offsite. That comes with some additional fees, but we were able to convince our upper management it was worth the price. We used to pay under 10k a year for maintenance, and now we're paying ten times that. It was a relatively tough sell to our management, but I wonder if we have a choice anymore; this is where the market is."
"I rate the pricing a four on a scale of one to ten, where one is cheap, and ten is expensive."
"If you want something that works and do not have the money for Splunk or QRadar, take Graylog.​​"
"There is an open source version and an enterprise version. I wouldn't recommend the enterprise version, but as an open source solution, it is solid and works really well."
"We're using the Community edition."
"Consider Enterprise support if you have atypical needs or setup requirements.​"
"I use the free version of Graylog."
"Having paid official support is wise for projects."
"It's an open-source solution that can be used free of charge."
"We are using the free version of the product. However, the paid version is expensive."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Outsourcing Company
11%
Construction Company
10%
Manufacturing Company
9%
Comms Service Provider
11%
Computer Software Company
11%
Financial Services Firm
8%
University
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise6
Large Enterprise12
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise4
Large Enterprise11
 

Questions from the Community

What needs improvement with Devo?
Perhaps Devo could add some features in the future on the network part. Specifically, I think they could improve network traffic analysis capabilities.
What is your primary use case for Devo?
I have been using Devo as a partner and system integrator for three years. For log monitoring, the clients' use cases can utilize Devo perfectly. Compliance and security operation monitoring are th...
What is your experience regarding pricing and costs for Graylog?
I find the pricing, setup cost, and licensing of Graylog Enterprise to be somewhat expensive. However, it is cost-effective compared to other larger platforms. The pricing depends on factors such a...
What needs improvement with Graylog?
One improvement I want to see in Graylog Enterprise is artificial intelligence to help us automatically identify unusual patterns and suggest possible causes. I also want to see more ready-made das...
What is your primary use case for Graylog?
Graylog Enterprise serves as my main centralized log management solution. In our environment, we have many systems that generate logs, including servers, applications, network devices, and security...
 

Also Known As

No data available
Graylog2
 

Overview

 

Sample Customers

United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Blue Cross Blue Shield, eBay, Cisco, LinkedIn, SAP, King.com, Twilio, Deutsche Presse-Agentur
Find out what your peers are saying about Devo vs. Graylog Enterprise and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.