What users are saying about
18 Ratings
16 Ratings
18 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 7.9 out of 100
16 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.5 out of 100

Likelihood to Recommend

Darktrace

Darktrace would be well suited to any environment really; the only constraint would be the budget. The cost scales on the number of devices to be monitored by the product, so it can be quite expensive in larger environments. Any company that would benefit from having 24/7 monitoring of their network would find that this product would suit that need perfectly. It can also create a number of reports, which is useful if you have any requirement to present periodic figures and statistics for your network. There are also additional features available and in development such as Antigena, which can be configured to allow potential threats to be automatically mitigated; it can block connections to a certain address, using certain ports, or it can enforce "normal behaviour" where it will only allow a machine to communicate in a way that Darktrace has observed before and considers normal. This has huge benefits particularly for 24/7 organisations where you don't have the ability to have someone monitoring the network personally at all times, as it could stop a malware outbreak in its tracks.
Anonymous | TrustRadius Reviewer

Graylog

If you already have a basic understanding of Elasticsearch and/or MongoDB, Graylog will be a great fit when it comes to log aggregation. It will be a decent option even if you don't have any experience but have the time and willingness to roll up your sleeves that learning those tools will require. Graylog supports plugins to extend functionality for things like SNMP traps, telemetry collection, and solar flares. As is the case with most software with plugins, if the core functionality for which you are looking (i.e. not logging) is based on a plugin, Graylog probably isn't for you. The majority of the plugins in the marketplace are developed by third-parties looking to solve their specific use case so bug fixes and new features are not a given.
Anonymous | TrustRadius Reviewer

Pros

Darktrace

  • It did an ok job of analyzing and collecting data. It used a span (mirrored) port and then using its own algorithm developed flow records.
  • It did an ok job of segmenting traffic into networks - not always correctly, but ok.
  • It tried to identify devices by type - once again, it did ok, but not that great.
Matthew Frederickson | TrustRadius Reviewer

Graylog

  • The free edition is extraordinarily powerful.
  • Log searching is quick.
  • The web interface is sleek, and the install is relatively quick.
Anonymous | TrustRadius Reviewer

Cons

Darktrace

  • False positives. Darktrace uses "AI" to create its alerts for "unusual" or "malicious" activity. It is very common to see an alert for completely benign and normal device behavior - PC tries to print for the first time in a while, for example.
  • Antigena actions. To some extent, this is a continuation of the previous point. Darktrace can break the network connectivity of the suspected device automatically. The excessive number of false positives makes administrators reluctant to use this feature, though. Also, the default Antigena actions are not relevant to real-world problems as I saw them in my experience with Darktrace.
Anonymous | TrustRadius Reviewer

Graylog

  • The graphs and visualizations are limited on the dashboard if there were more options it would be better for different kinds of data.
Anonymous | TrustRadius Reviewer

Likelihood to Renew

Darktrace

No score
No answers yet
No answers on this topic

Graylog

Graylog 10.0
Based on 1 answer
The product is great, and the support we have gotten from the developers has been top notch!
Andrew Meyer | TrustRadius Reviewer

Support Rating

Darktrace

Darktrace 9.5
Based on 2 answers
Any time I have had any issue with Darktrace, I've been able to contact an engineer through their support desk, and I have always had a very speedy response. Even when the issue has been caused by something outside of the Darktrace devices, they have still been very keen to try to help and identify what the problem was. The customer portal also has a large number of videos and guides that you can use to educate yourself on the product
Anonymous | TrustRadius Reviewer

Graylog

Graylog 5.6
Based on 3 answers
From a product perspective, it's an 8.
I am still unhappy with the pricing model for the enterprise. Graylog competes against the likes of IBM and Splunk, but your still the new kid on the block. To price Graylog enterprise at 50k for 20GB ingest an unrealistic data. It would require multiple facets of Graylog to be stood up and only forward pruned logs to the paid version.
Jeremy Cejka | TrustRadius Reviewer

Alternatives Considered

Darktrace

We have not evaluated others as they seem to be in their own class.
Anonymous | TrustRadius Reviewer

Graylog

Graylog provides some great functionality for free. There are some more premium products that would handle more logs and would be a little easier to configure
Anonymous | TrustRadius Reviewer

Return on Investment

Darktrace

  • We had an ROI just during the POC. DarkTrace helped us identify a ransomware attack and we stopped it before it happened.
  • The weekly reports more than pay for itself within the first few months.
  • The powerful search capability helps us solve problems where other solutions fall short.
Anonymous | TrustRadius Reviewer

Graylog

  • We do not purchase support, so the only operational cost is that of the time it takes to maintain it.
  • All the components of Graylog that we use are free and open source, so there was no capital expense other than that of servers (repurposed from another recently-decommissioned project).
  • If there is a software crash that doesn't recover gracefully, it's usually something obscure that will take a while to diagnose and fix. Unless you build out a distributed and more resilient system with no single points of failure, that may have an impact on the organization or industry requirements for compliance.
Anonymous | TrustRadius Reviewer

Pricing Details

Darktrace

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Graylog

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Add comparison