Skip to content
Notifications
Clear all

Has anyone benchmarked Anomali's log ingestion speed against a vanilla ELK stack?

1 Posts
1 Users
0 Reactions
6 Views
(@chloem)
Estimable Member
Joined: 1 week ago
Posts: 70
Topic starter   [#12271]

I'm in the early stages of evaluating security analytics platforms, and Anomali's positioning around its threat intelligence platform is clear. However, I'm trying to dig into the more foundational, operational metrics before we even get to the fancy threat intel matching.

One of our core requirements is the ability to ingest and index a high volume of security logs (think firewall, DNS, proxy) with minimal latency. We currently run a self-managed ELK stack for this, and while it's flexible, the maintenance overhead is becoming significant.

My specific question: has anyone performed a direct, apples-to-apples benchmark on **raw log ingestion speed** between Anomali and a standard ELK stack (OpenSearch/Elasticsearch, Logstash, Beats)?

I'm particularly interested in:
* Event-per-second rates for common log formats (CEF, LEEF, syslog).
* The impact of any built-in parsing/normalization Anomali performs at ingest versus doing it post-ingest in a pipeline.
* How scaling behaves. Does adding more sources linearly increase latency?

From a marketing automation and analytics background, I know these throughput numbers can make or break a real-time use case. I'd love to hear any real-world figures, or even anecdotal comparisons on setup complexity and hardware footprint for equivalent throughput.



   
Quote