Try our new research platform with insights from 80,000+ expert users

Cribl vs Panther comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cribl
Ranking in Security Information and Event Management (SIEM)
10th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
20
Ranking in other categories
Application Performance Monitoring (APM) and Observability (12th), Log Management (6th), Observability Pipeline Software (1st)
Panther
Ranking in Security Information and Event Management (SIEM)
45th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cribl is 1.2%, up from 0.2% compared to the previous year. The mindshare of Panther is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Cribl1.2%
Panther0.4%
Other98.4%
Security Information and Event Management (SIEM)
 

Featured Reviews

Manoj Gowda J - PeerSpot reviewer
Helps reduce log ingestion cost by dropping unnecessary events and customizing pipelines
The best feature in Cribl, when getting logs from some custom application, is the ability to break up logs that pile up together and come as one event. Cribl has a feature called JSON Unroll or Unroll function that allows you to differentiate the events; each event will come ingested as a single log instead of piling it up with multiple events. This is critical as this generally happens in CrowdStrike. This feature helps us significantly. When the ingestion is high from unwanted logs, logs not related to security purposes can be dropped by writing the parser function. By dropping events that are not required for security purpose monitoring, we can reduce the ingestion, which drastically reduces the cost as well. Cribl gives another option where I can store some logs, and when needed, I can pick them up from there. The interface is very handy and not very complicated, yet there are many functions you can perform. You can play around with numerous functions, parse there, and add UDMs to SecOps, which makes it really easy. To simplify the pipeline, when we go to the pipelines, there are vast options. We can make it specific requirements based on the customers. I would prefer a customized or simplified version. Cribl is a very good platform to work with, with lots of features that other platforms don't provide.
RT
Detection capabilities and helpful support team enhance log analysis and integration flexibility
I find Panther's detection capabilities and integrations to be highly valuable. It allows integration with anything as long as I am willing to write detections, and their team is very helpful. I find its log analysis capabilities valuable. It enables me to filter down to individual roles in AWS, and if I am skilled at SQL queries, I can query anything. The infrastructure as code feature allows me to use Git repositories to manage detections and import detections from other Git repositories.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"My favorite option in Cribl is the Stream product."
"Cribl is a very good platform to work with, with lots of features that other platforms don't provide."
"When it comes to the product's installation phase, it is not tough for people who have good knowledge...The tool is worth the investment."
"The platform's most valuable feature is the ability to transform data in real-time within the pipeline without sending it to a destination."
"Cribl offers other valuable features. For instance, you can replay data from an edge device, store your daily data in a stream, and replay specific event data into Splunk if a security incident occurs"
"Our experience with Cribl has been very smooth; everything runs seamlessly, there are no delays or sluggishness, which I really appreciate."
"Cribl definitely helps with the complexity because you don't have to push for deployment—they provide the interface where you can mimic what the output will look like, and you can see that in real time when setting up the Cribl configuration, which definitely helps considerably."
"The product's most valuable features include the internal management of events, coding perspective, data processing, and serialization."
"I find Panther's detection capabilities and integrations to be highly valuable."
 

Cons

"Perhaps more flexibility in terms of metrics would be helpful."
"There is room for improvement in the documentation and knowledge base, particularly regarding configurations like sources where logs are being ingested"
"When I explored the endpoint, I found myself wishing for clearer instructions presented in a sequential manner."
"We encountered some issues with the syslog data stream, particularly with handling large databases and extensive data logs."
"Cribl doesn't have as many packs available"
"Cribl could improve by offering easier integrations with enterprise products, similar to what Splunk provides."
"There have been several administrative issues. Another point is that the browsing functions aren't very intuitive."
"The deployment itself is a bit complicated and the documentation is not very clear."
"The solution could be improved by providing more built-in integrations, which would reduce the need for me to build them myself."
 

Pricing and Cost Advice

"The product pricing is reasonable compared to other solutions."
"I would not say it is a cheaply priced tool as it has been doing wonders in the market. The tool has been budget-friendly for organizations."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
868,787 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
9%
Manufacturing Company
8%
Healthcare Company
8%
Manufacturing Company
16%
Computer Software Company
15%
University
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise8
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cribl?
Cribl is very inexpensive, with enterprise pricing around 30 cents per GB, which is really decent. Organizations looking to ingest terabytes or petabytes of data each day find it quite an inexpensi...
What needs improvement with Cribl?
They've already done many good things with the product, but perhaps they could implement a temporary SIEM solution where we could store logs and display them as a SIEM, though I think that's not th...
What is your primary use case for Cribl?
Our main use case for Cribl was SIEM migration, where we merged multiple SIEM solutions to a single SIEM solution. SIEM migration was the most major use case we were looking for. The second use cas...
What is your experience regarding pricing and costs for Panther?
I find the pricing to be reasonable, although I can't recall the exact cost.
What needs improvement with Panther?
The solution could be improved by providing more built-in integrations, which would reduce the need for me to build them myself.
What is your primary use case for Panther?
We use Panther ( /products/panther-reviews ) for our SIEM ( /categories/security-information-and-event-management-siem ) solution. It is used for aggregating logs and analyzing user activities. We ...
 

Comparisons

 

Overview

 

Sample Customers

Information Not Available
Docker, Loom, Discord, Dropbox, HubSpot, Asana, GoFundMe, Zapier, Benchling, JupiterOne, Jumio, Bitstamp, Intercom, Randori, and Cedar
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: September 2025.
868,787 professionals have used our research since 2012.