Try our new research platform with insights from 80,000+ expert users
Subhash Sreenivasan - PeerSpot reviewer
Head of Professional Services at a tech services company with 11-50 employees
Real User
Top 5
Mar 25, 2024
Its most valuable features include robust dashboards and effective alerts
Pros and Cons
  • "I find LogRhythm's log management capabilities to be beneficial."
  • "Appliance-based setups can sometimes pose scalability issues"

What is our primary use case?

LogRhythm SIEM is primarily utilized for cybersecurity analysis and incident management.

What is most valuable?

Its most valuable features include robust dashboards and effective alerts. I find LogRhythm's log management capabilities to be beneficial.    

We integrate multiple credentials and feeds from various sources to enrich customer data. However, we haven't extensively explored its capabilities for compliance reporting as it hasn't been a priority for our clients.

Regarding identifying potential security incidents, LogRhythm's preconfigured alerts are quite effective in detecting vulnerabilities. As for the impact of LogRhythm's log management capacity on security posture, it largely depends on the deployment type. The analytics and intelligence features, particularly the correlation functionalities, have proven valuable in catching complex cyber security threats.

What needs improvement?


For how long have I used the solution?

I have been using LogRhythm SIEM for 1.5 years.

Buyer's Guide
LogRhythm SIEM
January 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,927 professionals have used our research since 2012.

What do I think about the stability of the solution?

We haven't encountered any significant problems, so it effectively keeps our processes running smoothly. I'd rate it an eight. It's generally stable, though we haven't faced any major stability issues.

What do I think about the scalability of the solution?

I'd give it a 6 because appliance-based setups can sometimes pose scalability issues, but otherwise, it's fine. 

How are customer service and support?

We have specialists, and whenever we need technical support, we can easily get it.

How would you rate customer service and support?

Positive

What was our ROI?

LogRhythm SIEM is a factor in our capabilities, particularly for incident response and insurance management.

The incident response times have improved since implementing LogRhythm SIEM.

What's my experience with pricing, setup cost, and licensing?

On a scale of one to ten, I'd rate the pricing of this solution as a seven - not too expensive but not cheap either.

Regarding licensing costs, it varies depending on factors like being a partner or an end user, but there are no additional costs aside from standard licensing fees for the basic SIEM solution.

What other advice do I have?

My advice for someone considering implementing LogRhythm SIEM would be to start with proper controls and understand the value it provides.

Before installing the solution, users should consider factors like EPS calculations and endpoint support to ensure proper sizing, especially if not going for an appliance.

Overall, I'd rate this product an 8 and would recommend it to others due to its cost-effectiveness, value for money, and user-friendly nature.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Regional Technical Manager at a consultancy with 51-200 employees
Reseller
Aug 7, 2023
A scalable tool for network monitoring, user behavior analytics, and log collection
Pros and Cons
  • "The most valuable features of the solution are network monitoring, user behavior analytics, and log collection."
  • "The console installation is an area with a shortcoming in the solution that needs improvement. If LogRhythm SIEM can offer a web console, it would be great."

What is our primary use case?

In my company, we use LogRhythm SIEM for integrations. We use the product for SOC use cases. If we have SOC implementations, LogRhythm is the SIEM solution we use since it can also offer a SOAR solution.

What is most valuable?

The most valuable features of the solution are network monitoring, user behavior analytics, and log collection. Our company uses almost all the features offered by the solution.

What needs improvement?

The console installation is an area with a shortcoming in the solution that needs improvement. If LogRhythm SIEM can offer a web console, it would be great. Since the product does not offer a web console, my company must rely heavily on the client console. There need to be some improvements in design. I want LogRhythm SIEM to be more user-friendly.

The File integrity monitoring (FIM) features offered by LogRhythm are great, but it is not competitive with the other solution offering the same feature.

For how long have I used the solution?

I have experience with LogRhythm SIEM for two years. My company is a reseller of cybersecurity solutions. I use the solution's latest version.

What do I think about the stability of the solution?

It is a pretty stable solution. Stability-wise, I rate the solution an eight out of ten.

What do I think about the scalability of the solution?

It is a very scalable solution. Scalability-wise, I rate the solution a nine out of ten.

