We use the product for MDR requirements.
Cyber Security & ICT Director at Polish Security Experts Association
Provides good scalability, but it is challenging to create rules and context for the scripting language
Pros and Cons
- "The platform's most valuable features are multiple connectors and data output flexibility regarding dashboards and user experience."
- "A few areas are difficult to understand for someone who has less experience using the product."
What is our primary use case?
What is most valuable?
The platform's most valuable features are multiple connectors and data output flexibility regarding dashboards and user experience. We can seamlessly create graph dashboards and reports for the customers as per the contracts. The performance speed makes the operations easy. It connects the user accounts quickly, as in-built connectors are available for vendors in Palo Alto and Check Point.
What needs improvement?
It is challenging to create rules and context of the language. A few areas are difficult to understand for someone who has less experience using the product.
For how long have I used the solution?
We have been using Google Chronicle Suite for three months. It is a cloud deployment and the latest version.
Buyer's Guide
Security Information and Event Management (SIEM)
May 2025

Find out what your peers are saying about Google, Microsoft, Splunk and others in Security Information and Event Management (SIEM). Updated: May 2025.
851,604 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is stable enough at the moment. I rate the stability a nine.
What do I think about the scalability of the solution?
We have less than 100 Google Chronicle Suite users in our organization. It is a cloud solution and is easy to scale. It is suitable for all business verticals. I rate the scalability a ten out of ten.
How are customer service and support?
We receive support from local engineers. The technical support for Google consists of well-prepared information or documentation. We need to pay for raising tickets depending on SLA. Overall, the team is helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
It is a cloud deployment, and thus, we have to click a few buttons. The time taken depends on the scale of the operation. It takes at least an hour to install. However, it requires around six weeks to deploy and configure fully. The deployment involves multiple steps, from the initial setup to configuring connectors, defining data flows, specifying log files, and deciding what information is suitable for analysis to be visible on the dashboard.
I rate the process a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
I rate Google Chronicle Suite's pricing a five out of ten. We have to pay extra charges for the amount of data transfer and technical support services.
What other advice do I have?
I advise others to work with Google Chronicle Suite if they already use other GCP products. They should refer to all the strategies about how to utilize the product. They should work with an external company or consultant, as deploying everything from scratch is difficult.
I rate it a seven out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company has a business relationship with this vendor other than being a customer: consultant

It support specialist at AESG
The support team is responsive, and the product is affordable, but it is a little bit difficult to use
Pros and Cons
- "The support team is responsive."
- "The tool is a little bit difficult to use compared to Microsoft Sentinel."
What is our primary use case?
The solution is implemented in our organization. Most employees use it. We use it for storage and security. We are using it for endpoint security.
What is most valuable?
The support team is responsive.
What needs improvement?
The tool is a little bit difficult to use compared to Microsoft Sentinel. I use it every day. I needed time to adjust and get used to the solution.
For how long have I used the solution?
I have been using the solution for a few months.
How was the initial setup?
It was difficult to configure the solution the first time because I hadn’t seen such a solution before. The product provides documentation and support.
What's my experience with pricing, setup cost, and licensing?
The tool is cheaper than Microsoft Sentinel.
Which other solutions did I evaluate?
The solution is new compared to Microsoft Sentinel. There is a big difference between them. Sentinel is Microsoft’s cloud security solution. It supports all cloud solutions.
What other advice do I have?
We are looking into other solutions for endpoint security. A consulting company advises us on the solutions that can be integrated with Google Chronicle Suite. Overall, I rate the solution a six out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Security Information and Event Management (SIEM)
May 2025

