No more typing reviews! Try our Samantha, our new voice AI agent.

Groundcover Observability Platform vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Groundcover Observability P...
Ranking in Log Management
41st
Average Rating
8.0
Reviews Sentiment
5.4
Number of Reviews
3
Ranking in other categories
Application Performance Monitoring (APM) and Observability (47th), AI Observability (25th)
LogRhythm SIEM
Ranking in Log Management
14th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Security Information and Event Management (SIEM) (14th)
 

Mindshare comparison

As of August 2026, in the Log Management category, the mindshare of Groundcover Observability Platform is 0.4%, up from 0.0% compared to the previous year. The mindshare of LogRhythm SIEM is 3.1%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM3.1%
Groundcover Observability Platform0.4%
Other96.5%
Log Management
 

Featured Reviews

EO
Software Engineer at FairMoney
Centralized observability has improved transaction monitoring and now reduces errors through faster troubleshooting
Groundcover Observability Platform is already very vast, and improving it requires proper training for even a software developer to be able to use it. A person in tech needs training to navigate the system. The UI is better, but it can be improved to include a more intuitive design that easily explains itself to users so that navigation is simpler. Many features are hidden, and you need someone who is experienced with the platform to direct you on how to view certain information or complete specific tasks and walk you through the process. It would be better if Groundcover focused more on simplifying the user interface and improving human-computer interactions of the dashboard to make it so easy for a new developer or specialist to navigate and get what they need quickly. Querying data from Groundcover is not easy if you do not have specific information. You cannot perform a wildcard search in the text box. If you go to the log and enter an error message, it will not bring any results for you. You must first specify the workload or pods you are looking for, then enter the error. You need to add tags and put in your strings to be able to search for your particular logs or errors. If you just put a wildcard search in the text box, it will not work and will appear as if there are no logs that relate to that search, when in reality the logs exist. Making it easier for developers, users, and specialists using Groundcover to navigate and get what they need without the help of an experienced person walking them through is very important. This improvement is not about functionality but more about making navigation easier.
SumitKumar20 - PeerSpot reviewer
Security Engineer at Granicus Inc.
Tool consistently aids in effective threat detection and monitoring but could benefit from improved log source management and resource optimization
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments. This information is crucial for planning future storage needs and scalability. The system monitor (collector) agent has issues with resource consumption. Even when not actively collecting data, the agent continues to consume significant CPU and memory resources, which can be particularly problematic for small business environments with limited resources. LogRhythm SIEM could improve by adding more default device support. While they have good default settings for devices such as Palo Alto firewalls, custom log sources often require extensive work. Increasing the number of supported devices with built-in policies and functionality would reduce the need for custom work. Competitive SIEM tools often provide more comprehensive coverage for various devices and vendors.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We switched to Groundcover Observability Platform primarily because of the difficult query syntax in our previous solution, and we chose Groundcover for their business model as they don't charge based on log storage, they provide the infrastructure, and from a security perspective, the data stays in-house, which wasn't the case with our previous tool."
"Groundcover Observability Platform has impacted my organization positively as it is the primary way we use observability in our company, so it has a significant impact."
"Troubleshooting is very fast compared to manual investigation or using the other forms of logging that we used to have, and downtime and errors have decreased because we are able to see our performance and workload pods performing better, increase CPU and memory resources as soon as usage goes above the threshold, and make our application more scalable and improve performance metrics, reducing the number of errors in the application by at least 70%."
"Groundcover Observability Platform scales effectively with our organization's growth as we add new environments and everything works great, and the migration from our old product went very smoothly, allowing us to deprecate it rather quickly."
"I find LogRhythm's log management capabilities to be beneficial."
"Even other products we have that feed into it, instead of having to watch all of them we only have to watch one. For example, we have CrowdStrike, so instead of having to pay attention that solution - because their dashboard doesn't really pop when an alarm comes up - we can see issues with the red on the LogRhythm alarm. That is very nice."
"We have seen a massive increase in the amount of data that we can collect, the type of things that we can see, the way we can look at logs, the way we can get alerts, and the way can create our own customer roles, which has allowed us to customize the work in our environment."
"PCI compliance was our main driver for purchasing LogRhythm, but it turns out there was just a ton of other information that really came from having that appliance, other than just being PCI compliant and checking that box for us."
"LogRhythm was really the first major product that we bought and the installation was awesome; it went as expected, moved along quickly, and provided value as soon as we were done with the installation."
"What LogRhythm really excels at is its stability, since, in all the deployments that I have been involved in, there's no break-and-fix at all."
"I would recommend NextGen SIEM to other users as it is a leading solution with new features at a better price than competitors like Splunk and QRadar."
"The solutions have been great for us; we use the SmartResponse to do most of our automation work for us, to block attacks, and to kick off users if they're doing anything malicious, and it's saved us a lot of man hours."
 