My company caters to three customers who use the solution. Mostly our customers are enterprise-sized businesses with a few hundred or thousands of people.

How are customer service and support?

I rate the technical support as an eight out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was easy. I rate the setup phase an eight on a scale of one to ten, where one is difficult, and ten is easy.

The solution is deployed on-premises.

For deployments, it can take about two to three weeks. It could take more time when it comes to tuning or fine tuning needed in the solution, and it is not the case for LogRhythm alone but the same for all SIEM solutions. The deployments and the initial configuration can take around a month.

There are two aspects when it comes to the steps involved in the deployment phase, which are organizational and technical. Our company starts the deployment with the organizational aspects first, where we have to understand the company's context, to understand the company's use cases, and where we have to implement. Then, we start with the technical stuff, like installing solutions and configuring the use cases we have already discussed with the customers.

What's my experience with pricing, setup cost, and licensing?

On a scale of one to ten, where one is low, and ten is high, I rate the pricing between six and seven. Price-wise, it is not a solution for small businesses. My company works in the African market, and in African markets, LogRhythm SIEM could be very expensive for small enterprises. There are annual charges to be paid for using LogRhythm SIEM. There are no extra charges in addition to the licensing costs of the solution.

What other advice do I have?

To those planning to use the solution, I suggest they get trained before starting the use and deployment of the solution.

I rate the overall solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Buyer's Guide
LogRhythm SIEM
January 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,927 professionals have used our research since 2012.
reviewer2104419 - PeerSpot reviewer
Manager Solutions Architect at a comms service provider with 10,001+ employees
Real User
Feb 16, 2023
Reliable and flexible but can be difficult for inexperienced users
Pros and Cons
  • "Technical support has always been helpful."
  • "It's not easy for someone new to the solution."

What is our primary use case?

It's a next-generation SIEM solution. We use it for our clients. 

What is most valuable?

It has connectivity with multiple log sources - including those that are on-prem and in the cloud (including GCP, AWS and our own cloud).

It is extremely scalable. 

Technical support has always been helpful.

It is stable, reliable, and flexible. 

What needs improvement?

It's not easy for someone new to the solution. There are some complexities involved with the initial onboarding. It needs to have more user-friendly dashboards and onboarding processes. 

It is a premium solution which means it is quite expensive. 

For how long have I used the solution?

I've used the solution for the last three years. 

What do I think about the stability of the solution?

The solution is scalable. I'd rate it eight out of ten. There are no bugs or glitches. It's reliable, and the performance is good. 

What do I think about the scalability of the solution?

The solution is very scalable vertically as well as horizontally. It is great for big setups. You can scale as per your requirements. There's no issue with expansion. I'd rate the solution nine out of ten in terms of ease of scaling if a company has multiple locations or has a setup across countries. 

How are customer service and support?

We are a gold partner. We've never faced any support issues. They are very helpful and responsive. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I've also used with QRadar, which is easier, for example, to set up and is more user-friendly. 

How was the initial setup?

The solution can be difficult to set up. I'd rate the process six out of ten. You need to know what you are doing. There are complexities involved. 

A hardware-based setup would require some configurations. Typically, we need a minimum of three to four weeks to do a setup. 

What's my experience with pricing, setup cost, and licensing?

The solution is moderately priced. Sometimes they give good deals if there is a larger requirement. 

If the solution is on-prem, there is a cost to investment. If it is on cloud, this is not the case. 

What other advice do I have?

We are a gold partner. 

I'd recommend the solution to others. It has a lot of new features and offers AI and ML. There is good support, scalability, and flexibility on offer. 

I'd rate the solution seven out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Global Security Manager at a manufacturing company with 1,001-5,000 employees
Video Review
Real User
Oct 27, 2022
The solution reduced our investigation time from days to hours and assists in managing our workflows
Pros and Cons
  • "LogRhythm does a very good job of helping SOCs manage their workflows."
  • "One of the challenges of the SIEM for the LogRhythm 7 platform is the amount of time it takes to bring new log sources into the MDI."

What is our primary use case?

LogRhythm works within the core of our SOC. It's where our analysts work every day and where we do all of our investigatory work for security incidents.

