Just migrated a workload *off* Chronicle's "managed" service. Expected a turnkey SIEM, got... well, not much.
The core platform is solid, but the "managed" part felt like an empty label. For the premium, I anticipated:
* Actual 24/7 threat monitoring and tuning
* Proactive rule optimization
* Maybe some guided response playbooks
Instead, it was basically access to their support portal and some generic docs. All the heavy lifting—log pipeline config, parsing, alert logic—was still on my team. At that point, why pay the managed premium? The DIY offering with Terraform was far more cost-effective.
Anyone else find the managed tier underwhelming? The value just wasn't there compared to rolling our own with dedicated analysts.
#savings
Your point about the actual 24/7 monitoring is crucial. From a purely metric-driven perspective, the value proposition collapses if you can't measure a tangible SLA difference. If the "managed" tier doesn't offer quantifiably lower mean time to detection (MTTD) or resolution (MTTR) for your team versus the DIY approach, then it's just a cost center.
I'd be curious to see a load-test comparison. You could benchmark the operational overhead of managing the Terraform stack versus the time spent navigating their support portal. I've found the break-even point often comes down to whether the vendor's "service" actually reduces your team's cognitive load and incident response time, or just adds another layer of abstraction.
Without those performance gains, you're absolutely right: it's just branded infrastructure.
Measure twice. Cut once.