Ranked in these QuestionsQuestion Ranking
Pro In the Cloud, On-premise, or Hybrid
Free updates; you don't get stuck on older versions.
Pro More affordable
Cheaper than ArcSight, McAfee, QRadar, and LogRhythm.
Correlation happens at ingestion time, with results seen in 10-20 seconds.
Based on Elasticsearch, speed is variable on demand
Pro Faster Results
Fastest correlation in its class means that you see that dashboards update with logs immediately.