ELK Logstash Alternatives and Competitors

Get our free report covering Graylog, IBM, Splunk, and other competitors of ELK Logstash. Updated: January 2020.
389,772 professionals have used our research since 2012.

Read reviews of ELK Logstash alternatives and competitors

JayGrant
Real User
Manager of Security Services at OpenText
Jan 09 2020

What is most valuable?

The Activeboards are the most valuable feature. Given multiple different types of unstructured and structured data, we can then build Activeboards that can do queries… more»

How has it helped my organization?

Being able to build and modify dashboards on the fly with Activeboards streamlines my analyst time because my analysts aren't doing it across spreadsheets or five… more»

What needs improvement?

The only downfall that I have is it is browser based. So, when you start doing some larger searches, it will cause the browser to lock up or shut down. You have to learn… more»

What's my experience with pricing, setup cost, and licensing?

It's a per gigabyte cost for ingestion of data. For every gigabyte that you ingest, it's whatever you negotiated your price for. Compared to other contracts that we've had… more»

Which solution did I use previously and why did I switch?

I've used a ton of other solutions: ELK Stack, Kibana, and Splunk. The cost of Devo, as it relates to Splunk, is significantly less with higher value. Its capabilities of… more»

What other advice do I have?

Definitely get training and professional services hours with it. It is one of those tools where the more you know, the more you can do. Out-of-the-box, there is a lot of… more»

Which other solutions did I evaluate?

We have used everything out there. We have used Splunk, ArcSight, and LogRhythm. We've used all those tools. We have leveraged them from customer environments and used… more»
Reza Azimi
Real User
Infrastructure Engineer at a tech vendor with 201-500 employees
Sep 10 2019

What is most valuable?

We are using it because we have a VMware product. It has its own built-in dashboards for VMware products, and that's a good thing. Also, filtering logs is very easy and extracting fields from the data… more»

What needs improvement?

The solution is a very good tool, but it has a lot of limitations. One of the main issues is around how you define your retention policy, for instance. It doesn't have it. You can't define a log… more»

What's my experience with pricing, setup cost, and licensing?

We are not paying extra for the solution because it was part of our bundle. That was one of the reasons we used it. There was no extra cost for us.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

What other advice do I have?

I would rate the solution six or seven out of ten. It's very easy to use, but at the same time it has some limitations. You have to consider that if you decide to try out the solution.

Which other solutions did I evaluate?

We started using this product because we wanted to have something up and running. We are currently evaluating other products now, as well, even though we are continuing to use this solution. We are… more»
JasonCrow
Real User
Senior Architect at a tech vendor with 51-200 employees
Mar 04 2018

What is most valuable?

* Searching errors * Alerting through Slack and OpsGenie using their plugins. We run a containerized microservices environment. Being able to set up streams and search for errors and anomalies across… more»

What needs improvement?

Elasticsearch recommendations for tuning could be better. Graylog doesn't have direct support for running the system inside of Kubernetes, so it can be challenging to fill in the gaps and set up… more»

What's my experience with pricing, setup cost, and licensing?

We use the free version.

Which solution did I use previously and why did I switch?

Splunk, Logstash, and Elasticsearch.

What other advice do I have?

Make sure your Elasticsearch cluster is sized right, memory-wise.

Which other solutions did I evaluate?

Splunk, Logstash, and Elasticsearch.
Christopher Mooney
Real User
Incident Manager at a tech services company with 201-500 employees
Apr 25 2018

What is most valuable?

The ability to manipulate data in Splunk is unparalleled. Splunk’s powerful, flexible query language can morph difficult to understand log formats into usable data… more»

How has it helped my organization?

Log files which were previously either not reviewed or reviewed incompletely are now being used in operations daily. Security and operational events are discovered and… more»

What needs improvement?

There is a definite learning curve to starting out. However, there is quite a bit of documentation out there to help you get started.

What's my experience with pricing, setup cost, and licensing?

Truly evaluate the data you want to ingest and go slow. Pulling in data that can provide no use to your mission only wastes data against your license.

Which solution did I use previously and why did I switch?

We previously used ArcSight, but found Splunk to be more cloud capable.

What other advice do I have?

Pick it up and jump into the community! It can help get you started a lot faster.

Which other solutions did I evaluate?

Other options were evaluated, such as ELK, but Splunk was identified to be more feature rich out-of-the-box.
Get our free report covering Graylog, IBM, Splunk, and other competitors of ELK Logstash. Updated: January 2020.
389,772 professionals have used our research since 2012.