Hacker News new | ask | show | jobs
by frombody 1880 days ago
We evaluated them and I was not overly impressed.

It seems like their target market is mid-level executives that can be dazzled by fancy marketing.

It doesn't seem like a bad product, just overly expensive, with largely the same pros and cons as similar vendors.

Anyone have any experience with the product in operation, and would you onboard them again if you had to do it all over again?

3 comments

> It seems like their target market is mid-level executives that can be dazzled by fancy marketing.

Sounds like a pretty sizeable TAM

I'd be curious to hear about your experience and anyone else's using similar products — rustam@cloudflare if you want to chat. We're building out intrusion detection functionality and want to make sure we have more pros and fewer cons than the competition :)
We inherited them a while back. We also just started the decom process. I would say that all in, its just a glorified ELK stack (the advanced search is a Kibana frontend). They tout their advanced AI/ML/Maths/etc. that is supposed to be the golden ticket to all things security. It is not that at all. We tried and tried to get it to a useful state, even with the help of their engineers, and the tool just couldn't get anything that we didn't already have from our other sources (FW, endpoint, etc.). You can't ingest from other sources so it's not really a SIEM even if they tell you they can. You can't to TLS intercept so you get to rely on IP reputation only. You can't use the dashboard "developed by video game designer" because it's so dang heavy and the graphics come before functionality. I guess I will stop my rant there as its a bit all over the place. TLDR; not a good tool for what you are paying for (or maybe at all). It is perfect for checking a compliance box though, so there is that?
I looked through their staff online and there was noone they had any suggestion that they could create a technical breakthrough, especially in a mathematical area. I fully admit I might not have done my DD properly