Find out what your peers are saying about Google, Microsoft, Splunk and others in Security Information and Event Management (SIEM). Updated: May 2025.
851,604 professionals have used our research since 2012.
Data Engineer at a wellness & fitness company with 51-200 employees
Comes with useful APIs but can be complicated for a first-time user
Pros and Cons
- "Google Chronicle Suite provides useful APIs."
- "The tool is complicated for a first-time user. It should also include newer APIs."
What is our primary use case?
We use the solution to check alerts.
What is most valuable?
Google Chronicle Suite provides useful APIs.
What needs improvement?
The tool is complicated for a first-time user. It should also include newer APIs.
For how long have I used the solution?
I have been working with the product for six months.
What do I think about the stability of the solution?
Google Chronicle Suite is stable.
What do I think about the scalability of the solution?
The tool is scalable.
How are customer service and support?
Google Chronicle Suite's technical support is good. If you don't want to experience delays, you need to set up a priority.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is dependent on the data amount.
What other advice do I have?
I rate the product a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solution Delivery Lead at a consultancy with 10,001+ employees
A SIEM solution that needs to improve GUI
Pros and Cons
- "The tool's most valuable feature is the search option, allowing easy navigation."
- "The tool needs to improve tasking packages. Its GUI needs to be improved. The product needs to include time-based filtration. We can only see the alert detection timeline now."
What is our primary use case?
We use the product as a SIEM.
What is most valuable?
The tool's most valuable feature is the search option, allowing easy navigation.
What needs improvement?
The tool needs to improve tasking packages. Its GUI needs to be improved. The product needs to include time-based filtration. We can only see the alert detection timeline now.
For how long have I used the solution?
I have been using the product for one year.
What do I think about the stability of the solution?
I rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
I rate Google Chronicle Suite's scalability a seven out of ten.
How was the initial setup?
The tool's deployment is not difficult.
What other advice do I have?
I rate the product an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at a tech consulting company with 1,001-5,000 employees
A highly scalable tool that performs well and has premade dashboards that provide information on errors in the system
Pros and Cons
- "The log folder is fairly simple."
- "The configuration is not optimal."
What is our primary use case?
I've been using the solution as a consultant while working for a client who has chosen Google Chronicle as their SIEM solution. We are using the product as a centralized log management solution and as a solution for threat intelligence. We use it to analyze incoming log information and automatically generate alerts from indicators that have been compromised.
What is most valuable?
The search feature is quite performant. The log folder is fairly simple. It is easy to get it up and running and to use for log management and forwarding. I found it quite useful that the solution has premade dashboards, which provide information on errors in the system and general monitoring functionality.
What needs improvement?
The configuration is not optimal. It requires copy and paste of configuration files. Generally, the ingest of logs could be done in simpler and more streamlined ways. The exporting of log information also has room for improvement.
For how long have I used the solution?
I am using the solution currently.
What do I think about the stability of the solution?
I rate the tool’s stability a ten out of ten. I have not encountered any issues.
What do I think about the scalability of the solution?
I rate the tool’s scalability a ten out of ten. Around 12 people use the product in our organization. The usage will increase as it's gaining traction on the market, and more people will have to work in consulting.
Which solution did I use previously and why did I switch?
I'm working as a SIEM consultant. I've worked with several SIEM systems over time.
How was the initial setup?
The initial setup is very easy. As a cloud-native tool, it includes provisioning an instance and connecting it to a single sign-on. I rate the ease of setup a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is not dependent on the volume of information ingested, which most competitors do. In many cases, that makes it less pricey than the competition, but not in all cases.
What other advice do I have?
The solution has room for improvement. People who want to use the tool must get a Google partner to work with them and outsource the whole thing. The product is a great choice. Organizations must ensure they have competent people who can use the tool to its full potential. A lot of it may be wasted if they don't have the right people or the right partner. Overall, I rate the product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security | SIEM Engineer at a tech services company with 51-200 employees
Stable product with efficient data retrieval and security features
Pros and Cons
- "The product's most valuable feature is threat hunting. We can detect the threats directly from the console from the past data as well."
- "The product's default dashboard feature has a few limitations regarding availability."
What is our primary use case?
We use the product for search engine integration and its ability to monitor and address network attention or login issues 24/7.
How has it helped my organization?
The product helps us with data retrieval and security features.
What is most valuable?
The product's most valuable feature is threat hunting. We can detect the threats directly from the console from the past data as well.
What needs improvement?
The product's default dashboard feature has a few limitations regarding availability.
For how long have I used the solution?
We have been using Google Chronicle Suite for two years as an integrator.
What do I think about the stability of the solution?
We encountered platform downtime once or twice.
What do I think about the scalability of the solution?
It is a scalable product. We manage accounts for Google Chronicle Suite seven to eight customers.
How are customer service and support?
We have limited technical support services. However, they provide good support, understand the queries, and respond.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup process is easy. The deployment involves checking default requirements for installing the product and configuring the log source. It requires five to ten minutes to complete. It doesn't need any maintenance. We have to make sure the forwarder is not switched off.
What other advice do I have?
I rate Google Chronicle Suite a nine out of ten. It helps connect to the log sources rapidly. However, it has limited IAM access and dashboarding features.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Security engineer at a tech services company with 51-200 employees
A highly scalable solution with good threat intelligence capabilities, but its GUI should be more user-friendly
Pros and Cons
- "Google Chronicle Suite is a highly scalable solution with good search capabilities."
- "The solution's graphical user interface (GUI) should be more user-friendly."
What is our primary use case?
We are one of the five partners of Google Chronicle Suite in the world. We resell the solution, and we implement it for Google.
What is most valuable?
Google Chronicle Suite is a highly scalable solution with good search capabilities. The enterprise version comes with one of the best threat intelligence capabilities in the world.
What needs improvement?
The solution's graphical user interface (GUI) should be more user-friendly.
For how long have I used the solution?
I have been using Google Chronicle Suite for more than two years.
What do I think about the stability of the solution?
I rate the solution eight and a half out of ten for stability.
What do I think about the scalability of the solution?
I rate Google Chronicle Suite nine and a half out of ten for scalability.
How are customer service and support?
The solution's technical support is good but not great. Recently, Google has started hiring people for the technical support team. We never needed their support unless it was something to be done to which we did not have access.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup is not that easy.
What about the implementation team?
We have done multiple implementations, and the solution's deployment time depends on the organization.
What's my experience with pricing, setup cost, and licensing?
Compared to other solutions, Google Chronicle Suite's pricing is fine.
What other advice do I have?
We are using the latest version of Google Chronicle Suite.
Scalability is one of the requirements in enterprise-level organizations. They need a flexible solution that can be scaled easily. An enterprise-level organization will have huge amounts of data. If you want to do threat hunting for one year for such an organization, you don't want a system that goes down if you search for more than 30 days. You need a solution that will give you good search results.
Google Chronicle Suite is one of the best products in the market if you are looking for incident response and threat-hunting use cases. It is not a recommended solution for compliance, reporting, or dashboarding.
Overall, I rate the solution a seven or seven and a half out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:

Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Google, Microsoft, Splunk, and more!
Updated: May 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Cortex XSIAM
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Sumo Logic Security
Coralogix
Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Google, Microsoft, Splunk, and more!
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?