No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs Microsoft Defender XDR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.5
LogRhythm SIEM enhances security, efficiency, and compliance, offering rapid threat detection and cost-effectiveness, especially for medium-sized organizations.
Sentiment score
7.3
Microsoft Defender XDR enhances security efficiency and cost savings by consolidating tools, improving threat management, and maximizing ROI.
We can quarantine and isolate a device within minutes.
Information Security Analyst at a educational organization with 10,001+ employees
Microsoft Defender XDR has saved me at least 50% of my time.
House security operator at Cypress Creek Renewables
It helped stop multiple intrusion points where we would have had millions in lost revenue if the attackers got in.
Network Technician at T. Baker Smith, LLC
 

Customer Service

Sentiment score
5.5
LogRhythm SIEM's support is praised for efficiency and expertise, though some users note occasional variability in service quality.
Sentiment score
6.2
Microsoft Defender XDR users experience mixed support satisfaction, desiring better documentation and faster issue escalations for improved service.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
Cyber Security Engineer at Diyar United Company
LogRhythm SIEM is quite complex, but that complexity allows us to specifically tailor a solution to the customer while some others are not as flexible.
Engineer Information Security at N-Able (Pvt) Ltd
Customer support is very helpful and effectively solves my problems.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
You get stuck in low-level support for way longer than you should, instead of them escalating the issue up the chain.
Enterprise Application Engineer at a legal firm with 1,001-5,000 employees
It's critical to escalate SEV B issues immediately to a domestic engineer.
Infrastructure engineer at Cetera Financial Group
Once issues are escalated to the second or third layer, the support is much better.
Cyber Security Engineer at a financial services firm with 1-10 employees
 

Scalability Issues

Sentiment score
6.6
LogRhythm SIEM excels in scalability and adaptability for growth, despite hardware and licensing challenges in high-volume environments.
Sentiment score
7.0
Microsoft Defender XDR is scalable, adaptable to environments, supporting cloud or on-premises, despite some licensing and complexity issues.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
Cyber Security Engineer at Diyar United Company
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
Security Engineer at Granicus Inc.
My concern is about the scale of events and alerts being generated, and the product is doing a very good job of only surfacing the important items for us.
Vice President, Information Technology at a construction company with 201-500 employees
It has a very good integration system that integrates with all Azure services, all threat intelligence data models, and integrates very well with other systems such as Palo Alto.
Infosec at a government with 10,001+ employees
Microsoft Defender XDR shows tremendous scalability, much more so than on-premises solutions.
Infrastructure engineer at Cetera Financial Group
 

Stability Issues

Sentiment score
5.0
LogRhythm SIEM is stable and resilient, though some experience hardware issues and setup challenges under high data volumes.
Sentiment score
8.1
Microsoft Defender XDR is stable, with minimal downtime, rare bugs, few false positives, and high user satisfaction ratings.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
Security Engineer at Granicus Inc.
The service has remained consistently online, with any issues isolated to specific components, suggesting a well-designed and modular architecture.
Senior System Engineer at a sports company with 5,001-10,000 employees
The services within our ecosystem have been reliable, meeting their SLAs.
Infrastructure engineer at Cetera Financial Group
It provides high-fidelity signals.
Information Security Analyst at a educational organization with 10,001+ employees
 

Room For Improvement

LogRhythm SIEM needs improved integration, customization, performance, usability, better support, and enhanced documentation for optimal user experience.
Microsoft Defender XDR requires enhancements in licensing, user-friendliness, integration, automation, cloud compatibility, pricing, and dashboard comprehensiveness.
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
Cyber Security Engineer at Diyar United Company
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
Security Engineer at Granicus Inc.
If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity.
Engineer Information Security at N-Able (Pvt) Ltd
The licensing process needs improvement and clarification.
Owner at a consultancy with 11-50 employees
Improvements are needed in automated response capabilities.
Security manager at a consultancy with 10,001+ employees
If you have a central location where you perform one isolation method, all other potentially affected systems that have been touched may also be isolated simultaneously.
CISO at Loeb & Loeb LLP
 

