Try our new research platform with insights from 80,000+ expert users
it_user756402 - PeerSpot reviewer
Cyber Security Engineer at a healthcare company with 1,001-5,000 employees
Vendor
I am impressed with their support. We ran into issues where it was not parsing correctly.
Pros and Cons
  • "It supports most standard log sources."
  • "It will definitely help if the parsing side would be much easier, meaning it would be better if we could easily make adjustments on the parser, both on standard and non-standard log sources."

How has it helped my organization?

  • Lower personnel requirements
  • Improved vendor support services
  • Ease of use

Key challenges are lack of personnel to manage LogRhythm. We are a small shop and we don't have a dedicated person to really manage LogRhythm, so our goal is for us to go to a level where we are doing a lot of automation.

What is most valuable?

  • The SmartResponse piece of it.
  • It supports most standard log sources.

What needs improvement?

We were having some challenges initially, especially ingesting those standard log sources. We ran into issues where it was not parsing correctly. That wasn't our expectation, because we considered them standard log sources, but there was some issue with parsing our logs.

As far as adding log sources, it is not as straightforward. At the same time, granting access we have noticed it's not using AD groups. It's more of the organizational unit in AD.

It will definitely help if the parsing side would be much easier, meaning it would be better if we could easily make adjustments on the parser, both on standard and non-standard log sources. The way it works right now, it looks like we have to engage LogRhythm in order for us to make adjustments on the parser.

What do I think about the stability of the solution?

In a two month period, we had one hardware issue, which might not be LogRhythm-related. It might be on the hardware side. It's fairly new, so we were expecting that to happen, the actually failure on the platform manager (PM) side.

Buyer's Guide
LogRhythm SIEM
May 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
853,118 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I think it's scalable. So far, we haven't really reached the point where we can say, "Yeah, we can definitely expand the use of it."

How are customer service and support?

They're pretty good. I'm impressed with their support. It has been easy to reach the right person.

Which solution did I use previously and why did I switch?

We are migrating from a different product (Curator) to this product, and we think LogRhythm is better than the older product that we were using. We were looking for a solution with scalability and ease of management. Also, Curator is more expensive.

How was the initial setup?

I was involved in the initial deployment and setup. I have used another SIEM solution. It's not easy, but it's not also that really complicated to setup.

What's my experience with pricing, setup cost, and licensing?

Look for whatever will give you the most value. That's the main point. It is not one size fits all.

Which other solutions did I evaluate?

Splunk. Cost is the main reason LogRhythm stood out.

What other advice do I have?

It is important solution be a unified end-to-end platform, especially because we are a small security group. If we can have it in one place, that would be a big plus for us.

Most important criteria when selecting a vendor: support.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
it_user756396 - PeerSpot reviewer
Security Administrator at a tech services company
Consultant
The artificial intelligence engine is its most valuable feature
Pros and Cons
  • "The artificial intelligence engine."
  • "More help and assistance with some of the open source products, everything seems to be focused on Windows versus giving some guidance and some documentation on how to use it."

How has it helped my organization?

We're in the process of a rollout right now. But from what I've seen, it will definitely be a huge benefit.

Our impression is the solution will be excellent toward meeting our meeting our existing security challenges.

Our biggest challenge right now, there is a big push towards docker containers and trying to wrap my head around how we are going to monitor and provide security for that.

What is most valuable?

The artificial intelligence engine.

What needs improvement?

Focus on open source, long sources like Linux and Docker, and those kind of things. More help and assistance with some of the open source products, everything seems to be focused on Windows versus giving some guidance and some documentation on how to use it. This seems to be lacking.

It would be a huge help if there were some guidelines or some new technologies that were developed specifically for that.

What do I think about the stability of the solution?

It seems pretty stable. I'm not had any issues with it.

What do I think about the scalability of the solution?

It seems like you could grow it horizontally. The solution that we have, it is the one that can split out with a couple of different data indexers and data processors. However, we are still in the roll-out phase.

How are customer service and technical support?

They were excellent and very knowledgeable.

Which solution did I use previously and why did I switch?

No, just some open source type of things.

We searched for a security solution because it is such a huge surface area to cover for a very small security shop. It is just two of us, and we have about 5,000 servers. It is a lot.

How was the initial setup?

I was involved in the initial setup. It was somewhat straightforward, somewhat complex. There are a lot of moving parts.

If they had some type of a script, which you could run depending on the solution and what boxes you have. A script that would just go and automatically configure things and get that part of it done, then you could focus on getting the events in, things like that.

What's my experience with pricing, setup cost, and licensing?

I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway. Better to do it upfront and have that headroom.

Which other solutions did I evaluate?

We were evaluating Splunk, and also QRadar.

We chose LogRhythm because the price point was within what we were looking to pay. It seemed like a more mature solution than some of the others.

What other advice do I have?

A unified end-to-end platform solution is important but I understand that there will be different tools for different jobs. LogRhythm, that is their sweet spot and I hope they stay there because they do it really well.

