

ArcSight Logger and Devo are leading log management solutions, each targeting different market needs. Devo often appears to have the edge with its advanced features, despite a higher cost, making it a preferred choice for many users.
Features: ArcSight Logger provides comprehensive data analysis, seamless integration with security tools, and scalability. Devo offers advanced analytics, real-time insights, and ease of use. ArcSight focuses on security integration, while Devo emphasizes analytical capabilities.
Room for Improvement: ArcSight Logger could improve scalability, query speed, and flexibility. Devo users seek better documentation, enhanced processing, and more ingestion options. Both products need adjustments to meet their users' evolving needs.
Ease of Deployment and Customer Service: ArcSight Logger is complex to deploy with mixed reviews on its support. Devo is noted for easy deployment and proactive service. ArcSight could streamline deployment, while Devo is strong in service delivery.
Pricing and ROI: ArcSight Logger is more affordable upfront, offering a reasonable ROI. Devo, though more expensive initially, justifies its cost through long-term value. ArcSight competes on cost, while Devo focuses on enhanced performance.
We provide pre-implementation, implementation, and post-implementation support.
Splunk does much more than SIEM, including log analysis, user behavior analysis, threat intelligence, and customer behavior analysis.
This is particularly evident when dealing with failed login attempts and determining true versus false positives.
ArcSight Logger installs on very minimal resources with very few requirements
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
| Product | Mindshare (%) |
|---|---|
| Devo | 1.2% |
| ArcSight Logger | 0.9% |
| Other | 97.9% |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 10 |
| Large Enterprise | 16 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 4 |
| Large Enterprise | 11 |
ArcSight Logger effectively manages vast log data volumes, streamlining complex query execution and data compression while supporting various devices to meet compliance needs.
ArcSight Logger, known for scalability, simplifies handling extensive log data and executes complex queries swiftly. Its data compression features, coupled with versatile device support, allow for smooth security analytics and log collection. Users appreciate its real-time network insights and intuitive interface. However, improvements are needed in indexing speed, user navigation simplification, enhanced system integration, advanced analytics, and comprehensive threat management. Companies leverage ArcSight Logger for on-premises log management, vital for IT asset event monitoring and compliance within telecom and enterprise sectors.
What are the key features?In industries like telecom and enterprise, ArcSight Logger facilitates on-premises deployments to manage logs, process queries, and integrate with security tools, essential for incident response. It aids in retaining logs, monitoring Windows events, overseeing communications, and is employed in fraud prevention and security monitoring involving syslog servers.
Devo offers powerful visual analytics, real-time data querying, and log integration capabilities within a cloud-native, multi-tenant architecture, supporting extended data retention ideal for long-term analysis and compliance.
Devo is recognized for its Activeboards, which facilitate visual analytics. High-speed search capabilities and real-time analytics enable efficient data manipulation and querying. Its multi-tenant architecture supports effective data segregation and customization tailored to distinct business needs, enhancing its value for handling complex log integrations. With extended data retention of 400 days and a cloud-native architecture, Devo is a robust platform for long-term analysis and compliance requirements. Though opportunities exist to improve browser stability on large searches, SOAR integrations, and its parser capabilities, Devo remains essential for incident response and security monitoring, offering centralized data storage and analysis.
What are Devo's most important features?Devo is extensively used in industries focused on incident response and digital forensics, centralizing data for security monitoring across hybrid environments. Organizations benefit from its ability to store and analyze aggregated logs, creating alerts and dashboards to enhance visibility for network and endpoint activities in multi-domain settings.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.