LogRhythm Axon vs LogRhythm SIEM comparison


Comparison Buyer's Guide

Executive Summary

Categories and Ranking

LogRhythm Axon
Ranking in Log Management
Average Rating
Number of Reviews
Ranking in other categories
No ranking in other categories
LogRhythm SIEM
Ranking in Log Management
Average Rating
Number of Reviews
Ranking in other categories
Security Information and Event Management (SIEM) (7th)

Mindshare comparison

As of July 2024, in the Log Management category, the mindshare of LogRhythm Axon is 0.3%, up from 0.2% compared to the previous year. The mindshare of LogRhythm SIEM is 2.2%, down from 3.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
No other categories found
Security Information and Event Management (SIEM)

Featured Reviews

Chris Young - PeerSpot reviewer
Oct 11, 2022
Investigations are fast, intuitive, and easy to use, but silent log source detection needs to be added
For me, the most valuable feature of LogRhythm Axon is the log parsing technology it has. With my company, I'm the current policy builder, so not having to know an archaic, cryptic format and being able to visually grab a log and assign an element to a particular meta tag quickly and easily, and being able to run tests on that have been super useful. It's going to revolutionize the way the logs are identified and classified. It's super easy to navigate workflows on the user interface. It is intuitive, and Axon uses a lot of industry-standard icons. You can quickly identify where you need to go to find the tool you need to use, whether it's creating new policies, creating widgets on the dashboard, or doing administrative tasks such as creating users or assigning permissions. Regarding Axon's impact on our investigation time, the investigations are extremely fast, intuitive, and easy to use. You just have to click and drag. We can quickly drill down into things versus that with the current solution, which requires a little bit of training and understanding of the query languages. Axon provides a much better way. The fact that your investigations can be saved into a single query string that you can copy and share with your teammates is going to be a game changer. The GUI's intuitive nature and ease of use, along with being able to quickly go in and create accounts for new users in the application, have streamlined our onboarding process. It's much faster and easier than that with the existing tool. My hope is that they're going to actually integrate Axon with Active Directory so that it can be automated within your environment and you can handle that at user onboarding. The visibility provided by Axon is great. The number of widgets that it has currently, the proposed widgets that they hope to add, the number of meta tags, and the way you can manipulate and change the way that you view the data are really useful. You can create multiple dashboards with different views, pivots, and ways to analyze the data. It gives you good visibility into what's going on. It's critical for any organization, including ours, to have centralized visibility across a variety of log sources. By using different dashboards and widget configurations and by changing the way that you analyze and look at the data, you can quickly have different views. You will be able to see things that are not normally visible in current products and have a more holistic view. The Axon log management searchable database has significantly improved the way that we create investigations. The ability to click, choose, create queries, modify those queries, save them, and share them among people has been a significant improvement compared to that with the existing LogRhythm product which is very GUI driven. You have to understand the logic behind it. It's going to be a good change to be able to quickly copy, paste, and send an investigation and have the person run it rather than having to recreate it or be locked into using a shared investigation that you've created. The cloud-based architecture is going to really reduce the number of resources for SOC engineers because they're going to be able to focus more on data analysis and data concepts rather than on supporting software problems or hardware issues.
Oct 18, 2022
The solution reduced our investigation time from days to hours and assists in managing our workflows
One of the features that we use the most and find the most valuable includes the Web Console. My analysts really like the interface and the ability to build queries using point-and-click without having to write Query languages. My favorite feature is the actual Admin Console and the ability to monitor all aspects of the SIEM's health and the ability to build new use cases for my analysts to work with. We also use the Machine Data Intelligence feature for classifying and contextualizing logs. It does struggle with unknown log sources and we've had some challenges over the years getting new log sources incorporated into the MDI Fabric. The ability to authenticate successes and failures using MDI is incredibly easy. For the log sources that we bring into the SIEM, that work is pretty much done for us by the MDI. We don't have to do any additional work.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:


