We were asked recently, "what is the main difference between KELSIEM and Sumologic?".
The main difference is KELSIEM shortens investigation times because you don't need to drill down to access more information.
In Sumologic you have to join multiple datasets together, which is not only difficult but also slow, whereas with KELSIEM we perform correlation automatically at ingestion time, so you don't need to do secondary searches to find out relevant information.
For example, in KELSIEM every network event has a Username and computer name attached to it. Without KELSIEM, you have to first find the network event, then lookup the last known user login for that IP in another set of logs, then look up the computer name in another set of logs.
If you'd like to know more, shoot me an email at firstname.lastname@example.org.