We performed a comparison between Runecast and VMware Aria Automation based on real PeerSpot user reviews.
Find out what your peers are saying about Palo Alto Networks, Wiz, Microsoft and others in Cloud Security Posture Management (CSPM)."The vulnerability management modules and the discovery and inventory are the most valuable features. Before using Wiz, it was a very manual process for both. After implementing it, we're able to get all of the analytics into a single platform that gives us visibility across all the systems in our cloud. We're able to correspond and understand what the vulnerability landscape looks like a lot faster."
"Our most important features are those around entitlement, external exposure, vulnerabilities, and container security."
"The solution is very user-friendly."
"Out of all the features, the one item that has been most valuable is the fact that Wiz puts into context all the pieces that create an issue, and applies a particular risk evaluation that helps us prioritize when we need to address a misconfiguration, vulnerability, or any issue that would put our environment into risk."
"The CSPM module has been the most effective. It was easy to deploy and covered all our accounts through APIs, requiring no agents. Wiz provides instant visibility into high-level risks that we need to address."
"The automation roles are essential because we ultimately want to do less work and automate more. The dashboards are easy to read and visually pleasing. You can understand things quickly, which makes it easy for our other teams. The network and infrastructure teams don't know as much about security as we do, so it helps to have a tool that's accessible and nice to look at."
"The security baseline and vulnerability assessments is the valuable feature."
"With Wiz, we get timely alerts for leaked data or any vulnerabilities already existing in our environment."
"Runecast is a good partner for VMware. Once we have installed it, we can see all the problems and issues. It also has VMware knowledge-based articles."
"Having an enterprise service catalog and being able to automate various parts of our infrastructure are among the most important components."
"quality-of-latest-release; Compared to the earlier versions, from my experience, the upgrade process is easier; for example, the compatibility checks. I also don't need to go and find out the resources that are required. It tells me in one report what the current environment is like and, if I want to go to the next level, what things I need to take care of. Based on that I can make things happen."
"The automation of the redundant tasks and the implementation of ServiceNow are huge for us..."
"If you do a deployment for a proof of concept, it is simple."
"The setup was straightforward. We upgraded to a newer version seamlessly. It worked really well."
"The solution is user-friendly and intuitive."
"The most valuable features for us are capacity planning as well as environment life management; putting in specific templates and workflows that we know are secure. That solidifies the environments that we're in or that are being provisioned. We also know that every environment being provisioned has a lifespan. It affects capacity, so it's great for budgeting, from my perspective, and good for my team."
"The most valuable feature is the portal where you can assign permissions to specific people to request specific items in the catalog and allow them to provision things for themselves. Or it enables them to request different services that you can create through vRO and vRA."
"The only small pain point has been around some of the logging integrations. Some of the complexities of the script integrations aren't supported with some of the more automated infrastructure components. So, it's not as universal. For example, they have great support for cloud formation and other services, but if you're using another type of management utility or governance language for your infrastructure-as-code automation components, it becomes a little bit trickier to navigate that."
"The remediation workflow within the Wiz could be improved."
"Given the level of visibility into all the cloud environments Wiz provides, it would be nice if they could integrate some kind of mechanism to better manage tenants on multiple platforms. For example, let's say that some servers don't have an application they need, such as an antivirus. Wiz could include an API or something to push those applications out to the servers. It would be great if you could remedy these issues directly from the Wiz platform."
"One significant issue is that the searches are case-sensitive, so finding a misconfigured resource can become very challenging."
"The only thing that needs to be improved is the number of scans per day."
"Wiz's reporting capabilities could be refined a bit. They are making headway on that, but more executive-style dashboards would be nice. They just implemented a community aspect where you can share documents and feedback. This was something users had been requesting for a while. They are listening to customer feedback and making changes."
"We wish there were a way, beyond providing visibility and automated remediation, to wait on a given remediation, due to a critical aspect, such as the cost associated with a particular upgrade... We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately."
"The reporting isn't that great. They have executive summaries, but it's only a compliance report that maps all current issues to specific controls. Whether you look at one subscription or project, regardless of the size, you will get a multipage report on how the issues in that account map to that control. Our CSO isn't going to read through that. He won't filter that out or show that to his leadership and say, "Here's what we're doing." It isn't a helpful report. They're working on it, but it's a poor executive summary."
"The product lacks network assessment capabilities. We cannot view our network assets or scan switches, routers, or IPs for vulnerabilities and issues."
"VMware should go the way of vROps, with everything in one machine, the ability to scale out, and a more distributed environment instead of having the usual centralized SQL database."
"Normally, on the first call to technical support, you don't get the right person. The log analysis takes a long time. This is something which should be improved."
"The stability needs a lot of work. The troubleshooting component of vRealize is a pain. The administration and the upgrades are not up to the mark. If they were able to improve on that, that would be the best thing and would make it much easier to run it in the enterprise."
"When it comes to the orchestration workflow, you're on your own. The documentation and resources are very limited, and you have to learn everything on your own."
"The initial setup was complex from beginning to delivery. The current version is a bit more complex than version 7 to deploy."
"The deployment mechanisms for the initial deployment of the product line lacks the appropriate documentation to give someone who's never used it before... There might be cases where someone wants to go to the website, go to the doc section, and do a step-by-step on how to deploy it. That's really not as brushed-up as other documents I've seen that they have. That would definitely be an improvement on their end."
"Multitenancy management is a little bit difficult to do, so it is an area that can be improved."
"We are migrating from vRA version 7 to 8, but the migration is really hectic and time-consuming. There are no straightforward paths to migrate. We are doing an entirely new deployment to go to vRA version 8.0, then somehow get all of the VMs to vRA 8.0. Therefore, it would have been great if VMware had some solutions to upgrade from vRA 7 to 8 seamlessly. This includes the management of all the objects or VMs from the older version. Unfortunately, it is not there."
Runecast is ranked 24th in Cloud Security Posture Management (CSPM) with 1 review while VMware Aria Automation is ranked 15th in Cloud Security Posture Management (CSPM) with 133 reviews. Runecast is rated 9.0, while VMware Aria Automation is rated 8.0. The top reviewer of Runecast writes "Helps with risk assessments for containers, assessing security, and ensuring container compliance". On the other hand, the top reviewer of VMware Aria Automation writes "Allows for a lot of orchestration or customization within our environment to suit our customers". Runecast is most compared with VMware Aria Operations, whereas VMware Aria Automation is most compared with Red Hat Ansible Automation Platform, VMware Aria Operations, vCloud Director, Morpheus and vCenter Orchestrator.
See our list of best Cloud Security Posture Management (CSPM) vendors.
We monitor all Cloud Security Posture Management (CSPM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.