Listing Thumbnail

    CrowdStrike Falcon LogScale: Log Management

     Info
    Deployed on AWS
    Vendor Insights
    Falcon LogScale is a modern, purpose-built log management platform that offers low TCO, industry-leading unlimited plans, and minimal maintenance and training costs to enable customers to log everything and answer anything in real time - at scale.

    Overview

    Play video

    Falcon LogScale changes the way enterprises relate and interact with their data by making it fast, easy, and cost-effective to log anything and answer anything at scale, in real-time. LogScale enables DevOps, ITOps, and SecOps to understand the IT environment, prepare for the unknown, proactively prevent issues, recover quickly from incidents, and understand the root cause.

    LogScale's flexible, modern architecture improves/enhances the log management experience for organizations by enabling complete observability to answer any question, explore threats and vulnerabilities, and gain valuable insights from all logs in real time. LogScale offers low total cost of ownership and unlimited plans (via private offer), with easy deployment at any scale

    With industry-leading unlimited plans, minimal maintenance and training costs, and remarkably low compute and storage requirements, LogScale delivers the lowest total cost of ownership with a savings of up to 80% over other solutions.

    For unlimited plans please reach out to: cloudmarketplaceoffers@crowdstrike.com 

    Highlights

    • Ingest, aggregate, and analyze massive volumes of streaming log data, from a wide array of sources, at scale. The platform also provides configurable, shared dashboards to visualize data, carry out investigations, and collaborate.
    • Improve the quality and reliability of systems in real time and proactively prepare for the unknown to prevent issues, recover quickly from incidents, and understand the root cause. Drive enhanced performance, and encourages alignment across teams.
    • Remove the limitations present in traditional logging solutions with unlimited ingest, reduced infrastructure costs and lower costs with a savings of up to 80% over other solutions. For unlimited plans: cloudmarketplaceoffers@crowdstrike.com

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. Request a private offer to receive a custom quote. Sign in to view any offers that have been extended to you.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    You can log a support ticket for any issues directly from the Falcon Portal or by emailing the support team at cloudmarketplaceoffers@crowdstrike.com  support@crowdstrike.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Data Analytics, Log Analysis
    Top
    100
    In Security
    Top
    10
    In Education & Research

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Log Ingestion Capability
    Supports massive volume log data ingestion from multiple sources with real-time streaming and scalable architecture
    Data Visualization
    Provides configurable shared dashboards for data exploration, investigation, and cross-team collaboration
    Observability Platform
    Enables comprehensive IT environment monitoring with real-time threat and vulnerability exploration capabilities
    Architectural Flexibility
    Offers modern, flexible log management architecture supporting comprehensive data analysis across DevOps, ITOps, and SecOps domains
    Performance Optimization
    Supports proactive system performance monitoring, root cause analysis, and rapid incident recovery mechanisms
    Threat Detection
    Advanced endpoint detection capabilities using proactive scanning and analysis techniques
    Malware Prevention
    Comprehensive protection against ransomware and sophisticated cyber threats through real-time monitoring
    Endpoint Management
    Scalable solution for centralized management and monitoring of organizational endpoints
    Detection and Response
    Integrated endpoint detection and response (EDR) framework with forensic investigation capabilities
    Security Strategy
    Flexible deployment options supporting standalone and extended detection and response (XDR) integration
    Threat Detection Mechanism
    Advanced endpoint detection and response (EDR) capabilities with multi-stage threat identification across attack vectors
    Malware Prevention Technology
    Sophisticated prevention-first approach using advanced blocking technologies against broad range of cyber attacks
    Security Investigation Tools
    Unified XDR platform enabling comprehensive threat investigation, detection, and response capabilities
    Attack Vector Coverage
    Multi-layered protection mechanism targeting different stages and types of cybersecurity threats
    Endpoint Protection Framework
    Comprehensive security solution with default strong protection settings and drift identification capabilities

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    100%
    0%
    0%
    1 AWS reviews
    |
    18 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Anil Kishore

    AI-powered fast search and data retention boosts efficiency and reduces storage costs

    Reviewed on Oct 16, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    Initially, the log was for log management. We store our logs for achieving compliance and log retention for longer periods. This function, LogScale, is now a platform where we can do correlation as well. It has become a next-generation SIM.