It created our security posture. It is the central component of all of our security tools and it is the heartbeat of our SOC and our daily operations. It sets the tone for everything that we do.

How has it helped my organization?

This solution improves our organization daily. It saves us countless hours doing correlation work and reduces our investigatory process from days to hours. It routinely brings issues to the forefront using the AI engine and the use cases that we've built that need investigating. We constantly find new sources of logs to bring into the system to continue to make it better. 

LogRhythm does a very good job of helping SOCs manage their workflows. Our SOC is very young and we're not leveraging that feature yet. I've seen other companies' SOCs and watched them use the workflow features and it's incredibly well done. We're not mature enough yet to use it. 

For cybersecurity exposures, the one downside from LogRhythm's perspective is that it can only tell me about use cases that I've already defined. It cannot identify unknown cases at this time. However, we have just recently purchased the NDR solution and that does have this capability.

This solution is our principal mechanism for doing all investigatory work. When we get alerts from LogRhythm, we'd go back to the logs and trace those events back to their source. This is is how we shut down attacks. 

What is most valuable?

One of the features that we use the most and find the most valuable includes the Web Console. My analysts really like the interface and the ability to build queries using point-and-click without having to write Query languages. My favorite feature is the actual Admin Console and the ability to monitor all aspects of the SIEM's health and the ability to build new use cases for my analysts to work with.

We also use the Machine Data Intelligence feature for classifying and contextualizing logs. It does struggle with unknown log sources and we've had some challenges over the years getting new log sources incorporated into the MDI Fabric.

The ability to authenticate successes and failures using MDI is incredibly easy. For the log sources that we bring into the SIEM, that work is pretty much done for us by the MDI. We don't have to do any additional work.

What needs improvement?

One of the challenges of the SIEM for the LogRhythm 7 platform is the amount of time it takes to bring new log sources into the MDI. We've waited a couple of years on some sources before they were incorporated. Writing our own custom MDIs is very challenging because it requires expert-level regex in order to write those rules and to make them efficient. Bringing in sources that aren't natively understood is where we've struggled the most.

For how long have I used the solution?

We have been using LogRhythm SIEM Solution for six years.

What do I think about the stability of the solution?

The stability of the solution, if it's deployed properly with the right resources, is rock solid. We have not experienced any performance issues. When we first bought the SIEM, we undersized it, and the performance was compromised. 

What do I think about the scalability of the solution?

This is a scalable solution. I've load-tested the SIEM at its current resource allocations up to four or five times as much as my daily ingest and the system handled it just fine.

How are customer service and support?

Their technical support is second to none and is one of the reasons why we continue to invest in and consider LogRhythm as a strategic partner. Their support team are really good at their jobs and they always come through when we need them. I would rate their support a ten out of ten. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

LogRhythm is the first SIEM I have used and the only SIEM I have a lot of experience with. I've demoed other SIEMs and we've gone to market twice to look at whether LogRhythm was still the right decision. Both times we concluded that it was.

How was the initial setup?

The setup of the SIEM is complex in its own right. LogRhythm typically recommends professional services assistance to deploy the SIEM properly. My company did not purchase those professional services so I had to figure it out for myself. Their support structure was so good and they helped me so much that we were able to get it working without professional help. 

LogRhythm is an out-of-box solution and this was why we bought it. I had no experience with SIEM when we bought it six years ago. I needed something that I could plug into the network, get up and running and get value out of immediately.

What was our ROI?

We get a vast amount of ROI from this solution. We get way more out of it than we put into it. One of the metrics that I track pretty closely in our SOC is the mean time to detect. Prior to the SIEM, the mean time to detect was measured in weeks and it's now measured in minutes.

What's my experience with pricing, setup cost, and licensing?

LogRhythm's pricing and licensing are extremely competitive and it's one of the top three reasons we continue to invest in the platform. 

Which other solutions did I evaluate?

We looked at Securonix, Azure Sentinel, IBM's QRoC, and QRadar on Cloud. What really won us over with LogRhythm was the ease of use of the interface and the simplicity of the underlying architecture. It really lends itself to being a low-cost solution to own over time.

What other advice do I have?

