No more typing reviews! Try our Samantha, our new voice AI agent.

Devo vs Graylog Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Devo
Ranking in Security Information and Event Management (SIEM)
18th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
26
Ranking in other categories
Log Management (18th), IT Operations Analytics (7th), AIOps (13th)
Graylog Security
Ranking in Security Information and Event Management (SIEM)
61st
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Devo is 1.2%, up from 1.1% compared to the previous year. The mindshare of Graylog Security is 0.5%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Devo1.2%
Graylog Security0.5%
Other98.3%
Security Information and Event Management (SIEM)
 

Featured Reviews

Usama Khan - PeerSpot reviewer
Team Lead SOC at a tech services company with 51-200 employees
Advanced threat hunting has improved SOC visibility and now supports faster incident response
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM is basically on the AWS cloud. There are specific ports which are enabled on the relay server, which are 514 and 13000, 13151, 152. However, when we talk about databases and custom integrations, there are not default ports in the relay server. No default ports are defined. For JDBC drivers, the port number is 1433, but it is not in the relay server. You have to add it manually. For Oracle RDBMS, the port is 1521, and it is also not there by default. I would appreciate more third-party integrations including Fortinet and others. Machine learning models can also be improved. Playbooks in the SOAR can also be improved. Regarding playbooks for automation, we utilize playbooks for automation in SOAR for automated IOC blocking on a firewall, on a web application firewall, on DNS security, etc. The only option for us to run the playbook is to schedule the job for it. However, if I want to manually run the playbook, there is no option for doing so. This needs improvement.
Tony Zafiropoulos - PeerSpot reviewer
Owner/ Chief Engineer at Fixvirus.com
Aggregates logs in one place and helps to review data points
We tried Graylog Security, starting with their inexpensive open-source version. We tested it out and continued using it for a while. As for the main differences between Graylog Security and other vendors, some users might prefer cloud-based platforms over on-premises solutions. It isn't inherently cloud-native, but that might not matter much for some.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The querying and the log-retention capabilities are pretty powerful. Those provide some of the biggest value-add for us."
"The most valuable feature is definitely the ability that Devo has to ingest data. From the previous SIEM that I came from and helped my company administer, it really was the type of system where data was parsed on ingest. This meant that if you didn't build the parser efficiently or correctly, sometimes that would bring the system to its knees. You'd have a backlog of processing the logs as it was ingesting them."
"It's a core tool for us in looking at logs, because logs are the starting point in any investigation, so leveraging Devo from start to finish in any investigation is basically what we do."
"The user interface is really modern. As an end-user, there are a lot of possibilities to tailor the platform to your needs, and that can be done without needing much support from Devo. It's really flexible and modular. The UI is very clean."
"Those 400 days of hot data mean that people can look for trends and at what happened in the past. And they can not only do so from a security point of view, but even for operational use cases. In the past, our operational norm was to keep live data for only 30 days. Our users were constantly asking us for at least 90 days, and we really couldn't even do that. That's one reason that having 400 days of live data is pretty huge. As our users start to use it and adopt this system, we expect people to be able to do those long-term analytics."
"But from a SaaS standpoint, if not best-in-breed, Devo is certainly in the top-two or top-three."
"Having one integrated tool helped us by removing the multiple teams, multiple pieces of equipment, and multiple software solutions from the equation."
"The most useful feature for us, because of some of the issues we had previously, was the simplicity of log integrations. It's much easier with this platform to integrate log sources that might not have standard logging and things like that."
"We use the solution to collect logs."
"The tool aggregates logs. We can see the logs in one place."
 

Cons

"Some basic reporting mechanisms have room for improvement."
"The overall performance of extraction could be a lot faster, but that's a common problem in this space in general. Also, the stock or default alerting and detecting options could definitely be broader and more all-encompassing. The fact that they're not is why we had to write all our own alerts."
"My opinion on the solution's technical support is not as great as it could be because of the issues I have faced regarding the service management element."
"There's room for improvement within the GUI. There is also some room for improvement within the native parsers they support. But I can say that about pretty much any solution in this space."
"The biggest area with room for improvement in Devo is the Security Operations module that just isn't there yet. That goes back to building out how they're going to do content and larger correlation and aggregation of data across multiple things, as well as natively ingesting CTI to create rule sets."
"We only use the core functionality and one of the reasons for this is that their security operation center needs improvement."
"There is room for improvement in the ability to parse different log types. I would go as far as to say the product is deficient in its ability to parse multiple, different log types, including logs from major vendors that are supported by competitors. Additionally, the time that it takes to turn around a supported parser for customers and common log source types, which are generally accepted standards in the industry, is not acceptable. This has impacted customer onboarding and customer relationships for us on multiple fronts."
"One major area for improvement for Devo... is to provide more capabilities around pre-built monitoring. They're working on integrations with different types of systems, but that integration needs to go beyond just onboarding to the platform. It needs to include applications, out-of-the-box, that immediately help people to start monitoring their systems. Such applications would include dashboards and alerts, and then people could customize them for their own needs so that they aren't starting from a blank slate."
"Graylog Security needs to incorporate security scorecards."
 

Pricing and Cost Advice

"It's a per gigabyte cost for ingestion of data. For every gigabyte that you ingest, it's whatever you negotiated your price for. Compared to other contracts that we've had for cloud providers, it's significantly less."
"Devo is definitely cheaper than Splunk. There's no doubt about that. The value from Devo is good. It's definitely more valuable to me than QRadar or LogRhythm or any of the old, traditional SIEMs."
"I'm not involved in the financial aspect, but I think the licensing costs are similar to other solutions. If all the solutions have a similar cost, Devo provides more for the money."
"[Devo was] in the ballpark with at least a couple of the other front-runners that we were looking at. Devo is a good value and, given the quality of the product, I would expect to pay more."
"Pricing is based on the number of gigabytes of ingestion by volume, and it's on a 30-day average. If you go over one day, that's not a big deal as long as the average is what you expected it to be."
"Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
"Our licensing fees are billed annually and per terabyte."
"Be cautious of metadata inclusion for log types in pricing, as there are some "gotchas" with that."
"I rate the tool's pricing a one out of ten."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
10%
Outsourcing Company
9%
Manufacturing Company
9%
Educational Organization
13%
Comms Service Provider
10%
Retailer
8%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise5
Large Enterprise12
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Devo?
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps. Its licensing model is basically on per-day ...
What needs improvement with Devo?
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM ...
What is your primary use case for Devo?
I am using Devo myself. Basically, I work at an MSSP, and we provide services to the organization for Security Operation Centers. In our Security Operation Center, we provide the service of SIEM vi...
Ask a question
Earn 20 points
 

Comparisons

 

Overview

 

Sample Customers

United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Information Not Available
Find out what your peers are saying about Devo vs. Graylog Security and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.