"The search feature within AXON is pretty robust. It's actually very fast in comparison to that in the previous platform. It's going to really help with investigations when they get rules put into the system."
"For me, the most valuable feature of LogRhythm AXON is the log parsing technology it has. With my company, I'm the current policy builder, so not having to know an archaic, cryptic format and being able to visually grab a log and assign an element to a particular meta tag quickly and easily and being able to run tests on that have been super useful. It's going to revolutionize the way the logs are identified and classified."
"Scalability-wise, LogRhythm Axon is a good product."
"As a SIEM, probably the best feature is that it can be tuned effectively. There are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed."
"Technical support is very helpful and responsive."
"When it comes to dealing with support, all my interactions have been great. Everyone has known what they're doing and have been quick to respond. They seem to always know the answer. I haven't stumped anybody yet."
"LogRhythm has increased productivity because all the tools that we need are in the web UI, allowing us to find threats on our network fast and efficiently."
"LogRhythm SIEM offers advanced features such as AI engine modules, machine learning, and threat intelligence integration, which help reduce false positives. Advanced analytics streamlines incident response processes, enabling incident responders to prioritize and automate alerts."
"The alarm functions have helped us cut down on the manual work. They bubble things up to us instead of our having to go look for stuff. Also, from an operational perspective, day to day, the Case Management functions are really useful for us. They allow us to track what we see in the incidents that we have."
"The correlation engine is extremely valuable because it uses machine learning to process information from the central manager and identifies issues in the network."
"Overall effectiveness is very good. I like how it is oriented to both analysts and technical support people. It's easily adopted by end users as much as by technologists."


"I'd give technical support a five out of ten. There are definitely areas that they can improve upon. Faster response times would be wonderful, and having more knowledgeable staff who provide the support would also be great."
"It's a very beta solution right now, and there are so many features that we would like to see added in, such as integration with Active Directory, which is essential for user management and for streamlining that process significantly."
"With LogRhythm Axon, stability and support are areas with shortcomings where improvements are required."
"The user interface needs improvement. The more the user can slide around and know what's going on, the better it will be."
"I would like to see APIs well-documented and public facing, so we can get to them all."
"I would like a more fuller implementation of STIX/TAXII so I can pull in some of the government lists without having to go implement a whole new STIX/TAXII platform."
"I would like to see our vulnerabilities counter. We will be using Tenable to fill that void right now."
"Right now there is the concern about being able to gather all of the data into the system."
"The built-in functionality of the solution for NDR, SOAR, SIEM, and EDS has room for improvement."
"My big thing is the easability. I don't like to go to two different systems. The fat client that you have to install to configure it, then the web console which is just for reporting and analysis. These features need to collapse, and it needs to be in a single solution. Going through the web solution in the future is the way to do it, because right now, it is a bit cumbersome."
"I would like to suggest that they should improve their usage of third party tools for making dashboards and reports. If they would create their own tools for dashboard and report, it would be much better in terms of security purposes."

Pricing and Cost Advice

"I know that there are certain payments to be made towards the licensing costs attached to the product...The pricing of LogRhythm Axon falls under the mid-range, in my opinion."
"In the context of our country, the price of this solution is too high."
"Everything is expensive with LogRhythm, and you don't get anything for free."
"It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"I would recommend talking to the rep. That's the biggest thing because they will know what questions to ask."
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"It is a very cost-effective solution."
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
793,295 professionals have used our research since 2012.

Top Industries

By visitors reading reviews
Computer Software Company
Performing Arts
Manufacturing Company
Educational Organization
Computer Software Company
Financial Services Firm

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available

Questions from the Community

What do you like most about LogRhythm AXON?
Scalability-wise, LogRhythm Axon is a good product.
What is your experience regarding pricing and costs for LogRhythm AXON?
I know that there are certain payments to be made towards the licensing costs attached to the product. LogRhythm Axon is neither a cheap nor an expensive solution, especially when compared to produ...
What needs improvement with LogRhythm AXON?
LogRhythm Axon has come up with the AI cloud concept in the market. When it comes to the AI cloud concept, you need to consider that every region has differences when it comes to data sovereignty. ...
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What do you like most about LogRhythm NextGen SIEM?
LogRhythm does a very good job of helping SOCs manage their workflows.
What is your experience regarding pricing and costs for LogRhythm NextGen SIEM?
LogRhythm's pricing and licensing are extremely competitive and it's one of the top three reasons we continue to invest in the platform.



Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM

Learn More

Video not available



Sample Customers

Information Not Available
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about LogRhythm Axon vs. LogRhythm SIEM and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.