Try our new research platform with insights from 80,000+ expert users

Cisco Threat Grid vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Threat Grid
Average Rating
7.6
Reviews Sentiment
7.7
Number of Reviews
3
Ranking in other categories
Threat Intelligence Platforms (30th)
LogRhythm SIEM
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
174
Ranking in other categories
Log Management (14th), Security Information and Event Management (SIEM) (9th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cisco Threat Grid is designed for Threat Intelligence Platforms and holds a mindshare of 1.1%, down 1.3% compared to last year.
LogRhythm SIEM, on the other hand, focuses on Security Information and Event Management (SIEM), holds 3.2% mindshare, down 4.2% since last year.
Threat Intelligence Platforms
Security Information and Event Management (SIEM)
 

Featured Reviews

Hasan A. Abu Al-Rob - PeerSpot reviewer
The solution is easy to implement, but the scalability and technical support must be improved
The solution is used for endpoint security The simplicity of implementation is valuable. The way the management file is integrated into the environment must be improved. Currently, I am using the solution. The tool is stable. We did not have any issues with it. I rate the tool’s scalability a…
Mokhammad Rakhman - PeerSpot reviewer
User-friendly dashboard and machine learning capabilities improve threat hunting efficiency
LogRhythm SIEM has strong machine-learning capabilities with behavioral rules and analysis. The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient. Analytics and behavioral analysis help me save time with rule creation. Its scalability allows me to add components as needed. Overall, LogRhythm SIEM offers end-to-end visibility with a reasonable price.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is easy to implement and is very scalable. It also comes with very good documentation. Cisco provides good technical support as well."
"The most valuable feature is the integration with firewalls. It's integrated with AMP so the ecosystem with equal solutions from Threat Grid is good with CISCO products."
"The simplicity of implementation is valuable."
"Overall effectiveness is very good. I like how it is oriented to both analysts and technical support people. It's easily adopted by end users as much as by technologists."
"The GUI is very intuitive and the solution has good integration."
"The user interface is good."
"The most useful feature that I've found so far is the search function. I like all the different ways you're able to search through metadata and the different ways you're able to correlate or search through logs to find out what's going on."
"We now have a central point of monitoring for all potential threats."
"The alarm functions have helped us cut down on the manual work. They bubble things up to us instead of our having to go look for stuff. Also, from an operational perspective, day to day, the Case Management functions are really useful for us. They allow us to track what we see in the incidents that we have."
"We take in around 750 million logs a day. We have a lot of products and that would be a lot of different panes of glass that we would have to look through otherwise. By centralizing, we can triage and take steps much more quickly than if we tried to man that many interfaces that come with the products."
"The most valuable feature is that we can alternate incident automations."
 

Cons

"I was told that the user interface could be more user friendly and easy in comparison to that of competitors. I remember that there is a competitor who has a much easier interface for many users to interact with."
"Support must be improved."
"They come in and have multiple management solutions but it doesn't scan or doesn't have the ability to look at every file extension."
"We do about 750 million a day and some days we do 715 million. Some days we do 820 million or 1.2 billion. But there's no way to drill in and find out: "Where did I get 400,000 extra logs today?" What was going on in my environment that I was able to absorb that peak? I have no way to identify it without running reports, which will produce a long-running PDF that I have to somehow compare to another long-running PDF... I would like to see like profiling behavior awareness around systems like they've been gunned to do around users with UEBA."
"Right now there is the concern about being able to gather all of the data into the system."
"I would really love to be able to take some of the data and not have to export it to a CSV file, so I can pull it into Excel to turn it into some other kind of graph."
"We're still struggling to get a real return on it and finding something that isn't false noise."
"My big thing is the easability. I don't like to go to two different systems. The fat client that you have to install to configure it, then the web console which is just for reporting and analysis. These features need to collapse, and it needs to be in a single solution. Going through the web solution in the future is the way to do it, because right now, it is a bit cumbersome."
"I would like to see more integration with more products that are out there within the same security field."
"We had a little bit of difficulty implementing a disaster recovery situation because it was leveraging only Microsoft native DNS and it wouldn't work with our Infoblox DNS deployment that we use in our environment. They've been working on that behind the scenes."
"Move it to Linux. I would like to see it get off the SQL Server."
 

Pricing and Cost Advice

"If I remember correctly, the licensing cost is a little bit higher than that of the competitor."
"The support which allows more customized to the environment when we are deploying new systems is called Professional Service and is very expensive. The technical annual support and there is an annual fee."
"The product is inexpensive than other tools."
"Look closely at the cost of licensing of other products. This should include setups and the need for support services. I did a RFQ to 2 other vendors before choosing this product."
"We work with French-speaking African countries, and it costs more than the average SIEM solution. Also, the pricing isn't too flexible. AlienVault, Splunk, and IBM QRadar are more suitable for customers on a tight budget."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"I think the tool is reasonably priced. There is a need to pay per year towards the licensing costs of the tool."
"In the context of our country, the price of this solution is too high."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms solutions are best for your needs.
854,338 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
11%
Energy/Utilities Company
9%
Manufacturing Company
8%
Computer Software Company
15%
Financial Services Firm
10%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Cisco Threat Grid?
The simplicity of implementation is valuable.
What needs improvement with Cisco Threat Grid?
The way the management file is integrated into the environment must be improved.
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
The SOAR capabilities need improvements as they currently require programming knowledge. A more user-friendly user interface with drag-and-drop features, similar to key competitors like Splunk, wou...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
 

Also Known As

Threat Grid, ThreatGrid
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

Center for Internet Security (CIS), ADP
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about CrowdStrike, Recorded Future, VirusTotal and others in Threat Intelligence Platforms. Updated: May 2025.
854,338 professionals have used our research since 2012.