Comparison Buyer's Guide

Executive SummaryUpdated on Jul 20, 2023

Categories and Ranking

LogRhythm SIEM
Ranking in Log Management
Ranking in Security Information and Event Management (SIEM)
Average Rating
Number of Reviews
Ranking in other categories
No ranking in other categories
Ranking in Log Management
Ranking in Security Information and Event Management (SIEM)
Average Rating
Number of Reviews
Ranking in other categories
Extended Detection and Response (XDR) (3rd)

Mindshare comparison

As of July 2024, in the Log Management category, the mindshare of LogRhythm SIEM is 2.2%, down from 3.8% compared to the previous year. The mindshare of Wazuh is 18.6%, up from 11.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
Security Information and Event Management (SIEM)
Extended Detection and Response (XDR)

Featured Reviews

Oct 18, 2022
The solution reduced our investigation time from days to hours and assists in managing our workflows
One of the features that we use the most and find the most valuable includes the Web Console. My analysts really like the interface and the ability to build queries using point-and-click without having to write Query languages. My favorite feature is the actual Admin Console and the ability to monitor all aspects of the SIEM's health and the ability to build new use cases for my analysts to work with. We also use the Machine Data Intelligence feature for classifying and contextualizing logs. It does struggle with unknown log sources and we've had some challenges over the years getting new log sources incorporated into the MDI Fabric. The ability to authenticate successes and failures using MDI is incredibly easy. For the log sources that we bring into the SIEM, that work is pretty much done for us by the MDI. We don't have to do any additional work.
Jun 15, 2023
Good for file integrity monitoring
There is room for improvement in Wazuh, but it's possible they are already working on it. The only challenge we faced with Wazuh was the lack of direct support. They charge for support, whether it's five days a week or seven days a week. We don't expect it to be free because revenue is generated through the support they provide. In future releases, I would like to see a feature. There is one feature we observed in a premium tool in the industry called Dynatrace. It provides automatic relations between different devices and components. For instance, if you receive a web login request, Dynatrace can trace and show you the path it takes from the firewall to the switch, then to the Apache server, the actual job application, and finally back to the client. It intelligently correlates all the components involved in a single event. If Wazuh could include this feature, where all the components are integrated, it would automatically relate them for any activity in your environment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:


"It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable."
"Technical support has always been helpful."
"LogRhythm NextGen SIEM is customizable, simple to manage, and there are many features. The solution does not require an expert to be able to use it, anyone can use it."
"The ability for me to go into the Web UI, and just learn what's going on in my environment."
"We now have a central point of monitoring for all potential threats."
"We have seen a massive increase in the amount of data that we can collect, the type of things that we can see, the way we can look at logs, the way we can get alerts, and the way can create our own customer roles, which has allowed us to customize the work in our environment."
"Its benefits are broad. The solution isn't necessarily made to do any one thing, but it can do anything you tell it to. It is able to tackle any different type or size of job."
"Compliance reporting is another great feature of this product. It has built in reports right out of the box."
"Wazuh is simple to use for PCI compliance."
"It offers built-in modules for file integrity and vulnerability management."
"I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform."
"The deployment is easy and they provide very good documentation."
"It's stable."
"The MITRE ATT&CK correlation is most valuable."
"It has efficient SCA capabilities."
"Wazuh's best features are syscheck, its ability to immediately resolve vulnerabilities, and that it's open source."


"LogRhythm's SOAR and NDR features don't stack up well against competitors. maybe integrating theme functionality as the other do. But in general, it's okay."
"Only area I can think of to improve on is the proof reading and using the guides before releasing them. Out the the 20+ guides I used one had issues with wrong information in it."
"I have probably submitted half a dozen log parser requests, and I keep finding more stuff that we need to keep an eye on that doesn't have a definition in LogRhythm."
"I would like to see case management become more independent from LogRhythm itself."
"LogRhythm SIEM can improve its user interface. The current interface is quite complex and can be challenging to navigate. While it offers many valuable features, understanding how to access and utilize them efficiently takes time. Simplifying the client console's user interface would significantly enhance the user experience and make it more user-friendly."
"There used to be the ability to create alarms based on message text that was included in LR Version 6.x that has been removed in LogRhythm 7.x, and on that, I would like to see it added back."
"When we had version 7.2.6, there were a lot of issues deploying that version and with the indexing. The indexer was unstable. So, we were not able to use the platform when we were on that version until we were able to upgrade to 7.3.4."
"We have run into problems with stability going through upgrade processes. Recently, we have been on the front edge of the upgrade path. When that happens we tend to run into issues either with certain functionality not working after the upgrades or stability issues because of the upgrades."
"The tool doesn't detect anomalies or new environments."
"We would like to see more improvements on the cloud."
"One area where Wazuh could use some improvement is in its reporting mechanism, especially for high-level management like CSOs and CEOs."
"Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."
"It would be great if there could be customization for the decoder portion."
"Wazuh is missing many things that a typical SIEM should have."
"The computing resources are consuming and do not make sense."
"The deployment is a bit complex."

Pricing and Cost Advice

"I would rate the tool's pricing around eight out of ten."
"LogRhythm's pricing and licensing is extremely competitive and it's one of the top three reasons we continue to invest in the platform."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"On a scale of one to ten, I'd rate the pricing of this solution as a seven - not too expensive but not cheap either. Regarding licensing costs, it varies depending on factors like being a partner or an end user, but there are no additional costs aside from standard licensing fees for the basic SIEM solution."
"Everything is expensive with LogRhythm, and you don't get anything for free."
"In the context of our country, the price of this solution is too high."
"The product is cheaper compared to other tools."
"Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year."
"When I contacted customer care, they mentioned bundling options, that I found to be overall affordable."
"It is a free-of-cost solution."
"They have a good pricing strategy for market expansion."
"Wazuh is an open-source tool."
"Wazuh is a cheaply priced product."
"The solution's pricing is very competitive."
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
793,295 professionals have used our research since 2012.

Top Industries

By visitors reading reviews
Educational Organization
Computer Software Company
Financial Services Firm
Computer Software Company
Manufacturing Company
Financial Services Firm

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What do you like most about LogRhythm NextGen SIEM?
LogRhythm does a very good job of helping SOCs manage their workflows.
What is your experience regarding pricing and costs for LogRhythm NextGen SIEM?
LogRhythm's pricing and licensing are extremely competitive and it's one of the top three reasons we continue to invest in the platform.
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating mu...
What is your primary use case for Wazuh?
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.



Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
No data available

Learn More




Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Information Not Available
Find out what your peers are saying about LogRhythm SIEM vs. Wazuh and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.