"Extremely Fast and Excellent Documentation"
The easy integration with existing systems via raw syslog or the Elastic bulk ingest API, and their Grafana plugin. And of course, the price—it's very cheap compared to other enterprise products. While the online documentation is comprehensive, it's also a lot to read just to do basic searches and alerting. But once you get the hang of it, it's no problem. There are no pre-made parsers for syslog data, so you'll likely need to create parsers to break log data into searchable fields yourself. We're in the process of moving all our logging to Humio and already use it for alerting and operations.
M
Machine Learning Engineer
"Great Log Aggregation, Slow UI"
Now that our platform team has set up Humio, all logs from applications and deployments stream in without needing additional configuration at the application level, which is fantastic. We develop on Kubernetes, and besides application logs, we get platform logs, so we can debug and monitor the whole stack. Handling structured logs is also nice; Humio automatically parses many formats, and you can write custom parsing rules. Once parsed, you can filter and display specific fields, saving results into persistent, live dashboards. The only downside is the UI. Scrolling through logs to find relevant messages can be tough unless you set up filters. Each page only shows 200 lines, which isn't much for significant applications. The pagination is painfully slow for me, maybe due to my browser. This can be mitigated by smart filtering, but waiting for pages to load is awkward. I use structured logging to get the most out of Humio. I use it to debug applications, view logs, and build persistent dashboards to monitor app performance over time.
"Humio Allows Us to Ingest 1 TB of Logs per Node"
Humio provides excellent data aggregation reports thanks to its comprehensive observability framework. It's relatively easy to explore, iterate, and understand all our logs, and it offers great compatibility for hybrid cloud deployments. We can pinpoint security concerns in any environment easily and perform RCA simply. There's a dependency on ingest listeners when working with Syslog data; without them, Humio SaaS can't accept logs from Syslog. Apart from that, we've had no issues using Humio for container solutions. Container visualization is beneficial for our security team; we can easily monitor health checks, capacity thresholds, and deviations. The compression algorithm effectively optimizes data size in clusters and the disk/CPU ratio. We manage about 1 TB of ingest log volume per day on each node, which helps in our clustered production setup as per client specs. Its comprehensive border security features encompass all structured and unstructured data, making it easy to analyze and correlate in our hybrid cloud infrastructure.
M
Mid-Market (51-1000 emp.)
"A Good Tool but Not Widely Recognized in Cybersecurity"
It had substantial power and included regex support to enhance searching, hunting, and troubleshooting. It doesn't appear to be a widely recognized tool in cybersecurity or technology. We're highly satisfied with Logscale as it significantly improves search performance, allowing us to handle larger data sets efficiently. While Logscale currently offers fewer integrations than Splunk, this is changing over time. Another advantage is the option to develop custom apps when needed. We chose the Logscale Complete Route for our transition.
"NGSIEM Delivers Unmatched Performance, Clean UI, and Seamless Integrations"
NGSIEM basically has all the features that other SIEMs brag about but don't implement well. The UI is clean and easy to use, integrates with many products, and feeds data to third-party integrations. Performance is unmatched, and pricing isn't an issue since it's standard for everyone. CrowdStrike offers world-class support and is always there to help you get started. As with all their products, you can use the built-in AI, Charlotte, to query the SIEM and get accurate, helpful results. Like any CrowdStrike product, there's a lot of configuration and a learning curve. It's our all-in-one SIEM!
"Fast Search and Seamless Integration, but Learning Curve Exists"
I really like the fast search capability in Falcon Next-Gen SIEM, which lets me quickly pivot through large volumes of logs during investigations without delays. The seamless integration with endpoint data is another highlight, allowing efficient correlation of alerts and endpoint activity in the same place, speeding up root cause analysis. The unified platform reduces the need to switch between tools, making investigations much quicker. Initial setup is pretty straightforward since it's cloud-based, enabling data integration through connectors or creating users with different roles. One area for improvement is the learning curve, especially with the query language and advanced use cases. Some features and integrations are still evolving, so it may not be as mature or flexible as traditional SIEMs in certain scenarios. Documentation can be improved; there's no open-source or community support. I'd like to see broader third-party integrations and more query language functions. I use Falcon Next-Gen SIEM for centralized log management, real-time threat detection, and improved visibility. It helps with threat hunting and incident investigation, solving the challenge of handling large log volumes and enabling fast search. It reduces alert noise and correlates data across sources.
"Centralized Security with Improved Efficiency"
I appreciate Falcon Next-Gen SIEM's real-time visibility across the environment, which keeps investigations simple and efficient. The main advantage is that it ingests data once and shares it across multiple modules like cloud, endpoint, and SIEM. Search is fast, and the interface is easy to navigate. CrowdStrike's out-of-the-box connectors make data onboarding easy. These features help reduce time spent searching through large volumes of security data and investigating incidents. Real-time visibility lets us spot threats as they happen, while fast search quickly finds relevant events during investigations. The intuitive interface boosts analyst productivity. Initial setup is straightforward since it's SaaS-based. It delivers strong visibility and fast data access, helping teams respond swiftly and confidently. One limitation is the limited set of query commands, and we can't create custom commands based on our needs. Falcon Foundry is tricky, making custom app development harder than other platforms. Documentation is also limited and only available in-platform. Falcon Next-Gen SIEM centralizes logs from multiple sources, solving log visibility, threat detection, and investigation challenges. Its fast search and real-time visibility improve efficiency in monitoring and responding to threats. The intuitive interface enhances search and investigation efficiency.
