M
Mid-Market (51-1000 emp.)
"Outstanding in Every Way"
RunReveal is extremely simple to configure and use daily compared to its peers. Streamlined log ingestion and thoughtful AI implementation let me focus on hunting threats and making a real difference in security. It's so good that I only dislike that some features are paywalled in the free version, so I can't use it fully in my homelab. The main issue RunReveal helps us with is doing detection and response at scale with limited staff. For a small team, time is precious, and RunReveal's ease of use and optimized design give us time back to focus on more important security matters.
"RunReveal Stores Data Efficiently and Simplifies Investigations with AI"
First, RunReveal stores data much more efficiently than Splunk, so we have more data in our SIEM for analysis. Close second is their incredible AI integrations that make investigations easier and even automated. They may lack some features, but if you need something, their turnaround is amazing—they're incredibly agile and great to work with. RunReveal has helped us combat the high cost of running a SIEM and brought modern capabilities that others won't have for years.
D
Detection and Response Engineer
"The Team Really Knows Their Stuff"
It's built by people who understand the security analytics problem space. It's engineered to solve real problems and supported by passionate employees. One feature that stands out is RunReveal's MCP server—it's been a game changer, enabling large-scale investigations, detection development, and audit capabilities at an unprecedented pace. Shipping with out-of-the-box materialized views for common ingestion sources would improve performance on high-volume tables. Overall: simple data onboarding, smart storage choices like ClickHouse, and meaningful AI application to big data analysis.
S
Small-Business (50 or fewer emp.)
"Fast, Clean, and Intuitive SIEM Makes Investigations Effortless"
They're fast and responsive when you request new data sources, especially if you use a rare product without an existing source. Pricing is great, the UI is clean, and it's easy to find what you need. With various AI models, investigations feel trivial. They fully support major model providers, and you can use your own Bedrock models or theirs. The founders come from a security background and built a simple product that addresses the shortcomings of other bloated SIEMs. Adding sources is easy and intuitive, and for ones that need extra care, the documentation is helpful. Anything I've disliked has been quickly addressed after feedback. If anything, I wish I had more reason to use the site. I found RunReveal when considering putting audit logs in ClickHouse and wondered if someone had already done it. They had, and it's much easier to pay a reasonable fee than maintain infrastructure, and I get all the features they keep adding.
M
Mid-Market (51-1000 emp.)
"RunReveal Continuously Improves with a Responsive, Hands-On Team"
RunReveal isn't just evolving and improving its offerings; the team is also very involved and consistently open and responsive to feedback. Nothing! That's why I've chosen RunReveal for two companies. RunReveal helps us enhance detections and alerts, giving us better visibility into security incidents and events.
"Agile Team with AI Integrated Throughout the Platform"
RunReveal's team is agile and efficient in how they operate. Although they're a small company, they've made a significant impact on the security industry. They adopted AI early, before some competitors, and now it's woven into their platform. The only downside so far is limited log sources. They're an agile and modern SIEM system.
"Easiest and Fastest SIEM Setup: Logs and Alerts in Under a Day"
RunReveal is by far the easiest and quickest log aggregation and SIEM we've tried. We had multiple log sources and alerts up and running within a day. Other providers would take a week just for a sales call. Some parts could be easier to set up with current documentation, but overall, it's easy log aggregation and alerting for our business. We don't need multiple systems for logs or custom alerts—RunReveal makes the whole process simpler.
"RunReveal Provides High-Signal Security Visibility with Minimal Noise"
RunReveal really impressed me. It delivers the high-signal visibility you'd expect from serious security tools: fast, focused, and without the typical noise. The detections feel carefully engineered rather than tacked on, and the overall experience shows a deep understanding of how security teams work daily. It doesn't just collect data—it helps you reason about what matters and understand what you see. Tools that truly amplify a security team are rare, and RunReveal absolutely does. Honestly, there's nothing significant to complain about. The product feels thoughtfully designed and mature where it counts. If anything, I'm just eager to see how it evolves, but I have no specific complaints. RunReveal tackles a core security challenge: separating real risk from background activity. By giving focused, high-signal detections in a clean, usable interface, it significantly boosts our team's effectiveness. The benefit isn't just better alerts—it's better decisions and faster response.
"RunReveal: The First SIEM Built for the AI Era"
The RunReveal team truly understands the challenges around security logging, detection, and response. Security teams shouldn't need dedicated SIEM engineers to get logs ingested and detections written, and you definitely shouldn't need six different products just to alert on security issues. RunReveal solves all of that. They have the most powerful MCP available, and they don't restrict any features in their API—you can use RunReveal however you like. They're responsive to feature requests and are always improving. They get how code-first security teams operate. We've completely transformed our detection and response because of RunReveal. Features we appreciate: the MCP alone is worth it, no other security team comes close; the API lets us do everything programmatically; built-in logging pipelines; AI-native features for writing and improving queries and detections; the investigation feature that consolidates queries during alerts; and their support for detection-as-code—they've supported this from day one. We now compare every other tool against RunReveal, and none match their capabilities or team. There's nothing I dislike. They track feature requests, so when we need something, we can see its progress—we feel part of the development lifecycle. They're only getting better and let us focus on actual security instead of managing our SIEM. We can do more with less, leveraging AI to interact with RunReveal for investigations. They make it easy to ingest logs, write detections, and keep building. I've never had to deal with logging pipelines, indexing, sharding, or any classic SIEM issues.
"RunReveal's Integrations and AI Triage Streamline Security Response"
The standout aspect is how smoothly RunReveal integrates with our existing stack. The integrations are top-notch, especially pulling in Wiz findings with other security signals, so I avoid toggling between multiple consoles to get the full picture. We've connected it to our GitHub Actions, so alerts appear where the team already works, reducing the hassle of checking another dashboard. The AI-assisted triage is another major advantage. Instead of manually going through every finding weekly, I receive a preliminary analysis that highlights what truly needs human attention, and the SQL-based queries allow me to dig into raw data if I doubt the summary. This has made our weekly triage routine sustainable instead of a dreaded chore. Honestly, there's little to complain about. If I had to pick, the AI triage sometimes flags things I would have deprioritized, so there's an initial tuning period as it adapts to our environment, but that balances out, and the SQL layer lets me verify its decisions against the raw data. Nothing has hindered us significantly. RunReveal tackles the problem of having too many signals and not enough time when managing security across multi-cloud setups. We were overwhelmed by findings spread across separate tools, and merging them was consuming valuable time weekly. Centralizing this, especially incorporating Wiz findings, means our team works from a single source of truth instead of manually reconciling five consoles. The concrete benefit is that our weekly triage is now maintainable. The AI does the first pass, so humans only review what's essential, and because it's all SQL-backed, I can investigate the raw data whenever needed. Integrating with GitHub Actions ensures alerts land where the team already operates, eliminating the extra dashboard burden. Net result: faster triage times and a security process that scales with our cloud growth rather than collapsing under it.