When comparing ODE vs Snare, the Slant community recommends ODE for most people. In the question“What are the best log management, aggregation & monitoring tools?” ODE is ranked 35th while Snare is ranked 44th. The most important reason people chose ODE is:
ODE instances are independent of each other, so they don't have to worry about a peer being added/removed. This allows the cluster to grow without any performance hit on the log aggregation. There is no redundancy built-in, but you can always use the forwarder to duplicate data. There is no sharding configuration or any other penalty that comes up with scaling a cluster. The clustering configuration is also very easy where you just list out peers for one of the node in order for it to run a search query on the whole cluster and merge the results. Scales better than any other open source log management tool out there.
Ranked in these QuestionsQuestion Ranking
Pros
Pro Scales easily
ODE instances are independent of each other, so they don't have to worry about a peer being added/removed. This allows the cluster to grow without any performance hit on the log aggregation. There is no redundancy built-in, but you can always use the forwarder to duplicate data. There is no sharding configuration or any other penalty that comes up with scaling a cluster. The clustering configuration is also very easy where you just list out peers for one of the node in order for it to run a search query on the whole cluster and merge the results. Scales better than any other open source log management tool out there.
Pro Add new parsers as you like
You can add any parser you want to ODE.
Pro Highly customizable
Pro Easy to use
Pro Offered as a Cloud Service
Snare have hosted servers in most AWS locations.
Pro Uses Elastic Search as its Data Warehouse
Elasticsearch is recommended as a leader in its space handling high volumes of data.
Pro Full Log Analytics
All your log data, regardless of your log agent vendor can now be analysed through the web-based Dashboard.
Cons
Con Still in beta
Opallios ODE seems to be still in beta, as such there may be issues or missing features which are not yet implemented.