Graylog vs. Sophos UTM

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Graylog
Score 8.4 out of 10
N/A
Graylog, headquartered in Houston, offers their eponymous platform for centralized log management that helps users find meaning in data faster so as to take action immediately. Graylog is available via Enterprise and Cloud plans, but also has a Small Business Plan, and an Open (free) plan with limited features.N/A
Sophos UTM
Score 9.2 out of 10
N/A
Sophos UTM provides core firewall features, plus sandboxing and AI threat detection for advanced network security. It has customizable deployment options.N/A
Pricing
GraylogSophos UTM
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
GraylogSophos UTM
Free Trial
NoYes
Free/Freemium Version
YesNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Detailst2.small - $0.123 - Total / hr m3.medium - $0.417 - Total / hr m3.large - $0.883 - Total / hr m3.xlarge - $1.366 - Total / hr m3.2xlarge- $1.982 - Total / hr c3.large - $0.555 - Total / hr c3.xlarge - $1.11 - Total / hr c3.2xlarge - $1.72 - Total / hr c3.4xlarge - $2.59 - Total / hr c3.8xlarge - $3.68 - Total / hr c4.large - $0.55 - Total / hr c4.xlarge - $1.099 - Total / hr c4.2xlarge - $1.698 - Total / hr c4.4xlarge - $2.546 - Total / hr c4.8xlarge - $3.841 - Total / hr m4.large - $0.868 - Total / hr m4.xlarge - $1.365 - Total / hr m4.2xlarge- $1.931 - Total / hr
More Pricing Information
Best Alternatives
GraylogSophos UTM
Small Businesses
SolarWinds Papertrail
SolarWinds Papertrail
Score 8.9 out of 10
pfSense
pfSense
Score 9.5 out of 10
Medium-sized Companies
LogicMonitor
LogicMonitor
Score 8.9 out of 10
pfSense
pfSense
Score 9.5 out of 10
Enterprises
LogicMonitor
LogicMonitor
Score 8.9 out of 10
Palo Alto Networks Next-Generation Firewalls - PA Series
Palo Alto Networks Next-Generation Firewalls - PA Series
Score 9.5 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
GraylogSophos UTM
Likelihood to Recommend
7.8
(7 ratings)
9.0
(11 ratings)
Usability
-
(0 ratings)
10.0
(1 ratings)
Support Rating
3.6
(3 ratings)
7.9
(3 ratings)
User Testimonials
GraylogSophos UTM
Likelihood to Recommend
Graylog
For small companies, Graylog is the best solution possible. It's easy to configure and "just works." Above everything else, it's free. The only thing I hold against it is the fact that it's Linux-based. [This] makes sense because Elasticsearch is Linux-based. But Linux adds a layer of complexity that we don't need for something basic as a logging server. I'm pretty sure that we would have had a logging server years earlier if I had to convince quite a few decision-making people to go ahead with it anyway.
Read full review
Sophos
UTM works great if you want a solid, obvious firewall. There's not a lot of second-guessing as to what you are about to do with every change you make. If you incorporate their wireless access points and RED (remote ethernet device) for remote users or small offices, it's considerably much easier to set up than other comparable solutions. If you are looking to manage your firewalls via the cloud, you are out of luck.
Read full review
Pros
Graylog
  • Graylog does a great job of its core function: log aggregation, retention, and searching.
  • Graylog has a very flexible configuration. The backend for storage is Elasticsearch and MongoDB is used to store the configuration. You have to option to make your configuration as simple as possible by storing everything on one box, or you can scale everything out horizontally by using a cluster of Elasticsearch nodes and MongoDB servers with several Graylog servers pointed to all the necessary nodes.
  • Graylog does a good job of abstracting away a fair portion of Elasticsearch index management (sharding, creation, deletion, rotation, etc).
Read full review
Sophos
  • Firewall Protection. The protection is unmatched, setup it a little daunting, but once set up it pretty much runs itself.
  • Site-to-site VPN. Super easy to deploy so we are able to network all our sites together.
  • The DHCP server function is actually really nice, I prefer using it over the traditional way of using a DC for DHCP.
Read full review
Cons
Graylog
  • Support for more log sources
  • Event alerts/emails - Some cases where unable to separate data from multiple clients, and no easy fix
  • API - Limits results to 10,000 and can cause server to lockup on queries that exceed the limit
Read full review
Sophos
  • Better standard support, it used to be great, now, not so much (for paying customers, that only aquired the Hardware)
  • Better wireless solution, there is always room for that, now that everybody needs robust wifi, even at home!
  • Faster and more robust wireless Access Points, or different vendor-like compatibility.
Read full review
Usability
Graylog
No answers on this topic
Sophos
The interface is no non-sense and easy to understand. No need for any consultants to help implement this solution. The performance is consistent and solid. Paired with a good amount of firmware and definitions, it's hard to find any fault in this product. It's interoperability with other Sophos products make a compelling argument to invest in more Sophos products.
Read full review
Support Rating
Graylog
Community support does not give simple straightforward answers; simply search up Graylog Issues and look at some of the responses on the forums. The documentation is your only hope if you are on the free version, as you can NOT purchase only support. The few times I have worked with Graylog Enterprise support they were great though.
Read full review
Sophos
I find the support fair. The wait can be frustrating when dealing with fire. The pandemic has not helped with this. Although the wait can be long, the support reps are knowledgeable and was able to resolve the issues I was facing.
Read full review
Alternatives Considered
Graylog
In terms of log aggregation, the free product fully stacks up with the competitors listed. Full control over the data ingests for flexible configuration. Graylog even better on that front than AlienVault USM because you cannot configure the variable mapping. We haven't used the threat exchange stuff or correlation. But with regex searches, we have created function dashboards that show threat theater pictures of our network based on logs from our firewall.
Read full review
Sophos
I would rate Sophos second on this list right below Webroot. Webroot has an easier user interface and policy builder. However, Sophos would be on top of its UI would be improved. I would rank CrowStrike third and McAfee last. Sophos is great for complex environments that have multiple needs.
Read full review
Return on Investment
Graylog
  • Graylog is just less expensive than some other options which meant it fit into our budget otherwise we might not be able to justify a higher cost.
  • Being able to track issues that we normally couldn't track using other tools is a bonus to help us know of any issues we have and can fix before an outage or failure that could potentially cost money.
  • We have had to spend more time than I would like to understand and customize Graylog which has taken time away from other tasks and projects.
Read full review
Sophos
  • Sophos has provided a secure Firewall for us.
  • Integration with Sophos Central makes it easier to manage both.
  • Site to site VPN Failover groups has caused more trouble than it's worth.
  • High availability doesn't recognize when you are restarting for an update.
Read full review
ScreenShots