Logstash vs. SentinelOne Singularity

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Logstash
Score 9.0 out of 10
N/A
N/AN/A
SentinelOne Singularity
Score 8.9 out of 10
N/A
SentinelOne is endpoint security software, from the company of the same name with offices in North America and Israel, presenting a combined antivirus and EDR solution.
$4
per agent, per month
Pricing
LogstashSentinelOne Singularity
Editions & Modules
No answers on this topic
Singularity Ranger IoT
$4
per agent, per month
Singularity Core
$6
per agent, per month
Singularity Control
$8
per agent, per month
Singularity Complete
$12
per agent, per month
Singularity Cloud
$36
per VM/Kubernetes worker node, per month
Offerings
Pricing Offerings
LogstashSentinelOne Singularity
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
LogstashSentinelOne Singularity
Features
LogstashSentinelOne Singularity
Endpoint Security
Comparison of Endpoint Security features of Product A and Product B
Logstash
-
Ratings
SentinelOne Singularity
9.1
15 Ratings
7% above category average
Anti-Exploit Technology00 Ratings9.514 Ratings
Endpoint Detection and Response (EDR)00 Ratings9.915 Ratings
Centralized Management00 Ratings8.815 Ratings
Hybrid Deployment Support00 Ratings8.17 Ratings
Infection Remediation00 Ratings9.615 Ratings
Vulnerability Management00 Ratings8.112 Ratings
Malware Detection00 Ratings9.715 Ratings
Best Alternatives
LogstashSentinelOne Singularity
Small Businesses
SolarWinds Papertrail
SolarWinds Papertrail
Score 8.9 out of 10
ThreatLocker
ThreatLocker
Score 9.4 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 9.3 out of 10
BlackBerry Protect (CylancePROTECT)
BlackBerry Protect (CylancePROTECT)
Score 9.1 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 9.3 out of 10
BeyondTrust Endpoint Privilege Management
BeyondTrust Endpoint Privilege Management
Score 9.9 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
LogstashSentinelOne Singularity
Likelihood to Recommend
9.0
(4 ratings)
9.3
(18 ratings)
Likelihood to Renew
-
(0 ratings)
10.0
(1 ratings)
Usability
9.0
(1 ratings)
8.6
(8 ratings)
Support Rating
-
(0 ratings)
9.2
(4 ratings)
User Testimonials
LogstashSentinelOne Singularity
Likelihood to Recommend
Elastic
Perfect for projects where Elasticsearch makes sense: if you decide to employ ES in a project, then you will almost inevitably use LogStash, and you should anyways. Such projects would include: 1. Data Science (reading, recording or measure web-based Analytics, Metrics) 2. Web Scraping (which was one of our earlier projects involving LogStash) 3. Syslog-ng Management: While I did point out that it can be a bit of an electric boo-ga-loo in finding an errant configuration item, it is still worth it to implement Syslog-ng management via LogStash: being able to fine-tune your log messages and then pipe them to other sources, depending on the data being read in, is incredibly powerful, and I would say is exemplar of what modern Computer Science looks like: Less Specialization in mathematics, and more specialization in storing and recording data (i.e. Less Engineering, and more Design).
Read full review
SentinelOne
It works extremely well for investigating the root cause analysis of events because you can see so much detail into what was happening before, after, and around the detective incident. A weak point would be when the AI gets a little over-aggressive or doesn’t quite understand the use case for specific tools. Our RMM tool was detected as a pup.
Read full review
Pros
Elastic
  • Logstash design is definitely perfect for the use case of ELK. Logstash has "drivers" using which it can inject from virtually any source. This takes the headache from source to implement those "drivers" to store data to ES.
  • Logstash is fast, very fast. As per my observance, you don't need more than 1 or 2 servers for even big size projects.
  • Data in different shape, size, and formats? No worries, Logstash can handle it. It lets you write simple rules to programmatically take decisions real-time on data.
  • You can change your data on the fly! This is the CORE power of Logstash. The concept is similar to Kafka streams, the difference being the source and destination are application and ES respectively.
Read full review
SentinelOne
  • Installs on all of our Windows machines and only requires 1 reboot for the install to finish.
  • It allows you to customize the UI and filters based on your use case.
