No more typing reviews! Try our Samantha, our new voice AI agent.

Exabeam vs LogRhythm SIEM vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Exabeam is 1.6%, up from 1.3% compared to the previous year. The mindshare of LogRhythm SIEM is 2.5%, down from 3.1% compared to the previous year. The mindshare of NetWitness Platform is 0.9%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.5%
Exabeam1.6%
NetWitness Platform0.9%
Other95.0%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2265966 - PeerSpot reviewer
Enterprise Account Manager South at a outsourcing company with 201-500 employees
Advanced analytics have transformed our threat detection and streamlined incident investigations
I would appreciate seeing additional dashboards in Exabeam Fusion SIEM or perhaps more options or the ability to customize them further. While we can customize them currently, there may be additional options available. I value the outcomes navigator because it matches the log piece to the use cases, which is helpful. The correlation rules are excellent. I am interested in whether there are additional threat intelligence feeds available that we could use, whether we can integrate our own, or if we could ingest different ones.
SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The user interface and the timelines they use are the most valuable features. The price model is very simple so that one can understand it easily and there are no surprises within it."
"The most valuable feature of Exabeam Fusion SIEM is the easy-to-use user interface."
"The user interface and the timelines they use are the most valuable features, and the price model is very simple so that one can understand it easily and there are no surprises within it."
"The solution has great technology, it's a very user-friendly product and a very comprehensive technology, the security on offer is very good, and cost-wise, compared to other technology, it's affordable."
"Exabeam includes machine learning features and out-of-the-box rules that we rely on."
"Timeline based analysis; good platform support"
"It is user-friendly and quite simple to use."
"The most valuable feature of Exabeam Fusion SIEM is the easy-to-use user interface."
"Straight away it was fairly evident that the LogRhythm application itself, and the agent roll-out, was straight out of the box."
"We raise a ticket to LogRhythm, and they will give us their support."
"It has centralized monitoring for our security operations. Therefore, it improves our analysts' work."
"I see LogRhythm SIEM as value for money; I would rate it eight out of ten."
"Over a period of time, LogRythm has improved a lot and the future, the road map of the product, really looks nice."
"We use this solution to examine disparate log sources and provide a cohesive method to search for anomalous behavior."
"The most valuable feature is that we can alternate incident automations."
"It seems like it will scale easily with the way our environment is set up."
"The development of use cases on the SSA console is quite user friendly, which means that the security analyst or the researcher does not have to learn another language."
"The most valuable features are the packet inspection and the automated incident response."
"Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients."
"The solution is reliable."
"Offers a good wireless feature."
"Their customer service is excellent, one of the best."
"The most valuable features are the integration and ease of use."
"Technically speaking, this is a good product."
 

Cons

"Exabeam lacks customizable dashboards, which might be a limitation if visualization is a key requirement."
"I would say the pricing for Exabeam Fusion SIEM is not cost prohibitive, but it was a little more than I initially thought."
"Updating the new release of Exabeam Fusion SIEM takes time and slows our performance."
"The product is good but the organization is rigid and not flexible in the way they operate."
"Exabeam's integration capabilities are not good, as Exabeam has a very limited number of integrations and no out-of-box integration, which is an area where Exabeam should improve."
"The initial setup of Exabeam Fusion SIEM is complex because it needs to integrate with the SIEM solution, but after this is complete it is straightforward."
"Exabeam needs to improve its documentation and provide more customization for dashboards and case management."
"We use the on-prem Exabeam product and face limitations using the web UI and administration of custom models and rules."
"Move it to Linux. I would like to see it get off the SQL Server."
"For me, room for improvement is the upgrade process."
"NextGen SIEM's integration with other software is good but could be improved."
"We have gone through a few versions which has caused a lot of instability. We have logged a lot of hours with professional services."
"Then, there is whole mention of hot versus warm and being able to keep data because SecondLook is terrible."
"Right now there is the concern about being able to gather all of the data into the system."
"LogRhythm SIEM can improve its user interface. The current interface is quite complex and can be challenging to navigate. While it offers many valuable features, understanding how to access and utilize them efficiently takes time. Simplifying the client console's user interface would significantly enhance the user experience and make it more user-friendly."
"One of the challenges of the SIEM for the LogRhythm 7 platform is the amount of time it takes to bring new log sources into the MDI."
"The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions."
"The product's licensing models are complex to understand. This particular area needs improvement."
"Cross Platform Integration could be improved."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"It is not so easy to customize this product."
"Health monitoring of the event sources and devices."
 

Pricing and Cost Advice

"There is an annual license required to use Exabeam Fusion SIEM. The price of the solution should be reduced."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
"Exabeam Fusion SIEM's pricing is reasonable."
"They have a great model for pricing that can be based either on user count or gigabits per day."
"Exabeam is not a cheap solution."
"The solution is expensive."
"It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that."
"I would rate the pricing 4 out of 5. There are no additional costs to the standard licensing fees."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"On a scale of one to ten, I'd rate the pricing of this solution as a seven - not too expensive but not cheap either. Regarding licensing costs, it varies depending on factors like being a partner or an end user, but there are no additional costs aside from standard licensing fees for the basic SIEM solution."
"The setup and licensing for small and medium size businesses is straightforward, though when it comes to the enterprise it pays to keep in mind the possibility for complications given all the extras and add-ons that may be required."
"I think the tool is reasonably priced. There is a need to pay per year towards the licensing costs of the tool."
"We have seen a measurable decrease in the mean time to detect and respond to threats. As it comes out new features and new releases, the window is becoming a lot narrower because you can pivot a lot more with the data. Therefore, the new features and enhancements are reducing that."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"It’s cheaper to run virtual machines in a VMware environment."
"We are on an annual license for the use of the solution."
"It is cheap."
"This is a pricey solution; it's not cheap."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
894,830 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Manufacturing Company
8%
Computer Software Company
8%
Comms Service Provider
7%
Financial Services Firm
10%
Construction Company
9%
Computer Software Company
8%
Comms Service Provider
8%
Financial Services Firm
11%
Comms Service Provider
10%
Construction Company
8%
Performing Arts
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise7
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on...
What needs improvement with Exabeam Fusion SIEM?
Exabeam's integration capabilities are not good, as Exabeam has a very limited number of integrations and no out-of-b...
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon you...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting an...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negoti...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with ...
 

Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
RSA Security Analytics
 

Overview

 

Sample Customers

Hulu, ADP, Safeway, BBCN Bank
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Los Angeles World Airports, Reply
Find out what your peers are saying about Splunk, IBM, Wazuh and others in Security Information and Event Management (SIEM). Updated: April 2026.
894,830 professionals have used our research since 2012.