Cons

"I think it would be beneficial to see the body and content of API calls in the traces as a possible improvement."
"I would assess the stability and reliability of Groundcover Observability Platform as an eight out of ten; while I haven't experienced issues personally, I am aware they occasionally encounter some challenges."
"Querying data from Groundcover is not easy if you do not have specific information."
"We have had some issues that have taken a long time to resolve, various technical issues that have taken longer to resolve than we desire."
"Their ticketing system for managing cases can be improved. They can either do that or adopt some of the open-source ticket systems into theirs. The current system works and gets the job done, but it is very bare-bones and basic. There are some things that could be improved there. They should also bring in more threat intelligence into the product and also probably start to look into the integration of more cloud or SAS products for ingesting logs. They're doing the work, but with the explosion of COVID, a lot of businesses have started to move towards more cloud applications or SAS applications. There is a whole diverse suite of SAS products out there, which is a challenge for them and I get it. They seem to be focusing on the big ones, but it'll be nice to be able to, for example, pull in Microsoft logs from Office 365. They are working towards a better way of doing that, and they have a product in the pipeline to pull logs in from other SAS applications. The biggest thing for them is going to be moving away from a Windows Server infrastructure into a straight-up Linux, which is more stable in my eyes. For the backend, they can maybe move into more of an up-to-date Elastic search engine and use less of Microsoft products."
"The product's initial setup phase is pretty complex."
"We have a lot of issues with stability."
"We are seeing performance issues with the appliance."
"I think a must-have feature would be better reporting. The reports do not provide information such as, who are your top ten end users generating the most activity within the environment, or appliances, per se, so that's very limited."
"Stability has probably been one area where Health Checks have not been great with the product. We have been told that they are going to improve Health Checks on product, though we do struggle with them on a daily basis."
"The challenges are being spread out and using some of the technology that we do use, which are not easily integrated into the SIEM."
 

Pricing and Cost Advice

Information not available
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"I would rate the tool's pricing around eight out of ten."
"In the context of our country, the price of this solution is too high."
"The license cost is around $10 per MPS."
"We work with French-speaking African countries, and it costs more than the average SIEM solution. Also, the pricing isn't too flexible. AlienVault, Splunk, and IBM QRadar are more suitable for customers on a tight budget."
"If you don't have your staff, absolutely look into the co-pilot and factor that into your cost evaluation."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
37%
Financial Services Firm
9%
Recreational Facilities/Services Company
7%
Comms Service Provider
7%
Construction Company
12%
Financial Services Firm
9%
Outsourcing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
 

Questions from the Community

What needs improvement with Groundcover Observability Platform?
Groundcover Observability Platform is already very vast, and improving it requires proper training for even a software developer to be able to use it. A person in tech needs training to navigate th...
What is your primary use case for Groundcover Observability Platform?
My main use case for Groundcover Observability Platform is for application logs, insights, workload observability, and visibility.
What advice do you have for others considering Groundcover Observability Platform?
Groundcover Observability Platform is a good platform and very good to use. I would rate this review as highly positive.
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
 

Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

Information Not Available
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about Groundcover Observability Platform vs. LogRhythm SIEM and other solutions. Updated: July 2026.
909,725 professionals have used our research since 2012.