    How has it helped my organization?

    The solution definitely saves us time because it has a Google-like search. We can pull out log information in seconds, whereas traditional solutions would take hours or days. Additionally, the compression ratio is very high, which means our storage costs are minimal.

    What is most valuable?

    The fast search and index-free data retention are very valuable. The platform now works on an AI and ML-based engine, and we can analyze anything that is stored.

    What needs improvement?

    The integration could improve. Easy parser writing should be an option to ingest log in a human-readable format for unsupported devices. For visibility perspective, the dashboard should be more user-friendly. It should visualize what is happening in the complete ingestion, showing how many log sources there are, data volumes, and use cases or correlation rules triggered based on AI and ML analytics.

    For how long have I used the solution?

    We have used LogScale for approximately one and a half years.

    What do I think about the stability of the solution?

    Stability is good. I would rate it nine out of ten.

    What do I think about the scalability of the solution?

    Currently, scalability needs improvement in the visualization and representation of LogScale. The integration needs to be dimensioned.

    How are customer service and support?

    CrowdStrike support is good, but in some cases, it takes time to resolve on-premises solutions. I would rate the support seven out of ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    There are no previous solutions mentioned.

    How was the initial setup?

    If the user wants to install it in their infrastructure on-premises, it's complex. If they are using a cloud as a SaaS service, it is easy.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is average. I would rate it six or seven out of ten.

    Which other solutions did I evaluate?

    In the India market, OpenText  is the direct competitor for log management and SIM products. IBM's QRadar  is also mentioned.

    What other advice do I have?

    LogScale can be used across all company segments.

    I'd rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    reviewer2343936

    Fast search results, transformative data analysis, and easy to set up

    Reviewed on Sep 25, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    This is a next-generation SIEM  solution. It's used for fast search results compared to traditional SIEM  solutions that take much longer due to the huge volume of data.

    How has it helped my organization?

    The traditional SIEM could not cope with the indexing algorithm, but with Falcon LogScale , we can get the result within a few seconds when we search for a keyword.

    What is most valuable?

    One of the key features is the fast search functionality, enabling us to get results within a few seconds.

    What needs improvement?

    So far, there are no features in need of improvement. The price could be lower.

    For how long have I used the solution?

    I've been working with LogScale for about half a year.

    What do I think about the stability of the solution?

    There don't appear to be any complexities with stability. The rating for stability is nine out of ten.

    What do I think about the scalability of the solution?

    I rated scalability as eight. It has the ability to scale well.

    How are customer service and support?

    Customer service is rated nine out of ten. So far, so good.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The setup process was simple. We managed to get it done within a day.

    What's my experience with pricing, setup cost, and licensing?

    The pricing could be lower.

    Which other solutions did I evaluate?

    The main competitor on the market is Splunk.

    What other advice do I have?

    I'd rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Shaik Shaheer

    A highly commendable and robust solution offering powerful features and comprehensive log data management

    Reviewed on Oct 11, 2023
    Review provided by PeerSpot
    ">

    What is our primary use case?

    As an MSSP company, we work with various products and tools, including Falcon EDR and Falcon LogScale by CrowdStrike. We handle the configurations, integrations, and other tasks related to these tools on our tenant. We also create dashboards, perform quarantines, and use it for log management and fast data access.

    How has it helped my organization?

    It allows us to efficiently manage and store our data. Its compression and archiving features not only reduce storage costs but also minimize the infrastructure resources needed for data backup. Since we have multiple security solutions in place, it allows us to streamline data handling. We can selectively send security-related events to the SIEM while directing other non-security events from various tools to Falcon LogScale. This flexibility ensures that we have access to all the data we need when required, and we can easily export this data from it as necessary, optimizing our data management and making it readily available for analysis or other purposes.

    What is most valuable?

    It has an impressive data retention capability, allowing you to collect and store data for up to a year. Also, its data retrieval speed is remarkable, taking just a fraction of a second to access the information you need. This combination of extensive data retention and quick data retrieval sets it apart from other log management tools I've worked with in the past.  It offers the capability to view live log ingestion directly from the console which means you can seamlessly manage live log data ingestion alongside accessing and analyzing older data from the past.

