Most Helpful Review
Identifies threats that would not have otherwise been identified, but needs better integration with ServiceNow
We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
When we were looking for products for our security monitoring needs, our biggest requirement was that we wanted something based on machine-learning and analytics. If you go with rules, it can raise a lot of noise. Securonix, with its UEBA capability, had the best analytics use-cases.
The machine-learning algorithms are the most valuable feature because they're able to identify the 'needle in the haystack.'
The feature that is most valuable is the fact that it's an open platform, so it allows us to modify policies and tune policies as needed. There's also a feature called Data Insights which allows us to create different dashboards on specific things of interest for us.
What I like most is that the threat models and risk scoring are very accurate and very helpful to the analysts on my team. They help highlight the most important things for them to look at.
The second feature is that within the SNYPR product there is a functionality called Spotter. We use that for link analysis diagrams and to run the stats command. That's extremely useful because it replaces a tedious, manual process we used to use, using Microsoft Excel and a couple of other methods, to bring data together.
The customizability of the tool is valuable. We are able to customize the use cases and create them easily without a large amount of Securonix assistance. It's very flexible. We do not have to rely on Professional Services to modify or create a new use case.
One of the most valuable features it has is the thread chaining. One of the common issues that we always had was the number of anomalies that we used to get and the number of alerts that we used to get. But with this approach of thread chaining, we've found the false-positive rate has decreased very significantly. That was something that we never could have achieved before.
The most valuable feature is being able to look at users' behavioral profiles to see what they typically access. One of the key events that we monitor is people's downloading of objects... It's very easy to see people's patterns, what they typically do.
We are able to diagnose problems before our customers.
It helps a lot because we can troubleshoot issues pretty easily.
We have used it many times to find a root cause of a live issue, then fix the problem in the applications.
Support has been excellent. Sumo Logic's support staff is really good, both their account management staff and direct support.
It provides easy visibility. I also like the shareable queries because we share a lot across groups.
For many of our services, we use Sumo Logic to track errors and send notifications to our Slack channel, if there are issues. Then, we have our support people monitoring this, and they can react quickly.
Scalability has been good for our needs. We haven't run into any scaling issues in regards to size so far.
I have no concerns about the stability of the product. I feel it handles the stress we put on it very well.
We have compliance needs. We have investigation needs. And we have situations where an analyst needs to look at threats. These three things require a different view of how they look at the threats. What would be good is to have Securonix create three different views of their Security Command Center so that, depending on the persona of the person logging in, they'd get the relevant data they need and not see everything.
There is room for improvement in the product's integration with ServiceNow and in the reporting features.
Securonix implements risk scores based on different policies that are triggered. We've seen some challenges with the risk scores and how they trigger. These are things that Securonix has recognized and they've been working with us to help improve things.
A helpful feature would be an event export. A way to create more substantial summary reports would be nice.
Other than issues with the training, there have been issues with the encryption. There have also been issues with some of the reporting, minor glitches that they have fixed as they've gone along.
One of the things they can improve on a little bit is the usability side, to make some things simpler... The tool does have a lot of knobs, you can turn a lot of things on and off and you can change things. Sometimes, it can become a little overwhelming. They should remove some confirmation options and make it simpler for the less mature customers and people who are still trying to grasp it.
We have a lot of users who, because they're engineers and they're bringing down product data - where, at times, a top-level product could be 10,000 or 15,000 objects - it's difficult for us to determine what should be a concern and what shouldn't be a concern. We work with the Securonix folks to try to come up with better ways to identify that.
There are some API gaps that are missing.
We would like to have some type of predefined setup for the logs, making the setup easier by default.
We would like the ability to drill down into a dashboard and get into deeper levels.
There needs to be improvement on imported data which can be used within Sumo Logic to do more advanced queries.
I would like better UI-driven functionality to create alerts and reports. Now, we have to understand the syntax, so it is a little difficult for someone to pick it up without using the manuals. If there was more of a graphical user interface, it would be beneficial.
