No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs Palo Alto Networks AutoFocus comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Log Management (14th), Security Information and Event Management (SIEM) (14th)
Palo Alto Networks AutoFocus
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
7
Ranking in other categories
Threat Intelligence Platforms (TIP) (21st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. LogRhythm SIEM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.6%, down 3.1% compared to last year.
Palo Alto Networks AutoFocus, on the other hand, focuses on Threat Intelligence Platforms (TIP), holds 1.3% mindshare, up 1.1% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.6%
Splunk Enterprise Security7.6%
IBM Security QRadar5.5%
Other84.3%
Security Information and Event Management (SIEM)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks AutoFocus1.3%
Recorded Future6.4%
CrowdStrike Falcon4.4%
Other87.9%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

SumitKumar20 - PeerSpot reviewer
Security Engineer at Granicus Inc.
Tool consistently aids in effective threat detection and monitoring but could benefit from improved log source management and resource optimization
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments. This information is crucial for planning future storage needs and scalability. The system monitor (collector) agent has issues with resource consumption. Even when not actively collecting data, the agent continues to consume significant CPU and memory resources, which can be particularly problematic for small business environments with limited resources. LogRhythm SIEM could improve by adding more default device support. While they have good default settings for devices such as Palo Alto firewalls, custom log sources often require extensive work. Increasing the number of supported devices with built-in policies and functionality would reduce the need for custom work. Competitive SIEM tools often provide more comprehensive coverage for various devices and vendors.
Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Seamless integration into existing ecosystem empowers effective threat detection
The most valuable feature of Palo Alto Networks AutoFocus is its seamless integration into the Palo Alto Networks ecosystem, allowing the threat intelligence feeds to be automatically consumed without manual effort. It uses the STIX format, which is automatically understood by the firewalls. AutoFocus also excels in behavioral analytics and reputation scoring, providing thorough threat analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has saved us a lot of time."
"It has been the easiest SIEM platform that I have worked with or seen in production."
"It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable."
"The customer service team is excellent and they have resolved anything we have thrown at them in a timely fashion."
"Compliance reporting is another great feature of this product. It has built in reports right out of the box."
"All in all, it's one of the best SIEMs, as a total package, that I've worked with."
"LogRhythm really helps with our cybersecurity exposure because it gives us insights to make us more proactive versus reactive regarding events happening in our environment."
"LogRhythm SIEM has strong machine-learning capabilities with behavioral rules and analysis."
"The most valuable feature is alerting."
"It is very easy to install and set up AutoFocus."
"It's a very good solution, it identifies critical attacks and alerts you."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"The logs play a crucial role as they contribute to blocking unwanted Internet traffic."
"Palo Alto Networks AutoFocus has had a positive impact on my company as we can reduce the cost for the SOC investment, and we can also get good feedback on how to strengthen our network from the expertise people available."
"The feature that I like best is the dashboard."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
 

Cons

"I would like to see APIs well-documented and public facing, so we can get to them all."
"More features that I would like to see more development in are the automation and the smart response."
"Sometimes the error-logging is not altogether helpful. For example, on an upgrade, a systems data processor, a Windows box, was throwing an error code like 1083. Then it just stopped and it died right out of the installer and nobody looked. We searched through Google and what it means is the Windows Firewall wasn't turned on so that it could create a rule for the product. Why wouldn't they bubble up that description so that I wouldn't have to call support and I could just know, "Okay, the firewall wasn't turned on. Turn it back on. Re-run the installer and keep going.""
"I think they're limited now with this to Office 365."
"Scalability misses the mark sometimes, especially when you have an integrated disaster recovery built into the solution."
"There is room for improvement with separate running sources or better integration."
"In terms of blind spots, we are looking for more improvements since we don't have visibility over everything."
"I work in a highly regulated industry. I know the product has compliance mechanisms, but being able to get more governance surrounding some of the compliance would be helpful."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"Palo Alto Networks AutoFocus is not affordable."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
"It must be on-premises as well; it must have a server on-premises. It is a completely cloud-based product at present."
"It would be helpful to have better documentation for configuring and installing the solution."
"There were one or two instances where firewalls were not getting the threat intelligence feeds."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
 

Pricing and Cost Advice

"The setup and licensing for small and medium size businesses is straightforward, though when it comes to the enterprise it pays to keep in mind the possibility for complications given all the extras and add-ons that may be required."
"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"When it comes time to renew, they say, "This is what you are using. This is what we can do for you." So, they work with you on pricing."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"LogRhythm's pricing and licensing is extremely competitive and it's one of the top three reasons we continue to invest in the platform."
"The support which allows more customized to the environment when we are deploying new systems is called Professional Service and is very expensive. The technical annual support and there is an annual fee."
"NextGen SIEM's pricing is moderate."
"It is expensive."
"The solution is reasonably priced."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
9%
Outsourcing Company
8%
Comms Service Provider
7%
Performing Arts
14%
Outsourcing Company
10%
Manufacturing Company
10%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
By reviewers
Company SizeCount
Small Business5
Large Enterprise4
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
What needs improvement with Palo Alto Networks AutoFocus?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed Service feature, which is still not available with Palo Alto. The MDR feature i...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself. I use the threat data correlation feature, which correlates with Cortex. We can use it for data corre...
What advice do you have for others considering Palo Alto Networks AutoFocus?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager. I confirm that we will publish these reviews on peerspot.com in written or audio format...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
Palo Alto Threat Intelligence Management
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Telkom Indonesia
Find out what your peers are saying about Splunk, IBM, Wazuh and others in Security Information and Event Management (SIEM). Updated: August 2026.
908,800 professionals have used our research since 2012.