    What needs improvement?

    There are some overlapping features found in multiple tools.

    For how long have I used the solution?

    We have been using it for a year now.

    What do I think about the stability of the solution?

    The solution remains stable without any notable issues. It performs exceptionally well when dealing with substantial data ingestion. Retrieving data from one or two months ago is virtually instantaneous.

    What do I think about the scalability of the solution?

    As a relatively small organization, we haven't had the chance to deploy and scale it yet. Our daily data ingestion is relatively modest, typically around fifteen to twenty GB and we don't have subsidiary branches where we can replicate the same LogScale environment for further scaling. However, we are open to exploring potential opportunities for expansion in the future.

    How are customer service and support?

    Around six months ago, we engaged in a workshop with one of CrowdStrike's Subject Matter Experts. During this session, they provided us with an overview of their products, explaining how they function, their capabilities, and the new features that had been added.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I've had experience working with Global Chronicle, Sumo Logic, and Splunk, including an Indian tool. In comparison to these solutions, Falcon LogScale appears to be a well-rounded and efficient solution. It excels in certain areas where others fall short, making it a strong choice for log management in my experience.

    How was the initial setup?

    The initial set up is straightforward, and its operation is easily comprehensible. You can swiftly deploy it on your own without much complexity.

    What about the implementation team?

    For on-premises deployment, you'll require a dedicated server with specific backend requirements and you'll need to obtain the OVFA from CrowdStrike LogScale. While we haven't had the chance to perform an on-premises deployment, based on my knowledge and the available documentation, the process is estimated to take around thirty to forty-five minutes to complete.

    What other advice do I have?

    I would suggest that, based on your organization's log management needs, if you're already using an SIEM  solution, you can complement it with Falcon LogScale for extended data ingestion and storage. It provides flexibility, allowing you to customize data retention based on your specific requirements and organizational compliance standards. You can tailor data ingestion to send security-related alerts to the SIEM while storing other logs for future use. Its capacity to handle vast amounts of data ingestion and provide lightning-fast query capabilities is a significant advantage. I would rate it nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Retail

    A good tool but not recognized in the Cybersecurity domain anymore.

    Reviewed on Aug 19, 2023
    Review provided by G2
    What do you like best about the product?
    It possessed substantial power and incorporated regular expression (regex) support to elevate its capabilities for searching, hunting, and troubleshooting.
    What do you dislike about the product?
    Doesn't appear to be a widely recognized or commonly known term or tool in the realm of cybersecurity or technology.
    What problems is the product solving and how is that benefiting you?
    We're highly satisfied with Logscale as it significantly improves search performance, enabling us to handle larger data sets more efficiently. While Logscale currently offers fewer integrations compared to Splunk, this is changing over time. Another advantage is the option to develop custom apps when necessary. We chose the Logscale Complete Route for our transition.
    Nikitha S.

    Humio gives me the convenience to ingest our 1 TB of log volume on each node

    Reviewed on May 12, 2022
    Review provided by G2
    What do you like best about the product?
    Humio provides superb data aggregation reports thanks to its well-rounded observability framework. Its relatively easy to explore, iterate and understand all our logs and also offers excellent compatibility for our hybrid cloud deployments. We can easily pinpoint security concerns in any environment and it makes it simple to perform RCA.
    What do you dislike about the product?
    There's a dependency on ingest listeners while working with our Syslog data in Humio platform. Without these, Humio SaaS won't be able to accept logs from Syslog. Apart from this, we didn't encounter any hurdles while working with the Humio platform for container solutions.
    What problems is the product solving and how is that benefiting you?
    Container visualization is beneficial for our security team using Humio we can easily observe health check routines, capacity thresholds and drifts from the expected outcomes. The compression algorithm effectively optimizes available data size in clusters and the ratio between disks & CPU resources. We are able to manage about 1 TB of ingest log volume per day on each node which is helpful for our production setup of clustered version as per our client's specifications. Its comprehensive border security features encompass all structured & unstructured data, making it easy to analyze and correlate data in our hybrid cloud infrastructure.
    View all reviews