Try our new research platform with insights from 80,000+ expert users

Devo vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.7
Devo enhances root cause remediation by 50%, offering cost savings, scalability, fast cloud deployment, and diverse client flexibility.
Sentiment score
5.7
LogRhythm SIEM enhances detection, response times, productivity, and security posture, offering cost-effectiveness and resource savings for medium-sized organizations.
 

Customer Service

Sentiment score
7.0
Devo's customer service is responsive and efficient, but improvements are needed in documentation and onboarding support.
Sentiment score
5.4
LogRhythm SIEM's support excels in expertise and quick resolutions, earning high satisfaction despite occasional delays.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
Cyber Security Analyst at Diyar United Company
Customer support is very helpful and effectively solves my problems.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
 

Scalability Issues

Sentiment score
7.6
Devo's cloud-based structure ensures seamless scalability, supporting diverse roles and extensive deployments for effective data handling and monitoring.
Sentiment score
7.8
LogRhythm SIEM is highly scalable, easily expands across environments, and integrates well, suitable for medium to large enterprises.
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
Cyber Security Analyst at Diyar United Company
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
Security Engineer at Granicus Inc.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
 

Stability Issues

Sentiment score
7.3
Devo is highly stable and reliable, with minimal issues and efficient management, evolving positively as a cloud-native service.
Sentiment score
4.7
LogRhythm SIEM is stable with high uptime, strong support, handling large data, though updates may affect stability.
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
Security Engineer at Granicus Inc.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
 

Room For Improvement

Devo faces performance, customization, integration, and pricing challenges, needing improvements in AI, reporting, and dashboard capabilities.
LogRhythm SIEM needs improved integration, user interface, automation, scalability, documentation, and compatibility with non-mainstream platforms and Linux.
Integrations with other sandboxes could be improved to better interpret data using AI and machine learning models.
Strategic Account Executive at a computer software company with 51-200 employees
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
Cyber Security Analyst at Diyar United Company
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
Security Engineer at Granicus Inc.
A more user-friendly user interface with drag-and-drop features, similar to key competitors like Splunk, would be beneficial.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
 

Setup Cost

Devo offers competitive pricing with flexible licensing, though metadata costs and subscription models may affect overall expenses.
LogRhythm SIEM is cost-effective for enterprises, offering transparent pricing and flexible licensing, yet incurs higher professional service fees.
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
Cyber Security Analyst at Diyar United Company
The license cost is around $10 per MPS.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
 

Valuable Features

Devo's Activeboards offer intuitive, fast data visualization with high-speed queries, real-time analytics, and seamless integration for effective insights.
LogRhythm SIEM offers advanced threat detection, user-friendly interface, comprehensive log management, and automated alerts for enhanced security efficiency.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
Strategic Account Executive at a computer software company with 51-200 employees
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
Cyber Security Analyst at Diyar United Company
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
Security Engineer at Granicus Inc.
 

Categories and Ranking

Devo
Ranking in Log Management
28th
Ranking in Security Information and Event Management (SIEM)
24th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
23
Ranking in other categories
IT Operations Analytics (11th), AIOps (20th)
LogRhythm SIEM
Ranking in Log Management
13th
Ranking in Security Information and Event Management (SIEM)
9th
Average Rating
8.4
Reviews Sentiment
6.4
Number of Reviews
175
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Devo is 1.1%, up from 1.0% compared to the previous year. The mindshare of LogRhythm SIEM is 2.6%, down from 3.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
LogRhythm SIEM2.6%
Devo1.1%
Other96.3%
Security Information and Event Management (SIEM)
 

Featured Reviews

FR
Strategic Account Executive at a computer software company with 51-200 employees
Has improved investigative workflows with interactive dashboards and simplified data correlation
The data analytics cloud component focuses on real-time analytics, which is very impressive. The SIEM collects and correlates logs data from different sources and can integrate with ServiceNow, hardware asset management, and software asset management. The security orchestration, automation, and response (SOAR) is another valuable feature. The security data platform serves as the foundation of Devo. Regarding advanced query capabilities, Devo offers several models including query logs, visual query builder, language integrated query, and SQL, with SQL being the most frequently used querying data capability. The single pane of glass that Devo offers is the SOC. The tools in Devo's active ports are for investigating, not just viewing data. They are more interactive than other market solutions. The drill-down reports capabilities allow analysts to click on any element in a widget. When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins. This is particularly important for enterprise companies with numerous endpoints and users. The dynamic filtering of inputs significantly reduces the time cybersecurity analysts spend trying to figure out failed logins and identifying false positives.
SK
Cyber Security Analyst at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
879,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
10%
University
8%
Manufacturing Company
6%
Computer Software Company
12%
Government
9%
Manufacturing Company
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise11
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise38
Large Enterprise83
 

Questions from the Community

What is your experience regarding pricing and costs for Devo?
Compared to Splunk or SentinelOne, it is really expensive. I rate the product’s pricing a nine out of ten, where one is cheap and ten is expensive.
What needs improvement with Devo?
The single pane of glass that Devo offers could be improved. The tools in Devo's active ports need enhancement in their investigative capabilities. The drill-down reports capabilities, while useful...
What is your primary use case for Devo?
During my time at MetaBase Q and as a partner integrator of ServiceNow, I had the chance to understand and be part of projects integrating SOCs, NOCs, and Security Operation Centers with Devo. Most...
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
 

Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about Devo vs. LogRhythm SIEM and other solutions. Updated: December 2025.
879,422 professionals have used our research since 2012.