Bridgecrew Room for Improvement
Any solution would have its pros and cons, however, for the most part, it would come down to specific environments. For those considering purchasing the thing that I would try to avoid is buying it just for its name. I know people do that specifically, however, if you are going in thinking "Hey, I've got some random environment, let me just go and buy this solution and it will work perfectly" you will be disappointed. The solutions themselves have to be architected or actually designed in there as opposed to just placed.
The biggest issue that I see companies run into is that they immediately think that, "Oh, this solution will be right, simply due to the name." But that's the same issue Splunk runs into. People will immediately jump to Splunk being the best SIEM tool, just because they're the largest. When in reality, QRadar, LogRhythm, and all these other ones are performing similar functions and would actually fit better in some people's environments. Therefore, it's important a company does its homework and does not assume one size fits all. Everyone needs to make sure that this actually works in the environment before just purchasing it.