Try our new research platform with insights from 80,000+ expert users

LogRhythm SIEM vs Security Onion comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Ranking in Log Management
12th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Security Information and Event Management (SIEM) (9th)
Security Onion
Ranking in Log Management
23rd
Average Rating
7.6
Reviews Sentiment
5.5
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Log Management category, the mindshare of LogRhythm SIEM is 2.6%, up from 2.2% compared to the previous year. The mindshare of Security Onion is 3.1%, down from 5.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.6%
Security Onion3.1%
Other94.3%
Log Management
 

Featured Reviews

SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
Jörg Kippe - PeerSpot reviewer
Scientist at a educational organization with 10,001+ employees
A mature and affordable solution that is easy to install and easy to update
The product takes time to learn, it's not that easy. In the beginning we had a lot of questions. If you want to use such a tool in an real (industrial) environment, you have to ask how to get the network data. Can we do a full packet capture? Can we provide agents to our end systems? There are no simple solutions to these questions. It's a general problem when running such systems in an industrial environment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of LogRhythm for me is the ability to correlate logs throughout many different log sources."
"It makes it possible to stay aware of much more of what's going on; we get an overview, a macro view that we can zoom in on as opposed to prior to that when we had individual panes of glass and might be stuck in the firewall interface for half a day while something going on is not getting addressed that we really should probably investigate."
"All in all, it's one of the best SIEMs, as a total package, that I've worked with."
"The Web Console is my favorite. It enables me, at a glance, to see the health of the environments."
"The artificial intelligence engine."
"LogRhythm has been really a good partner, they've reached out, they're always wanting information, "How we can improve? How can we do this or that?""
"LogRhythm's dashboard is very good compared to other SIEM solutions since it shows many details."
"Their support team is very good."
"We use Security Onion for internal vulnerability assessment."
"Security Onion is the most mature solution in the market."
"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
 

Cons

"It should have some more message monitoring features. It can also have some free message monitoring tools."
"I would like to see APIs well-documented and public facing, so we can get to them all."
"LogRhythm SIEM needs improvement in data grouping and manipulation capabilities."
"We usually do end up having to remind technical support about our issues, get back in touch with them to see what the status is on our tickets."
"The product's initial setup phase is pretty complex."
"We have run into problems with stability going through upgrade processes. Recently, we have been on the front edge of the upgrade path. When that happens we tend to run into issues either with certain functionality not working after the upgrades or stability issues because of the upgrades."
"There are a lot of pieces of it that are very complex and time consuming."
"Sometimes the Platform Manager crashes because it's built around Windows."
"The product is not easy to learn."
"Security Onion's user interface could be improved."
"The initial setup of the solution is a little bit difficult."
 

Pricing and Cost Advice

"The product is inexpensive than other tools."
"I would recommend talking to the rep. That's the biggest thing because they will know what questions to ask."
"We have seen a measurable decrease in the mean time to detect and respond to threats. As it comes out new features and new releases, the window is becoming a lot narrower because you can pivot a lot more with the data. Therefore, the new features and enhancements are reducing that."
"On a scale of one to ten, where one is low, and ten is high, I rate the pricing between six and seven."
"In the context of our country, the price of this solution is too high."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"It is a very cost-effective solution."
"Everything is expensive with LogRhythm, and you don't get anything for free."
"It is an open-source solution."
"Security Onion is an open-source solution."
"Security Onion is a free solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
8%
Government
7%
Manufacturing Company
7%
University
12%
Government
11%
Comms Service Provider
10%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise38
Large Enterprise83
No data available
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
What do you like most about Security Onion?
The most valuable feature of Security Onion for security monitoring is its ability to find infected ports.
What is your experience regarding pricing and costs for Security Onion?
Security Onion is an open-source solution. On a scale from one to ten, where ten is expensive and one is cheap, I rate the solution's pricing a six out of ten.
What needs improvement with Security Onion?
The initial setup of the solution is a little bit difficult.
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
No data available
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Information Not Available
Find out what your peers are saying about LogRhythm SIEM vs. Security Onion and other solutions. Updated: March 2026.
884,933 professionals have used our research since 2012.