No more typing reviews! Try our Samantha, our new voice AI agent.
Shaik Shaheer - PeerSpot reviewer
Security | SIEM Engineer at a tech services company with 51-200 employees
Real User
Oct 23, 2023
A highly commendable and robust solution offering powerful features and comprehensive log data management
Pros and Cons
  • "It offers the capability to view live log ingestion directly from the console which means you can seamlessly manage live log data ingestion alongside accessing and analyzing older data from the past."
  • "There are some overlapping features found in multiple tools."

What is our primary use case?

As an MSSP company, we work with various products and tools, including Falcon EDR and Falcon LogScale by CrowdStrike. We handle the configurations, integrations, and other tasks related to these tools on our tenant. We also create dashboards, perform quarantines, and use it for log management and fast data access.

How has it helped my organization?

It allows us to efficiently manage and store our data. Its compression and archiving features not only reduce storage costs but also minimize the infrastructure resources needed for data backup. Since we have multiple security solutions in place, it allows us to streamline data handling. We can selectively send security-related events to the SIEM while directing other non-security events from various tools to Falcon LogScale. This flexibility ensures that we have access to all the data we need when required, and we can easily export this data from it as necessary, optimizing our data management and making it readily available for analysis or other purposes.

What is most valuable?

It has an impressive data retention capability, allowing you to collect and store data for up to a year. Also, its data retrieval speed is remarkable, taking just a fraction of a second to access the information you need. This combination of extensive data retention and quick data retrieval sets it apart from other log management tools I've worked with in the past.  It offers the capability to view live log ingestion directly from the console which means you can seamlessly manage live log data ingestion alongside accessing and analyzing older data from the past.

What needs improvement?

There are some overlapping features found in multiple tools.

Buyer's Guide
Log Management
March 2026
Find out what your peers are saying about CrowdStrike, Elastic, Splunk and others in Log Management. Updated: March 2026.
885,376 professionals have used our research since 2012.

For how long have I used the solution?

We have been using it for a year now.

What do I think about the stability of the solution?

The solution remains stable without any notable issues. It performs exceptionally well when dealing with substantial data ingestion. Retrieving data from one or two months ago is virtually instantaneous.

What do I think about the scalability of the solution?

As a relatively small organization, we haven't had the chance to deploy and scale it yet. Our daily data ingestion is relatively modest, typically around fifteen to twenty GB and we don't have subsidiary branches where we can replicate the same LogScale environment for further scaling. However, we are open to exploring potential opportunities for expansion in the future.

How are customer service and support?

Around six months ago, we engaged in a workshop with one of CrowdStrike's Subject Matter Experts. During this session, they provided us with an overview of their products, explaining how they function, their capabilities, and the new features that had been added.

Which solution did I use previously and why did I switch?

I've had experience working with Global Chronicle, Sumo Logic, and Splunk, including an Indian tool. In comparison to these solutions, Falcon LogScale appears to be a well-rounded and efficient solution. It excels in certain areas where others fall short, making it a strong choice for log management in my experience.

How was the initial setup?

The initial set up is straightforward, and its operation is easily comprehensible. You can swiftly deploy it on your own without much complexity.

What about the implementation team?

For on-premises deployment, you'll require a dedicated server with specific backend requirements and you'll need to obtain the OVFA from CrowdStrike LogScale. While we haven't had the chance to perform an on-premises deployment, based on my knowledge and the available documentation, the process is estimated to take around thirty to forty-five minutes to complete.

What other advice do I have?

I would suggest that, based on your organization's log management needs, if you're already using an SIEM  solution, you can complement it with Falcon LogScale for extended data ingestion and storage. It provides flexibility, allowing you to customize data retention based on your specific requirements and organizational compliance standards. You can tailor data ingestion to send security-related alerts to the SIEM while storing other logs for future use. Its capacity to handle vast amounts of data ingestion and provide lightning-fast query capabilities is a significant advantage. I would rate it nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
reviewer2343936 - PeerSpot reviewer
Technical Manager at a tech vendor with 11-50 employees
Real User
Top 10
Sep 25, 2024
Fast search results, transformative data analysis, and easy to set up
Pros and Cons
  • "One of the key features is the fast search functionality, enabling us to get results within a few seconds."
  • "The price could be lower."

What is our primary use case?

This is a next-generation SIEM solution. It's used for fast search results compared to traditional SIEM solutions that take much longer due to the huge volume of data.

How has it helped my organization?

The traditional SIEM could not cope with the indexing algorithm, but with Falcon LogScale, we can get the result within a few seconds when we search for a keyword.

What is most valuable?

One of the key features is the fast search functionality, enabling us to get results within a few seconds.

What needs improvement?

So far, there are no features in need of improvement. The price could be lower.

For how long have I used the solution?

I've been working with LogScale for about half a year.

What do I think about the stability of the solution?

There don't appear to be any complexities with stability. The rating for stability is nine out of ten.

What do I think about the scalability of the solution?

I rated scalability as eight. It has the ability to scale well.

How are customer service and support?

Customer service is rated nine out of ten. So far, so good.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup process was simple. We managed to get it done within a day.

What's my experience with pricing, setup cost, and licensing?

The pricing could be lower.

Which other solutions did I evaluate?

The main competitor on the market is Splunk.

What other advice do I have?

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Log Management Report and find out what your peers are saying about CrowdStrike, Elastic, Splunk, and more!
Updated: March 2026
Product Categories
Log Management
Buyer's Guide
Download our free Log Management Report and find out what your peers are saying about CrowdStrike, Elastic, Splunk, and more!