No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs Snare vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of LogRhythm SIEM is 2.5%, down from 3.1% compared to the previous year. The mindshare of Snare is 0.8%, up from 0.3% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.1%, down from 9.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.1%
LogRhythm SIEM2.5%
Snare0.8%
Other89.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
Frank Eargle - PeerSpot reviewer
Information Security Engineer at Glasshouse Systems
A highly scalable solution that is easy to manage and super easy to set up
We use Snare for picking up Windows logs, and we used to use it for SQL as well. We had used it for Linux once or twice. We're mainly using it for Windows and Windows flat files The most valuable feature of Snare is flexibility or the ability to filter all things you don't want and don't have…
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of LogRhythm for me is the ability to correlate logs throughout many different log sources."
"I have found the Advanced Intelligence Engine has provided the most value to us because we can customize alarms based on our requirements and have created hundreds of alarms that notify different people for different scenarios."
"For us, LogRhythm has given us the kind of insight we need to understand when those threats either are being recon-ed, found out, or when they're really trying a brute force attack to get at us."
"The initial setup process is very user-friendly."
"Overall, my rating for LogRhythm SIEM is nine out of ten."
"We looked at LogRhythm, and LogRhythm seemed to have a lot of the stuff built in, canned already."
"The LogRhythm support system is phenomenal."
"It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable."
"The most valuable feature of Snare is flexibility or the ability to filter all things you don't want and don't have security value."
"Snare has good agents, especially for Windows."
"The best thing about Snare is its format and consistency."
"The stability and reliability of Splunk Enterprise Security is outstanding. It's a software and product that anybody can really pick up and use."
"Easy to deploy and simple to use."
"They are a good partner for Google Cloud. It provides great visibility, threat detection, and proactive mitigation of risks for our mutual consumers."
"While it might be an initial upfront investment on data onboarding, it's going to be something that makes your life incredibly easy once you get beyond that point."
"We can quickly search for almost anything across many log sources in seconds."
"Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us."
"The graph visualization is the most valuable feature."
"The ease of use and building queries, specifically SQL queries, is notably beneficial as it is easy to build, and the data model itself is very simple."
 

Cons

"The console installation is an area with a shortcoming in the solution that needs improvement. If LogRhythm SIEM can offer a web console, it would be great."
"Appliance-based setups can sometimes pose scalability issues"
"Right now there is the concern about being able to gather all of the data into the system."
"We have had some issues that have taken a long time to resolve, various technical issues that have taken longer to resolve than we desire."
"The main area of improvement is that the client must be installed on the computer for all of the functions to work."
"Better knowledge transfer during implementation. We definitely thought it was complex when we initially set it up, but that is usually just a single pain problem."
"I think they're limited now with this to Office 365."
"Logging improvements. I think that the template to reporting is just difficult, it's hard to go back."
"The solution is now developing a SIEM-like feature on Snare Central Server, but it's not complete yet."
"Snare should modernize its GUI a little bit."
"Users will initially find it difficult to identify the event types and installation in Snare."
"The solution is expensive."
"It'd be really nice if Splunk Enterprise Security had a better and solid configuration guide."
"There are some premium add-ons like Splunk Enterprise Security or ITSI which makes it more expensive."
"The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment."
"One issue is that we are getting a lot of false positives. We are trying to reduce them by customizing the default rules, changing thresholds, and using white-listing and black-listing. It's getting better and better as a result. But they need to build components that would reduce the false positives."
"Customizing our commands should be simpler. Creating custom commands in Splunk requires a long, complex process. For example, we have a command to add all the column data, but we don't have a command to get the average of the column data at the end. It would be useful to have a blank at the end to create our commands and leave the rest to others."
"Writing queries is a bit complicated sometimes."
"The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more."
 

Pricing and Cost Advice

"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"We work with French-speaking African countries, and it costs more than the average SIEM solution. Also, the pricing isn't too flexible. AlienVault, Splunk, and IBM QRadar are more suitable for customers on a tight budget."
"The product is inexpensive than other tools."
"It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"It is a very cost-effective solution."
"I give the price a six out of ten."
"Snare has reasonable pricing."
"Snare is a cheap solution because a lot of customers are using it."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate Snare's pricing a four out of ten."
"It is expensive, but it is a good tool. It is worth the cost."
"The pricing could be made more competitive."
"The price of Splunk is too high for our market."
"My customers have found the price of the solution to be high."
"Splunk is expensive based on our current requirements, but it's obviously worth what we pay."
"It is pretty straightforward and based on the sizing. If I compare it with other competitors, it makes sense."
"The license for Splunk Enterprise Security is expensive."
"It's a little bit expensive for a small to medium enterprise."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
894,807 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Construction Company
9%
Computer Software Company
8%
Comms Service Provider
8%
Financial Services Firm
16%
Outsourcing Company
8%
Healthcare Company
7%
Computer Software Company
7%
Financial Services Firm
14%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
No data available
By reviewers
Company SizeCount
Small Business119
Midsize Enterprise50
Large Enterprise270
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon you...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting an...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negoti...
Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
No data available
No data available
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Military, Defence and Security Agencies, Banking Finance and Insurance companies, Retail, Health and Utilities.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk, IBM, Wazuh and others in Security Information and Event Management (SIEM). Updated: April 2026.
894,807 professionals have used our research since 2012.