Most important criteria when selecting a vendor: It is about the integrations with all the different products that we are using. LogRhythm seem to have most of those boxes checked. Therefore, it was a good fit for us.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Buyer's Guide
LogRhythm SIEM
May 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
853,118 professionals have used our research since 2012.
it_user375531 - PeerSpot reviewer
Information Security Analyst at a financial services firm with 1,001-5,000 employees
Vendor
The most valuable feature is the AI engine and we're able to have all of our logs in one place.

What is most valuable?

The most valuable feature is the AI engine, as well as the usual SIEM product stuff. The ability to have all of our logs in one place is a big thing for me.

How has it helped my organization?

It’s brought all of our devices into one area, so I am able to understand and manage all of our devices and understand what is going on with an individual device.

What needs improvement?

The reporting aspect is difficult to use and very difficult to get your own reports. So far this is it; they have a web UI and we had a recent update which fixed a lot of bugs and added a lot of great features. But the reporting is lackluster.

For how long have I used the solution?

I've used it for 10 months.

What was my experience with deployment of the solution?

We've had no issues with deployment.

What do I think about the stability of the solution?

Since we purchased one of their boxes, we've had 99% uptime. The only downtime has been for updates and upgrades. So we've had no issues with instability.

What do I think about the scalability of the solution?

We foresee that it's scalable for our future developments. At the moment, we are using half of what it’s able to do.

How are customer service and technical support?

I've been happy with the support in the initial setup. The support in our environment was well done. For any issues, we have had someone on the phone on that day, so there have been no downtime issue. They are super nice.

Which solution did I use previously and why did I switch?

We didn’t have a solution before. It's usable out-of-the-box and it covers a lot of holes. It's done its job.

Which other solutions did I evaluate?

We looked at AlienVault and Qradar.

What other advice do I have?

Definitely do a test run, a proof of concept, so it’s understood how it’s going to work in your environment. Also, take the training that they provide; i t's super valuable.

Disclosure: I am a real user, and this review is based on my own experience and opinions.

PeerSpot user
it_user341232 - PeerSpot reviewer
IT Security Specialist at a manufacturing company with 1,001-5,000 employees
Vendor
Security management is what it's best at, but it's generally for medium-sized companies.

Valuable Features:

The advanced intelligence engine -- in fact, the whole suit -- is very powerful. It depends how you use it. Security management is what it's best at. As far I’m concerned, it’s one of the best.

Room for Improvement:

This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them. The solution is not robust. It depends on the size of the companies and the size of the firewalls you have which will determine if it will work for you. Thus product is really good and easy to use for medium sized companies.

Use of Solution:

I've used it for three years.

Deployment Issues:

Initially we had a lot of issues. Today it has improved dramatically, and it has no issues in deployment.

Stability Issues:

It is very stable, but we have to work with it and identify which logs we need. If we don’t, it doesn't handle the traffic well. 

Every tool is different, and you just have to work with it.

Customer Service:

It’s one of the best customer services you could find. Everyone is very knowledgeable and helpful. You aren’t waiting around for tickets to be resolved. If they can’t resolve it, they escalate and resolve quickly.

ROI:

Absolutely we have made a ROI. It resolves a lot of issues. It helps a lot of our infrastructure and everyone is benefiting. It’s absolutely worth the money spent.

Cost and Licensing Advice:

They are very transparent about the licensing. They are upfront. They tell you what can handle what. They are honest people.

Other Advice:

I have been invited to user group meetings and we have had good conversations. They have been very helpful and they understand my needs. They listen to our input and really take it seriously. They really work with us on different issues. 

Everything is fantastic.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Muhammad Ahtsham - PeerSpot reviewer
Information Security Engineer at RapidCompute
Real User
Easy to deploy, stable, and scalable
Pros and Cons
  • "Our clients enjoy having one dashboard to monitor their environments in real time."
  • "There is room for improvement with separate running sources or better integration."

What is our primary use case?

I use the solution for logistics and metrics. We use LogRhythm SIEM for our company and our clients. The solution is deployed on separate machines.

What is most valuable?

The log correlation is the most valuable feature.

Our clients enjoy having one dashboard to monitor their environments in real time.

What needs improvement?

The coordination and load bussing has room for improvement. 

There is room for improvement with separate running sources or better integration.

I would like to have a better way to investigate the logs by adding correlations to the dashboard.

For how long have I used the solution?

I have been using the solution for one and a half years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

The technical support is responsive and always resolves our issues.

Which solution did I use previously and why did I switch?

I previously used IBM Security QRadar and switched to LogRhythm SIEM because it is the best in the market.

How was the initial setup?

The initial setup is straightforward. The deployment takes between nine to twelve hours.

What other advice do I have?

I give the solution an eight out of ten.

The solution is for medium and large organizations.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

PeerSpot user
it_user326481 - PeerSpot reviewer
Sr. Mgr of Network Operations at a comms service provider with 501-1,000 employees
Vendor
It allows us to detect and remediate Advanced Persistent Threats, but the log management database needs to be more efficient.

