Solid Product but Overkill for Most Organizations
Use Cases and Deployment Scope
We use it mainly to monitor infrastructure and application performance across multiple environments, but also as part of our broader security and compliance visibility stack. It helps us detect performance issues, and unusual activity before they turn into incidents. It helps with problem of fragmented monitoring and limited visibility across systems that have to meet regulatory requirement especially for HIPAA and PCI data . We use infrastructure monitoring, alerting, and real-time dashboards that support both IT operations and security response teams.
Pros
- Realtime visibility across infrastrucrte and applicaitons
- Excellent traceability of data to get us to root cause
- Dashboard are very flexible and customizable.
- Easy integrations with the rest of our tech stack
Cons
- Unnecessarily complicated licensing
- UI needs and update. It's overly cluttered and difficult to learn
- Big correlations for logs and traces can be slow and time consuming.
Return on Investment
- Satisfies observability requirements for the reglatory requirements we have
- Significantly reduces time to detect and remediate potential threats
- Expensive to use. Ensure you are not on a consumption model.
Usability
Alternatives Considered
IntSights Cyber Intelligence, from Rapid7, CrowdStrike Falcon and SentinelOne Singularity
Other Software Used
Fortinet FortiGate, Rapid7 InsightIDR