  • Gives a very high level of visibility into any concerns you have or should have in your network.
Read full review
Cons
Elastic
  • It is heavy i.e., intensive as of now. Need to reduce overhead to save CPU/RAM consumption
  • Need to be more Kubernetes-friendly. Should support auto-scaling and K8s observability
  • Initial configuration is still complex. A seamless config procedure is still required
Read full review
SentinelOne
  • Possibly for compatibility with legacy Windows OS's and non Windows OS's.
  • Some settings are greyed out and unable to change but I believe this is to protect you from making a bad configuration change.
  • Could do better with reporting at the base level subscription.
Read full review
Likelihood to Renew
Elastic
No answers on this topic
SentinelOne
Reliable for simple installation and above all efficient
Read full review
Usability
Elastic
As I said earlier, for a production-grade OpenStack Telco cloud, Logstash brings high value in flexibility, compliance, and troubleshooting efficiency. However, this brings a higher infra & ops cost on resources, but that is not a problem in big datacenters because there is no resource crunch in terms of servers or CPU/RAM
Read full review
SentinelOne
There are some minor issues with the platform that can be mildly frustrating, but the overall performance, peace of mind, and ROI make it worth using. The management console is intuitive and easy to learn, the endpoint clients are simple but give IT professionals enough data to make management easy and simple
Read full review
Support Rating
Elastic
No answers on this topic
SentinelOne
Their support is good and quick to respond. The one issue we faced was when a non-protection issue arose there was a lot of dancing around trying to figure things out. This was frustrating as it took significantly longer to figure out issues. Lots of repetitive log gathers, screen caps, uninstalls that never seemed to resolve issues. Eventually, the product would be updated and the issue seemed to be resolved, but seemed to be the only solution.
Read full review
Alternatives Considered
Elastic
Logstash can be compared to other ETL frameworks or tools, but it is also complementary to several, for example, Kafka. I would not only suggest using Logstash when the rest of the ELK stack is available, but also for a self-hosted event collection pipeline for various searching systems such as Solr or Graylog, or even monitoring solutions built on top of Graphite or OpenTSDB.
Read full review
SentinelOne
SentinelOne had all of the major features that we were looking for. The other products either required too much administrative attention or were lacking key features. For example, one could be uninstalled by the end user. We required that the installation be password protected to protect against end user disabling or uninstalling. One product required manual intervention for all remediation which put to high a burden on limited staff. All products are always being revised so these may no longer be issues but they had a significant impact on our decision.
Read full review
Return on Investment
Elastic
  • Positive: LogStash is OpenSource. While this should not be directly construed as Free, it's a great start towards Free. OpenSource means that while it's free to download, there are no regular patch schedules, no support from a company, no engineer you can get on the phone / email to solve a problem. You are your own Engineer. You are your own Phone Call. You are your own ticketing system.
  • Negative: Since Logstash's features are so extensive, you will often find yourself saying "I can just solve this problem better going further down / up the Stack!". This is not a BAD quality, necessarily and it really only depends on what Your Project's Aim is.
  • Positive: LogStash is a dream to configure and run. A few hours of work, and you are on your way to collecting and shipping logs to their required addresses!
Read full review
SentinelOne
  • SentinelOne has already proved its value by stopping attacks that would have gone otherwise unnoticed until much later in their infection process.
  • The Vigilance team has provided quick response to threats that were not easily contained via the automated response SentinelOne's agents provide. This has given us a significant piece of mind.
Read full review
ScreenShots

SentinelOne Singularity Screenshots

Screenshot of SentinelOne