The nice thing about LogRhythm is that they continue to innovate and come up with new capabilities like their NDR solution that we recently invested in. They continue to stay relevant. 

I would rate LogRhythm a nine out of ten. The on-prem version of the solution is fantastic and is the core of my SOC. It's our daily tool for all of our investigations. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Joseph W. - PeerSpot reviewer
System Administrator at a financial services firm with 501-1,000 employees
Video Review
Real User
Oct 27, 2022
Has pre-built pieces for third party vendors and does not take a long time to implement
Pros and Cons
  • "One of the main features that I like about LogRhythm NextGen SIEM is that there are a lot of pre-built pieces. Like with our AV, we didn't have to tell it how to read the logs; they already had it pre-made. So, we essentially just had to follow their guide to get the logs imported in and set up some rules for it. We've only had to manually create the parsing rules for a few of our vendors so that we could interpret the logs correctly. Most of them had already been pre-created for us."
  • "When we originally got LogRhythm, their tech support was fantastic, and I loved them. Now, we don't quite get as quick of a response. I've been disappointed in the more recent tech support. When you call in, they'll say that they will get you somebody, and you'll finally get someone who will contact you back a day or so later. Whereas before, I would get help right away."

What is our primary use case?

We have a lot of use cases. Originally, it started out pulling in a bunch of the logs so we could get some ideas on network traffic. More recently, we have proceeded with pulling in logs from some of our other vendors. This really helped out a lot with our AV, which didn't always notify us as quickly as we wanted it to. LogRhythm made it possible for us to get notifications faster so that we can remediate things faster. We've been expanding it more and more as we've gone through the years to include more traffic, giving us more insight into our network.

How has it helped my organization?

LogRhythm really gave us a better understanding of what our overall risk is within our network and has opened our eyes to include other products that helped address different types of issues. Whether it's getting into vulnerability scanners or different pieces of other software, it's opened the door to what's out there. It helped us to turn on different features or other products along the way and helped us to identify what we need to improve on and present it to our executive team.

What is most valuable?

One of the main features that I like about LogRhythm SIEM is that there are a lot of pre-built pieces. Like with our AV, we didn't have to tell it how to read the logs; they already had it pre-made. So, we essentially just had to follow their guide to get the logs imported in and set up some rules for it. We've only had to manually create the parsing rules for a few of our vendors so that we could interpret the logs correctly. Most of them had already been pre-created for us.

We use the Event Log Filtering feature a lot. We use it for simple troubleshooting tasks like when a user is logged out, to more important tasks like trying to investigate a threat. As far as its effect on productivity, we can go and search instead of trying to troubleshoot and guess what is causing an error. We can identify what the program is or where the hiccup is.

LogRhythm helped us to identify a lot of blind spots. Originally, we didn't have a SIEM tool. We had auditors say that this is something that we should be doing. My management team asked me to go and find a product, and I researched a bunch of them and found LogRhythm. It really opened our eyes to see how much traffic we have, whether it's other IP addresses that are scanning us or external users trying to hit certain ports that could then get closed. It helped us tighten down some of those firewall rules that may have been left open unintentionally through other changes. It helped us a lot early on to identify who was trying to communicate with us or, essentially, who was trying to attack us.

As far as our overall security posture, our SIEM tool was the initial push that really got us going into identifying where all of our threats were. We expanded over the seven years that we've had it, and I implemented at least eight other products that are all security related because the SIEM tool indicated the need to identify other risks. It really helped us as an organization to identify risks and move forward to a more secure environment.

What needs improvement?

When we originally got LogRhythm, their tech support was fantastic, and I loved them. Now, we don't quite get as quick of a response. I've been disappointed in the more recent tech support. When you call in, they'll say that they will get you somebody, and you'll finally get someone who will contact you back a day or so later. Whereas before, I would get help right away.

For how long have I used the solution?

We've had LogRhythm for almost seven years now.

What do I think about the stability of the solution?

It's very stable. We've been on the same system for the seven years that we've had the product. We've had no issues and haven't even had to upgrade any of the systems or increase anything hardware-wise up to this point.

What do I think about the scalability of the solution?