C
Cyber Security Consultant
"Fast, User-Friendly SIEM with Excellent Falcon Suite Integration"
Falcon Next-Gen SIEM integrates smoothly with other Falcon Suite products and offers a unified platform, making detection and investigation easy. Data onboarding and parsing are straightforward, and event searching is incredibly fast. The Charlotte AI simplifies creating detection rules. Pricing is much lower than competitors. The Falcon platform's UI/UX is very intuitive, and CrowdStrike provides excellent support with quick responses. However, customization is limited, and documentation isn't very detailed. It provides a fast, stable platform where we onboard both first-party endpoint data and third-party data. Since it's integrated with XDR and SOAR, all our use cases are covered with a single platform at a low cost.
A
Artificial Intelligence Engineer
"Robust SIEM with a Steep Learning Curve"
The best part is having everything consolidated in one spot. Previously, we were forever switching between tools, and things slipped through the cracks. Now, logs and alerts from various sources converge into a single view, and when you look at it, it all makes sense.
The correlation engine is what really convinced me. It automatically identifies related events—things our team would have spent hours trying to connect manually. Search speed is impressive too: even with massive log volumes, results come back quickly, which is crucial during an active incident.
Overall, it has made our investigations faster and given the team much better visibility without adding complexity to our workflow. The interface can feel overwhelming when you're starting out—it's not the most intuitive for new users and takes time to get used to. Setting up and fine-tuning detection rules took much longer than expected, with a lot of trial and error early on that consumed time we didn't have.
On the support and onboarding side, better guided walkthroughs would have saved us many headaches. Pricing is on the higher side, so smaller teams should think carefully before committing. The AI-driven detections are impressive but require some experience to fully comprehend and act on. Integrations work well overall, but initial configuration isn't always as plug-and-play as you'd hope.
Alert fatigue was our biggest issue before this. Too many tools, too much noise, and the team was burning out just trying to keep up. Falcon Next-Gen SIEM consolidated everything under one roof, and suddenly we could see what was happening without drowning in irrelevant alerts.
The automatic event correlation has been a game changer. Things that would have taken hours to piece together manually now surface on their own. During incidents, the fast search means we're not waiting around—we get to the root cause quickly and respond before things escalate. Overall, it has saved us significant time and given the whole team more confidence in our security coverage.
A
Associate Security Engineer
"A SIEM That Unifies Endpoint, Identity, and Cloud Data"
The standout feature of CrowdStrike Falcon Next-Gen SIEM is its seamless integration with the entire Falcon platform. Unlike standalone SIEMs that demand extensive connector setup and data normalization just to start ingesting logs, this solution automatically pulls telemetry from Falcon endpoints, identity protection, and cloud workloads without any admin overhead. This built-in integration alone saves considerable time during deployment and maintenance.
Detection quality is another highlight. Leveraging CrowdStrike's threat intelligence and AI-driven correlation, it delivers high-fidelity alerts with useful context, sparing analysts from being overwhelmed by raw, uncorrelated log noise. Custom detection rules can be written using a flexible query language, giving security teams the ability to tailor detections to their specific environment without relying solely on vendor-provided content.
The unified timeline view that merges endpoint, identity, and network events into a single investigation workflow is particularly valuable for incident response. Instead of toggling between multiple tools and consoles to reconstruct an attack chain, everything is presented in one place, significantly reducing mean time to detect and respond. For teams handling complex, distributed environments, this level of integration and context is a true force multiplier.
However, there are notable limitations from an administrator's perspective. The cost is on the high end, and the licensing model can be confusing, especially when data ingestion costs can escalate quickly, requiring careful budgeting upfront. The query language, while powerful, has a steep learning curve for analysts coming from platforms like Splunk or Sentinel. The syntax is different enough that team members need a real adjustment period to write efficient, complex queries confidently. Better documentation and in-product guidance would ease this transition.
Additionally, integrating third-party data sources remains challenging. Normalizing and ingesting logs from diverse network devices, legacy systems, or niche security tools often demands significant manual effort, and out-of-the-box report templates frequently don't meet real-world audit and compliance needs without heavy customization.
Falcon Next-Gen SIEM tackles the persistent problem of security telemetry being scattered across disconnected tools. In most environments, endpoint data resides separately from network logs, identity events, and cloud workload telemetry. During active investigations, piecing this together manually is slow and error-prone. This platform centralizes everything into a unified, correlated workflow, fundamentally improving how quickly and effectively teams respond to threats.
It also solves the alert fatigue that plagues traditional SIEMs. Legacy systems generate massive volumes of low-fidelity alerts that analysts must triage one by one. Falcon Next-Gen SIEM's AI-driven correlation and built-in attack chain mapping dramatically reduce time spent on false positives and low-priority noise.
From a day-to-day operations perspective, the benefits are substantial. Mean time to detect and respond has improved noticeably, as investigations that once required switching across four or five consoles now happen within a single timeline. Threat hunting has become more proactive, with powerful query capabilities allowing analysts to search historical telemetry and spot indicators of compromise before they escalate. For lean security teams managing complex environments, this operational efficiency directly translates to a stronger security posture and faster incident resolution.