No more typing reviews! Try our Samantha, our new voice AI agent.

LogLogic vs LogRhythm SIEM vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of LogLogic is 0.9%, up from 0.2% compared to the previous year. The mindshare of LogRhythm SIEM is 2.5%, down from 3.1% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.1%, down from 9.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.1%
LogRhythm SIEM2.5%
LogLogic0.9%
Other89.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

it_user126030 - PeerSpot reviewer
Senior ICT Solutions Expert at a comms service provider with 1,001-5,000 employees
I've evaluated Splunk and IBM Q1 but LogLogic is the best choice for log management. SIEM functionality needs improvement.
If you are searching for log management solution, LogLogic is probably the best choice. The SIEM functionality is not at that level, and I suggest instead to choose another SIEM solution (eg: IBM Q1). In my experience, a good practice is to separate log management from SIEM in a way that they are two separate systems.
SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Having logs in a central location helps with troubleshooting, forensic investigations, and legal investigations."
"If you are searching for log management solution, LogLogic is probably the best choice."
"As far as technical support, professional support, and overall organizational support, LogRhythm has probably been one of the best companies that I have worked with since I have been in technology."
"SOAR is integrated with the dashboard that we use for threat management. Because it's all integrated, it is useful for us when we deploy something on-prem."
"I have found the Advanced Intelligence Engine has provided the most value to us because we can customize alarms based on our requirements and have created hundreds of alarms that notify different people for different scenarios."
"LogRhythm is a perfect example of "Garbage In, Garbage Out" in Information Security—LogRhythm reports on the Cardholder Data Environment (CDE) activity are only as reliable as the data coming in."
"The security operation center is excellent."
"LogRhythm NextGen SIEM is customizable, simple to manage, and there are many features, and the solution does not require an expert to be able to use it, anyone can use it."
"With LogRhythm, our SIEM solution offers more of a rounded perspective, especially from security, making sure they are not only operational, but they're operational in a security conscious manner."
"The most valuable features of the solution are network monitoring, user behavior analytics, and log collection."
"It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions."
"I very much enjoy Splunk's robust search nature, which enables me to find the data I want within the data I have."
"There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
"The flexibility of the search capability is most valuable. You can use it for more than just a basic log aggregator. It is powerful in that regard."
"The initial setup is really straightforward; it's one of the easiest installations."
"Splunk is appropriate for small to medium-sized projects, and it should be calculated for large projects."
"The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
"Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
 

Cons

"Customer Service: On a scale of 1-5, 0. They say the right things but don't deliver when it counts."
"Definitely SIEM – other vendors have gone a lot further in developing SIEM functionality and made a lot more in this area."
"A cleaner interface. I keep getting confused and forgetting where everything is."
"This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them."
"We do about 750 million a day and some days we do 715 million. Some days we do 820 million or 1.2 billion. But there's no way to drill in and find out: "Where did I get 400,000 extra logs today?" What was going on in my environment that I was able to absorb that peak? I have no way to identify it without running reports, which will produce a long-running PDF that I have to somehow compare to another long-running PDF... I would like to see like profiling behavior awareness around systems like they've been gunned to do around users with UEBA."
"I work in a highly regulated industry. I know the product has compliance mechanisms, but being able to get more governance surrounding some of the compliance would be helpful."
"Some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity."
"My rating of eight out of 10 for LogRhythm is because, while I think the support is great, the solution is a little rough around the edges."
"It should be improved for automated setup and auto-configuration. There should be ease of integration and ease of setup."
"Going into the beta, stability was very good, but in the beta it's not been as great for us lately."
"The UI can be improved. Dashboards and reports can be better in terms of graphics."
"The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more."
"Most importantly, Splunk can be outrageously expensive. That is the problem with both Splunk and Sentinel. Their pricing literally explodes based on the amount of data you feed in."
"I feel the solution to be too slow."
"One thing that I probably dislike the most about the Splunk product is their support."
"When you get into large amounts of data, Splunk can get pretty slow."
"The GUI can be improved. Splunk has always suffered from having a kind of goofy UI, it needs some updating."
"There is improvement needed when importing from some types of data sources."
 

Pricing and Cost Advice

Information not available
"I would rate the tool's pricing around eight out of ten."
"When it comes time to renew, they say, "This is what you are using. This is what we can do for you." So, they work with you on pricing."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"The license cost is around $10 per MPS."
"If you don't have your staff, absolutely look into the co-pilot and factor that into your cost evaluation."
"I give the price a six out of ten."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that."
"Splunk is really expensive."
"Splunk Enterprise Security is expensive but the solution is equipped with a lot of features."
"Splunk Enterprise Security is an expensive solution."
"It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it. There is just the licensing fee. That's all."
"In addition to the licensing fee, there is also a support and maintenance charge."
"I work on the technical side, so I don't know precise figures. However, I know that Splunk is a premium product, so it's somewhat costly. Still, you get a lot of unique features for the money."
"Splunk Enterprise Security's pricing is pretty competitive."
"The pricing depends on the bandwidth of an organization and is good compared to some SIEM tools. IBM, for example, is quite costly. But Microsoft Sentinel is notably cheaper."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
892,868 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
10%
Construction Company
9%
Computer Software Company
8%
Comms Service Provider
7%
Financial Services Firm
14%
Manufacturing Company
9%
Computer Software Company
9%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
By reviewers
Company SizeCount
Small Business117
Midsize Enterprise51
Large Enterprise269
 

Questions from the Community

Ask a question
Earn 20 points
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon you...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting an...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negoti...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
 

Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
No data available
 

Overview

 

Sample Customers

Astrium, Cerner, Children's Hospital, Effiage, Lavego, Plantronics, Skipton Building Society, The Body Shop, The Lowry, University of Manitoba
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk, IBM, Wazuh and others in Security Information and Event Management (SIEM). Updated: April 2026.
892,868 professionals have used our research since 2012.