We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
"It's a per gigabyte cost for ingestion of data. For every gigabyte that you ingest, it's whatever you negotiated your price for. Compared to other contracts that we've had for cloud providers, it's significantly less."
"We have an OEM agreement with Devo. It is very similar to the standard licensing agreement because we are charged in the same way as any other customer, e.g., we use the backroom."
"I'm not involved in the financial aspect, but I think the licensing costs are similar to other solutions. If all the solutions have a similar cost, Devo provides more for the money."
"Devo is definitely cheaper than Splunk. There's no doubt about that. The value from Devo is good. It's definitely more valuable to me than QRadar or LogRhythm or any of the old, traditional SIEMs."
"[Devo was] in the ballpark with at least a couple of the other front-runners that we were looking at. Devo is a good value and, given the quality of the product, I would expect to pay more."
"Be cautious of metadata inclusion for log types in pricing, as there are some "gotchas" with that."
"Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
"Our licensing fees are billed annually and per terabyte."
"The price could be better. But I think it's rightly placed when we buy everything in one shot, and we get some discount for that. That's how we basically plan our deployment, and it's holistic. We pay for the license yearly."
"It could be cheaper, but that applies to every product."
Earn 20 points
Devo is the only cloud-native logging and security analytics platform that releases the full potential of all your data to empower bold, confident action when it matters most. Only the Devo platform delivers the powerful combination of real-time visibility, high-performance analytics, scalability, multitenancy, and low TCO crucial for monitoring and securing business operations as enterprises accelerate their shift to the cloud.
FireEye Helix is a cloud-hosted security operations platform that allows organizations to take control of any incident from alert to fix. Available with any FireEye solution, FireEye Helix integrates your security tools and augments them with next-generation SIEM, orchestration and threat intelligence capabilities to capture the untapped potential of security investments. Designed by security experts, for security experts, it empowers security teams to efficiently conduct primary functions, such as alert management, search, analysis, investigations and reporting.
SurfWatch threat intelligence solutions help drive the most effective defense. Delivering both strategic and operational threat intelligence, SurfWatch links actual threats to your business risk and helps you redirect your tactical defenses to focus on the most relevant and critical risks.
See how Devo allows you to free yourself from data management, and make machine data and insights accessible.
FireEye Helix is ranked 20th in Security Information and Event Management (SIEM) with 4 reviews while SurfWatch Labs SurfWatch is ranked 45th in Security Information and Event Management (SIEM). FireEye Helix is rated 8.8, while SurfWatch Labs SurfWatch is rated 0.0. The top reviewer of FireEye Helix writes "We can have an API connection with any cloud, the integration is very easy". On the other hand, FireEye Helix is most compared with Splunk, ServiceNow Security Operations, Azure Sentinel, IBM QRadar and Elastic SIEM, whereas SurfWatch Labs SurfWatch is most compared with McAfee ESM and ArcSight Enterprise Security Manager (ESM).
See our list of best Security Information and Event Management (SIEM) vendors.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.