

Cribl and Falcon LogScale compete in the data management and log analysis market. Falcon LogScale generally has an advantage in speed and scalability, while Cribl excels in data flexibility and cost reduction.
Features: Cribl provides flexible data management and integration with multiple tools, significantly reducing log sizes and costs. It can handle high volumes of diverse data and offers advanced routing and processing capabilities. Falcon LogScale is known for its rapid search functionality and scalability, with exceptional data retention and retrieval speeds, and an effective query system.
Room for Improvement: Cribl could improve performance during large-scale data ingestion and enhance its documentation and certifications. Users want updated documentation and better troubleshooting dashboards. Falcon LogScale needs to simplify complex queries and integrate better with CrowdStrike resources to enhance user experience.
Ease of Deployment and Customer Service: Cribl supports on-premises, public cloud, and hybrid deployments, praised for its customer service despite some inconsistencies. Falcon LogScale focuses on public and hybrid cloud deployments and is well-regarded for its technical support, although response times could improve.
Pricing and ROI: Cribl is cost-effective, offering significant savings through data reduction. Its pricing is seen as fair but high, particularly benefiting larger data volumes. Falcon LogScale is moderately priced, with cost-effectiveness varying based on usage, though some users note concerns over pricing transparency.
What we've seen is really an overall reduction of just shy of 40% in our ingest into our SIM platform versus prior to having Cribl.
The second thing is that data aggregation, sampling, and reduction that we're able to do of the data, lowering our overall data volume, both traversing the network as well as what's being stored inside of our final solutions.
In terms of reduction, we were able to save almost ~40% of our total cost.
You save man hours, and man hours convert to business time and money time as well.
Falcon LogScale helps ease this process and sends logs to XDR for further verification.
I have definitely seen ROI with Falcon LogScale so far.
They had extensive expertise with the product and were able to facilitate everything we needed.
Usually, within an hour, we get a response, and we are able to work with them back and forth until we resolve the issues.
Sometimes by hearing the problem itself, they will know what the solution is, and they will let us know how to resolve it, and we do it immediately.
I would rate the customer support a 10 on a scale of one to 10.
I raised a customer support request, and in response, they released a new version with a fix for that problem.
The information contained in Falcon LogScale's documentation is very clear.
The infrastructure behind Cribl Search is also scalable as it uses a CPU and just spawns horizontally more instances as it demands and requires.
Compared to other SIEM tools I use, any slight change on the operating system end impacts a lot on our SIEM tools and other things, but Cribl performs well in that regard.
Cribl performs effectively across both market segments.
If there is a critical incident with an associated IP, associated user, endpoints, or whatever factor it is supposed to associate, it associates it by default and makes our life easier, making the SOC life easier.
You could integrate as many endpoints as you want within a fraction of seconds, and it accommodates the number of resources that you integrate with it while maintaining the same response time.
Easily supports thousands of endpoints and servers across multiple locations without heavy infrastructure.
Migrating from those SC4S servers to Cribl worker nodes has truly been a game-changer.
Regarding scalability, we started with zero servers and have around 285 servers now.
Cribl is designed to deal with certain kinds of loads and is not designed to handle any scenario in the market.
It uses an index-free architecture, it does not suffer from index corruption or the complications that other legacy tools face.
Falcon LogScale is very strong in real-time log search.
We did not have any problems with Falcon LogScale in terms of stability and reliability.
A more stringent role-based access control feature would enhance security and allow granular control over what users can see and access.
When passing query logs or DNS logs, if certain malicious query patterns need to be identified or if fast-flux attacks are happening, Cribl can report that and those would definitely be a plus for them.
I would advise others looking to implement Cribl that if they are evolving Cribl Search, it would be very interesting to see more capability, more flexibility, and more ways to share the data similar to Splunk.
For the ease of use for Falcon administrators, the same documentation on the Falcon LogScale portal should be on the CrowdStrike dashboard.
KQL is simpler when compared to SQL. However, SQL is faster and quite efficient, but the language is a bit tough.
What they have done now is added what is called Charlotte AI, which is their new AI capabilities that can help with this.
Over time, the licensing cost has increased.
It was cheaper than the Splunk license.
Splunk is more expensive, and Cribl appears to be more affordable.
I believe when it comes to log ingestion, it is comparatively low compared to any other services like Microsoft, Trend Micro, or Splunk.
For us, it is a very cost-effective solution.
My experience with pricing, setup cost, and licensing is that it is straightforward, and the cost is quite low.
The data reduction and preprocessing capabilities make Cribl really unique.
Cribl has a feature called JSON Unroll or Unroll function that allows you to differentiate the events; each event will come ingested as a single log instead of piling it up with multiple events.
The Cribl UI is very simple and easy to use, particularly when working with data from various sources; it makes it very easy to create pipelines, add complex logic to those pipelines, and then gives you a preview of what your data looks like before applying that pipeline and what you get after.
You can describe what you want to do in English, and it converts it to a query language for you to use.
Traditional SIEM tools index logs, which is slow and expensive. Falcon LogScale stores logs without heavy indexing and searches directly, making it very fast.
The best features in Falcon LogScale include searches of billions of logs in seconds, near-real-time ingestion and alerting, and index-free architecture, which makes queries faster and cheaper.
| Product | Mindshare (%) |
|---|---|
| Cribl | 2.6% |
| Falcon LogScale | 0.9% |
| Other | 96.5% |


| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 8 |
| Large Enterprise | 34 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 9 |
| Large Enterprise | 3 |
Cribl offers advanced data transformation and routing with features such as data reduction, plugin configurations, and log collection within a user-friendly framework supporting various deployments, significantly reducing data volumes and costs.
Cribl is designed to streamline data management, offering real-time data transformation and efficient log management. It supports seamless SIEM migration, enabling organizations to optimize costs associated with platforms like Splunk through data trimming. The capability to handle multiple data destinations and compression eases log control. With flexibility across on-prem, cloud, or hybrid environments, Cribl provides an adaptable interface that facilitates quick data model replication. While it significantly reduces data volumes, enhancing overall efficiency, there are areas for improvement, including compatibility with legacy systems and integration with enterprise products. Organizations can enhance their operational capabilities through certification opportunities and explore added functionalities tailored towards specific industry needs.
What are Cribl's most important features?Cribl sees extensive use in industries prioritizing efficient data management and cost optimization. Organizations leverage its capabilities to connect between different data sources, including cloud environments, improving both data handling and storage efficiency. Its customization options appeal to firms needing specific industry compliance and operational enhancements.
Falcon LogScale is a modern log management tool that offers robust features for organizations seeking efficient log analysis. It provides high-speed log ingestion and query capabilities, enabling detailed insights into system performance and security events.
Falcon LogScale provides an efficient way for IT teams to handle massive volumes of log data. Its architecture supports rapid ingestion and real-time querying, making it ideal for security and operational analytics. With customizable search capabilities, it allows deep analysis to detect anomalies and troubleshoot issues effectively. Users appreciate its scalability and performance-driven approach, making it suitable for large infrastructures.
What are the most important features of Falcon LogScale?
What benefits or ROI should be anticipated?
Falcon LogScale is particularly beneficial in industries requiring detailed compliance reporting and real-time threat detection, such as finance and healthcare. It's implemented to support security operations and incident response teams by providing timely insights and operational efficiencies.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.