No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs Palo Alto Networks AutoFocus comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Log Management (11th), Security Information and Event Management (SIEM) (13th)
Palo Alto Networks AutoFocus
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
7
Ranking in other categories
Threat Intelligence Platforms (TIP) (20th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. LogRhythm SIEM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.7%, down 3.3% compared to last year.
Palo Alto Networks AutoFocus, on the other hand, focuses on Threat Intelligence Platforms (TIP), holds 1.4% mindshare, up 1.3% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.7%
Splunk Enterprise Security7.8%
IBM Security QRadar5.6%
Other83.9%
Security Information and Event Management (SIEM)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks AutoFocus1.4%
Recorded Future6.1%
Anomali3.9%
Other88.6%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

RS
Engineer Information Security at N-Able (Pvt) Ltd
Advanced threat detection has improved investigations but complexity and resource use need refinement
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat better and more matured in Wazuh compared to LogRhythm SIEM. Additionally, the parsers that I write for LogRhythm SIEM tend to get quite complex for log parsing, while with Wazuh, I can achieve a similar parser with much less complexity. Those are some of the pain points that some of our customers have been expressing. If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity. Therefore, they have been moved to Wazuh, which I am deploying for them. Even though LogRhythm SIEM has extremely good capabilities, their resource utilization is too heavy for certain customers, so if they could make a separate, lightweight version, that would be quite beneficial.
Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Seamless integration into existing ecosystem empowers effective threat detection
The most valuable feature of Palo Alto Networks AutoFocus is its seamless integration into the Palo Alto Networks ecosystem, allowing the threat intelligence feeds to be automatically consumed without manual effort. It uses the STIX format, which is automatically understood by the firewalls. AutoFocus also excels in behavioral analytics and reputation scoring, providing thorough threat analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The scalability is very good."
"We have NetFlow information going into it, so we can examine a lot of traffic patterns and anomalies, especially if something stands out and is not the baseline. This helps a lot."
"We are migrating from a different product (Curator) to this product, and we think LogRhythm is better than the older product that we were using."
"I don't feel like we just bought a product with LogRhythm, I felt that we bought a team."
"The most valuable feature is that we can alternate incident automations."
"For us, LogRhythm has given us the kind of insight we need to understand when those threats either are being recon-ed, found out, or when they're really trying a brute force attack to get at us."
"So far, my experience has been seamless."
"It seems like it will scale easily with the way our environment is set up."
"The feature that I like best is the dashboard."
"Palo Alto Networks AutoFocus has had a positive impact on my company as we can reduce the cost for the SOC investment, and we can also get good feedback on how to strengthen our network from the expertise people available."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
"It is very easy to install and set up AutoFocus."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"I would rate Palo Alto Networks AutoFocus a ten out of ten."
"It's a very good solution, it identifies critical attacks and alerts you."
"The most valuable feature is alerting."
 

Cons

"LogRhythm's SOAR and NDR features don't stack up well against competitors. maybe integrating theme functionality as the other do. But in general, it's okay."
"My big thing is the easability. I don't like to go to two different systems. The fat client that you have to install to configure it, then the web console which is just for reporting and analysis. These features need to collapse, and it needs to be in a single solution. Going through the web solution in the future is the way to do it, because right now, it is a bit cumbersome."
"The web and on-premise console interface should be the same instead of having a separate engine for each."
"I think a must-have feature would be better reporting. The reports do not provide information such as, who are your top ten end users generating the most activity within the environment, or appliances, per se, so that's very limited."
"Right now I know there's a big issue with reporting. It's challenging, at least for us, to do some of the reporting within the system itself."
"I would like to see support added for Exchange 2016, and Check Point OPSec Lea."
"We do about 750 million a day and some days we do 715 million. Some days we do 820 million or 1.2 billion. But there's no way to drill in and find out: "Where did I get 400,000 extra logs today?" What was going on in my environment that I was able to absorb that peak? I have no way to identify it without running reports, which will produce a long-running PDF that I have to somehow compare to another long-running PDF... I would like to see like profiling behavior awareness around systems like they've been gunned to do around users with UEBA."
"Better correlation of all events: We seem to get a lot of misinterpreted data coming from multiple sources."
"There were one or two instances where firewalls were not getting the threat intelligence feeds."
"It would be helpful to have better documentation for configuring and installing the solution."
"Palo Alto Networks AutoFocus is not affordable."
"It must be on-premises as well; it must have a server on-premises. It is a completely cloud-based product at present."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
 

Pricing and Cost Advice

"In the context of our country, the price of this solution is too high."
"The license cost is around $10 per MPS."
"When it comes time to renew, they say, "This is what you are using. This is what we can do for you." So, they work with you on pricing."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"The product is inexpensive than other tools."
"On a scale of one to ten, I'd rate the pricing of this solution as a seven - not too expensive but not cheap either. Regarding licensing costs, it varies depending on factors like being a partner or an end user, but there are no additional costs aside from standard licensing fees for the basic SIEM solution."
"I would rate the pricing 4 out of 5. There are no additional costs to the standard licensing fees."
"It is a very cost-effective solution."
"The solution is reasonably priced."
"It is expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Outsourcing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Performing Arts
14%
Outsourcing Company
11%
Manufacturing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
By reviewers
Company SizeCount
Small Business5
Large Enterprise4
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
What needs improvement with Palo Alto Networks AutoFocus?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed Service feature, which is still not available with Palo Alto. The MDR feature i...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself. I use the threat data correlation feature, which correlates with Cortex. We can use it for data corre...
What advice do you have for others considering Palo Alto Networks AutoFocus?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager. I confirm that we will publish these reviews on peerspot.com in written or audio format...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
Palo Alto Threat Intelligence Management
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Telkom Indonesia
Find out what your peers are saying about Splunk, IBM, Microsoft and others in Security Information and Event Management (SIEM). Updated: September 2026.
913,683 professionals have used our research since 2012.