Valuable Features

  • Investigation
  • Advanced Intelligence Engine
  • Alarming and Response

Improvements to My Organization

We have made this the foundation of our security intelligence within our organization. It has allows us to detect and remediate Advanced Persistent Threats.

Room for Improvement

I would like to the log management database perform more efficiently.

Use of Solution

I've used it for five years.

Stability Issues

Some minor bugs with the mediator. Those have been fixed in patch releases a long time ago.

Customer Service and Technical Support

Customer Service:

9/10.

Technical Support:

9/10.

Initial Setup

Setup was fairly straightforward. We were up and running with coverage of most log sources within two days.

Implementation Team

We implemented it in-house. Active Directory import makes initial configuration quick and easy.

Other Solutions Considered

We also evaluated Splunk, and we chose LogRhythm as the correlation rules performed it handled clients on DHCP better.

Other Advice

We recommend that people implementing it choose to log everything, including logs from desktops, laptops, servers, switches and routers.

Disclosure: I am a real user, and this review is based on my own experience and opinions.

PeerSpot user
Consultant at a tech services company with 51-200 employees
Real User
An extremely valuable correlation engine that uses machine learning to identify network issues
Pros and Cons
  • "The correlation engine is extremely valuable because it uses machine learning to process information from the central manager and identifies issues in the network."
  • "The security playbook could be pre-defined and available to other analysts with similar security issues."

What is our primary use case?

Our company manages the solution as a threat hunting platform for a semi-government client in the Hong Kong insurance industry. We collect logs for video, active directories, antivirus, and firewalls to consolidate them in the solution. 

From the central log collector, we build detection policies to identify threats or possible breaches. The solution also serves as a data storage platform to troubleshoot issues and find root causes.

In addition, logs that include performance data are created for devices such as routers and switches to monitor the availability of the office network. 

We also perform ongoing maintenance of the solution and all components to ensure everything runs smoothly. 

What is most valuable?

The correlation engine is extremely valuable because it uses machine learning to process information from the central manager and identifies issues in the network. 

The engine accurately and quickly identifies problem areas as it correlates events from various devices. 

Without this engine, logs would have to be built individually for each device. 

What needs improvement?

The security playbook could be pre-defined and available to other analysts with similar security issues. Currently, playbooks are individually written for various actions and threats. 

It would be faster and easier to react to issues if pre-defined playbooks were accessible to all analysts. 

For how long have I used the solution?

I have been using the solution for seventeen years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

I have escalated issues to technical support and rate the assistance I received an eight out of ten. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is complex and I rate it a six out of ten. 

What about the implementation team?

We implement the solution for our customers. 

Which other solutions did I evaluate?

The solution remains a top choice for our customers because of its performance, indexing rate, and coalition engine speed. Customers trying to use SIEM to collect logs and identify threats require a solution that responds quickly. 

The solution's correlation engine is very important because it uses machine learning to automatically collect and analyze quite a bit of data. 

What other advice do I have?

When choosing a solution, it is important to determine what you want to achieve instead of how the solution works. Most solutions have a method for collecting logs, relaying information, and identifying issues so selection is more about the speed and accuracy of end results.

I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

PeerSpot user
Associate Senior Engineer - Network & Security at Connex Information Technologies (Pvt) Ltd.
Reseller
Enables us to alternate incident automations but reporting needs improvement
Pros and Cons
  • "The most valuable feature is that we can alternate incident automations."
  • "We need to get better training for things like creating code and playlists. The way it's done now takes a long time."

What is our primary use case?

Our primary use case is for financial companies and telcos.

What is most valuable?

The most valuable feature is that we can alternate incident automations.

What needs improvement?

We need to get better training for things like creating code and playlists. The way it's done now takes a long time. 

For how long have I used the solution?

I have been using LogRhythm NextGen SIEM for two years. 

What do I think about the stability of the solution?

The stability depends on the client we installing or integrating for based on the server's requirements. We can create them according to that defined time period. It's not that difficult but depending on the customer or the other server requirements.

We can have a dashboard in a single platform, we can get notifications via email or SMS, and we have Smart Response actions. So that kind of possibility is there.

What do I think about the scalability of the solution?

Our clients are mostly on a larger scale. 

How are customer service and technical support?

You can request support and they respond immediately. They're really good. 

How was the initial setup?

The initial setup is easy. It can take two hours. The first day of deployment is easy. Then depending on the devices and log servers, it can take time. We can give them predefined or pre-created devices and logs. The deployment depends on the devices and systems we are integrating. But the initial stage is easy.

What's my experience with pricing, setup cost, and licensing?

Because we are a developing country, the costs depend on country development. We implement it for large-scale companies because normal companies, startup companies, can't afford products at that price. We mainly focus on large-scale companies.

What other advice do I have?

I would definitely recommend this solution if you can afford it. 

We get customized reports and we get reports including all the details, but when we start using them we couldn't start with the Outlook editor. We can customize a document and we can write a report. The dashboards are very user-friendly and very attractive. But when it comes to the reporting part, I think that could use improvement in the next release. 

I would rate it a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor

PeerSpot user
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.