We performed a comparison between ArcSight Logger and Graylog based on real PeerSpot user reviews.
Find out in this report how the two Log Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."In our country we are a little bit private in terms of solutions, so we are just starting to use the basic data capture. Now some users can start to use additional features that come with Micro Focus ArcSight like user behavior analytics for investigating."
"We haven't had any crashes or bugs. It is stable."
"The machine learning is a good feature."
"It's an efficient solution."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"The log digestion features from threat intelligence platforms like Recorded Future or Talos are valuable."
"The solution provides information about the risk factors."
"The ability to customize the solution in great detail is its most valuable features. We can customize the use cases and also have the ability to do scripting. We can personalize our dashboard as well. The scalability the solution offers is quite impressive."
"UDP is a fast and lightweight protocol, perfect for sending large volumes of logs with minimal overhead."
"We're using the Community edition, but I know that it has really good dashboarding and alerts."
"One of the most valuable features is that you are able to do a very detailed search through the log messages in the overview."
"I am very proud of how very stable the solution is."
"The product is scalable. The solution is stable."
"This had increased productivity for the dev and support teams, because we are directly notifying them."
"Allowing us to set up alerts and integrate with platforms we already use, such as Slack and OpsGenie to alert users of these errors proactively, is also a very useful feature."
"The best feature of Graylog is the Elasticsearch integration. We can integrate and we can run filters, such as an event of interest, and those logs we can send to any SIEM tool or as an analytic. Additionally, there are clear and well-documented implementation instructions on their website to follow if needed."
"I would like to see better scheduling in the next release of this solution."
"The console in older versions is not user-friendly."
"In the next release, I want to see more intelligence."
"The platform is quite expensive. They should reduce its cost."
"ArcSight has been sold two or three times, and the quality has decreased."
"The solution could be improved in maintenance settings."
"The initial setup was a little bit complex."
"I would rate the technical support only 5 out of 10. The technical support is not satisfactory."
"It would be great if Graylog could provide a better Python package in order to make it easier to use for the Python community."
"We ran into problems with Elasticsearch throwing a circuit-breaking exception due to field data size being too large. It turned out that the heap size directly impacted this size in a high-throughput environment, causing unexplained instability in Graylog. We were able to troubleshoot on the Elasticsearch size, but we should have been able to reference some minimum requirements for Graylog to know that our settings weren't sufficient."
"Graylog needs to improve their authentication. Also, the fact that Graylog displays logs from the top down is just ridiculous."
"I would like to see some kind of visualization included in Graylog."
"I would like to see a date and time in the Graylog Grok patterns so that I can save time when searching for a log. I like how the streams and the search query work, but adding a date and time will allow me to pull out a log in a milli-second."
"Dashboards, stream alerts and parsing could be improved."
"Elasticsearch recommendations for tuning could be better. Graylog doesn't have direct support for running the system inside of Kubernetes, so it can be challenging to fill in the gaps and set up containers in a way that is both performant and stable."
"Graylog can improve the index rotation as it's quite a complex solution."
ArcSight Logger is ranked 28th in Log Management with 31 reviews while Graylog is ranked 11th in Log Management with 18 reviews. ArcSight Logger is rated 7.8, while Graylog is rated 8.0. The top reviewer of ArcSight Logger writes "A scalable and stable solution that enables users to see all the event logs in one place". On the other hand, the top reviewer of Graylog writes "Great detailed search features and easy Java integration, but needs improvement in integration with Python". ArcSight Logger is most compared with Splunk Enterprise Security, IBM Security QRadar, Elastic Security and Wazuh, whereas Graylog is most compared with Grafana Loki, Wazuh, syslog-ng, Fortinet FortiAnalyzer and Splunk Enterprise Security. See our ArcSight Logger vs. Graylog report.
See our list of best Log Management vendors.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.