Setup Cost

LogRhythm SIEM offers competitive, transparent pricing suitable for medium to large businesses, with high initial setup costs.
Enterprise opinions on Microsoft Defender XDR's pricing vary, impacted by company size, existing infrastructure, and regional differences.
The license cost is around $10 per MPS.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
Cyber Security Engineer at Diyar United Company
There are certainly savings when using Microsoft Defender XDR, which can range from 30%, 40%, and even up to 50%.
Director, Sales at a tech vendor with 201-500 employees
I would rate the pricing as eight out of ten, indicating it is a reasonable cost for the product.
Security manager at a consultancy with 10,001+ employees
Microsoft purposefully obfuscates this through marketing ploys to hide costs.
Senior System Engineer at a sports company with 5,001-10,000 employees
 

Valuable Features

LogRhythm SIEM offers AI-powered features, seamless integration, and user-friendly dashboards for enhanced security and operational efficiency.
Microsoft Defender XDR enhances security with threat visibility, automation, and integration, streamlining operations while reducing breach risks and saving time.
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
Cyber Security Engineer at Diyar United Company
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
Security Engineer at Granicus Inc.
With Microsoft threat intelligence information, it detects various types of threats, including insider attacks, malicious content, and data exfiltration.
Security manager at a consultancy with 10,001+ employees
This allows us to secure our systems in advance and proactively improve security, rather than waiting for incidents to occur.
Works at Hometrack
Once we have it on the security dashboard, we can see a real-time storyline.
Information Security Analyst at a educational organization with 10,001+ employees
 

Categories and Ranking

LogRhythm SIEM
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Log Management (12th), Security Information and Event Management (SIEM) (9th)
Microsoft Defender XDR
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
108
Ranking in other categories
Endpoint Detection and Response (EDR) (8th), Extended Detection and Response (XDR) (4th), Microsoft Security Suite (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. LogRhythm SIEM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.6%, down 3.2% compared to last year.
Microsoft Defender XDR, on the other hand, focuses on Extended Detection and Response (XDR), holds 4.9% mindshare, down 6.7% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.6%
Splunk Enterprise Security7.2%
Wazuh5.8%
Other84.4%
Security Information and Event Management (SIEM)
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Microsoft Defender XDR4.9%
CrowdStrike Falcon9.9%
Wazuh6.8%
Other78.4%
Extended Detection and Response (XDR)
 

Featured Reviews

SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
KO
House security operator at Cypress Creek Renewables
Advanced threat hunting saves significant time in tracking and responding to incidents
Microsoft Defender XDR could be improved with a lower price. My main suggestion would essentially be what Copilot is providing, which is a single pane of glass, so I don't have to go to different windows. That's just a workflow consideration for me. It would be great to have all the information centralized into one particular data app. If I need to open up extra ones, I can, however, I would appreciate a future where everything I need is right there on one single pane of glass. Beyond that, there's really nothing else I see that I would want Microsoft to improve.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
9%
Financial Services Firm
9%
Construction Company
8%
Comms Service Provider
7%
Computer Software Company
11%
Financial Services Firm
8%
Manufacturing Company
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise38
Large Enterprise83
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise26
Large Enterprise40
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
What do you like most about Microsoft 365 Defender?
Microsoft Defender XDR provides strong identity protection with comprehensive insights into risky user behavior and potential indicators of compromise.
What is your experience regarding pricing and costs for Microsoft 365 Defender?
My experience with pricing, setup, costs, and licensing of Microsoft Defender XDR is tied to our E5 subscription, which is very straightforward for us. We also purchase the uplift for our mobile us...
What needs improvement with Microsoft 365 Defender?
I am not aware of a mobile app that would be available for my team. With a single analyst, if she is ever away, it would be beneficial to have easier access. While she can use the web portal, the e...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
Microsoft 365 Defender, Microsoft Threat Protection, MS 365 Defender
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Accenture, Deloitte, ExxonMobil, General Electric, IBM, Johnson & Johnson and many others.
Find out what your peers are saying about LogRhythm SIEM vs. Microsoft Defender XDR and other solutions. Updated: May 2023.
885,728 professionals have used our research since 2012.