When comparing Rocana vs Snare, the Slant community recommends Rocana for most people. In the question“What are the best log management, aggregation & monitoring tools?” Rocana is ranked 15th while Snare is ranked 44th. The most important reason people chose Rocana is:
Beyond simple rules-based alerting, Rocana Ops creates statistical models for each of the metrics you want to track and evaluates as data streams in to provide nearly instantaneous feedback on how your systems are performing. Unique WARN (Weighted Analytic Risk Notifications) Scores indicate components that are trending to the good or bad. Users can create custom metrics, which get evaluated just the same as "out-of-the-box" metrics.
Ranked in these QuestionsQuestion Ranking
Pros
Pro Great "out-of-the-box" analytics
Beyond simple rules-based alerting, Rocana Ops creates statistical models for each of the metrics you want to track and evaluates as data streams in to provide nearly instantaneous feedback on how your systems are performing. Unique WARN (Weighted Analytic Risk Notifications) Scores indicate components that are trending to the good or bad. Users can create custom metrics, which get evaluated just the same as "out-of-the-box" metrics.
Pro Highly scalable
Collect and analyze multiple TBs of data per day, built on Hadoop components Rocana Ops is a highly-distributed system offering massive scalability using commodity hardware. Rocana has customers collecting 10+ TBs of log data per day.
Rocana One free option provides up to 1TB of daily data volume for free.
Pro Offered as a Cloud Service
Snare have hosted servers in most AWS locations.
Pro Uses Elastic Search as its Data Warehouse
Elasticsearch is recommended as a leader in its space handling high volumes of data.
Pro Full Log Analytics
All your log data, regardless of your log agent vendor can now be analysed through the web-based Dashboard.
Cons
Con Expensive
Appears to be an expensive solution.
Con Doesn't run on a laptop
Well, maybe you can squeeze Rocana Ops on a laptop, but it is designed as a highly-distributed, fault-tolerant system and requires a Hadoop distro as the underlying platform.