It would be nice to have an improved ability to scroll through logs within a time frame. Right now, we can search for specific errors. However, if we want to look for "before and after" within a specific time frame, it's not easy using the tool. This would be an improvement.
It took a bit of trial and error to get it set up correctly based on everything we had to do. In the end, we had to send everything over HTTP, which was sort of a stop-gap.
If you want to up your subscription through the AWS Marketplace, it can be difficult. You can't just go back to the AWS Marketplace, and say, "I want a bigger one now." You have to contact the sales team, then they do it on the back-end. This could definitely be improved.
Pricing and Cost Advice
A good thing about Securonix is that they don't charge by volume of data or number of devices... They charge by the number of employees, which is a much more predictable number for me, versus data. Our costs are in the $100,000 range over a three-year subscription.
We have an annual license. We pay $200,000 for the base licensing and we pay another $50,000 for the software as a service.
We have a license from our 5.0, so that license just continued. We paid them the extra cloud-hosting costs for a year which were about $300,000.
We went in on a three-year agreement which has an annual licensing fee, based upon the number of people that we're monitoring. There have not been any additional costs to the standard licensing fees.
The AWS Marketplace pricing is borderline. Every annual renewal, we always contemplate if we are getting what we think we could out of it or could we do it cheaper with some other product.
The pricing is a little high, but for the features that we receive from Sumo Logic, it suits the price. For some small organizations, the price might be a little high.
I don't pay the bill. I've heard the AWS Marketplace pricing is high, but I like the value.
Pricing has been cheaper than some of the competing tools, like Splunk.
If we went to ELK Stack, which is open source, it would have been less costly, but it would have required more development from our side.
The only limit to the scalability of the product for us is how much we are willing to pay.
The price scaling comes in a bit expensive.
Purchasing the solution through the AWS Marketplace is very easy.
out of 42 in Security Information and Event Management (SIEM)
Average Words per Review
out of 44 in Log Management
Average Words per Review
Compared 21% of the time.
Compared 15% of the time.
Compared 11% of the time.
Compared 12% of the time.
Compared 11% of the time.
Compared 9% of the time.
Also Known As
|Securonix Solutions||Sumo Logic|
SNYPR is a next-generation security analytics platform that transforms big data into actionable security intelligence. Built on a Hadoop big data security lake, SNYPR combines an open data model, log management, security incident and event management (SIEM), user and entity behavior analytics (UEBA) and fraud detection into a complete, end-to-end platform that can be deployed in its entirety or in flexible, modular components.
|Sumo Logic simplifies how you collect and analyze machine data so that you can gain deep visibility across your full application and infrastructure stack. With the Sumo Logic service, you can accelerate modern application delivery, monitor and troubleshoot in real time and improve your security and compliance posture.|
Learn more about Securonix Security Analytics
Learn more about Sumo Logic
|Dtex SystemsPfizerWestern UnionHarrisITG||Ooyala, Webjet, Akamai, Kaiser Permanente, Alaska Airlines, Hotel Tonight, Dollar Shave Club, Interactive Intelligence, Restoration Hardware, RingCentral, WD-40, Zillow, Sage Software, Tunein Radio, Lookout, Infor, Houzz, Estee Lauder, Brightcove, Actelion, Anki, Elance, Voxer, Cytobank, Medicom Health Interactive, Task Rabbit, Zscaler, Thred Up, Netskope, Tobi, Infoblox, Imperva, Okta, Medallia, RelateIQ, Bazaar Voice, Blurb, Guidewire, Apigee, Swipely, Progress Software, Card Spring, Ubiquiti Networks, Pager Duty, McGraw Hill, Acquia, Limelight Networks, Blucora, Scripps Networks Interactive, Orange, Medidata, 3 Share|
Software R&D Company24%
Comms Service Provider16%
Financial Services Firm11%
Software R&D Company22%
Financial Services Firm10%
See also Securonix Security Analytics Reviews, Sumo Logic Reviews, and our list of Best Security Information and Event Management (SIEM) Companies.