I haven't really had much of a chance to do any scalability because we haven't had to scale anything up. Ours is a virtual instance, and if we needed to scale up, we could just shut the server down, add some more resources, spin it back up, and it would be good to go.

How are customer service and support?

Initially, tech support was a solid ten out of ten when we first started. Over the last couple of years, they have changed how they handle tech support requests, and the response time decreased from what it used to be. You call in, they'll take your information, and then they'll call you back later. That can take 24 hours or more. When you actually do get somebody on the phone, they're very good and know exactly what they're doing. They'll take care of you.

In terms of response time, I'd give tech support a six out of ten, but in terms of how good they are as tech support, I'd give them a seven or eight.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We didn't have a designated security person on staff, and our auditors came in and said that we should be doing this. As a help desk person, I looked for something specific that was going to give me the flexibility I need but also allow me to spin up and run while doing the rest of my duties, and LogRhythm was the best one that I found that could do that.

How was the initial setup?

It's pretty complex to set up, in a way. However, now that I've done it and have done an upgrade as well, it doesn't seem as bad.

I did something wrong on one of the initial upgrades, and it threw an error. I called in support, and they immediately jumped in and started working on a lot of the backend pieces that I don't normally touch. It's pretty complicated if you have to get into that, and that's where the tech support comes in.

With this last upgrade, I did not run into any errors, and it went through just fine. I thought that I was going to be doing this for six hours throughout the day, and I got it done within two or three hours.

What about the implementation team?

I set it up and upgraded it twice, once with help from LogRhythm and once all by myself.

What's my experience with pricing, setup cost, and licensing?

We're on a perpetual license, but they're trying to move us to a subscription-based license. We've been with them for so long, and we'd like to keep it the way it is rather than switch to a subscription-based license.

Which other solutions did I evaluate?

We looked at four products including QRadar and Rapid7 InsightIDR. We did POCs for all four solutions, and LogRhythm was the best solution for our needs.

One of LogRhythm's distinguishing features was its AI engine which analyzed the tools and allowed it to alert for specific events, instead of me having to dig down and create all these rules. It came with pre-created rules.

Another piece that was really important was the implementation. They had a lot of pieces for third-party vendors as well. We could pull in the logs. All we had to do is just create a rule that says, "alert." It came pre-programmed with a lot of alarms that would automatically correlate with our AV, along with our firewall. We didn't have to create them because they just came in pre-made, and that was a big feature that we looked for. Just implementing it or adding to it didn't take up too much time.

What other advice do I have?

If you are one who thinks that SIEM is an outdated security tool, I would be very curious to know what other solution would be better than a SIEM to accomplish the same goals. A SIEM tool gives you such an open perspective into what is going on in your network and gives you the ability to dig in if you really need to. Whereas if you have a completely managed solution or one that uses AI and does everything for you but doesn't provide you the logs, you might know what's wrong but won't know what else is going on out there. With a SIEM tool, you can dig in as far as you want to, and specifically with LogRhythm, you can be as hands-free as you want to be. It'll tell you what's wrong, and you can address those problems. You have a lot more flexibility with LogRhythm SIEM.

Overall, I'd rate LogRhythm SIEM a nine out of ten. I really enjoyed the solution. If you have to program anything yourself, there is a little bit of a learning curve. They've got lots of guides that you can use, and depending on your skill set, you may be able to figure it out sooner rather than later. The resources are all there, and the community is there to help you, which makes the product really great and easy to use.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Azhar Iqbal - PeerSpot reviewer
Sr security information engineer at a tech services company with 201-500 employees
Real User
Top 10
Jun 17, 2024
A self-hosted platform used to protect network and devices from external and internal threats or attacks
Pros and Cons
  • "LogRhythm SIEM offers advanced features such as AI engine modules, machine learning, and threat intelligence integration, which help reduce false positives. Advanced analytics streamlines incident response processes, enabling incident responders to prioritize and automate alerts."
  • "LogRhythm SIEM can improve its user interface. The current interface is quite complex and can be challenging to navigate. While it offers many valuable features, understanding how to access and utilize them efficiently takes time. Simplifying the client console's user interface would significantly enhance the user experience and make it more user-friendly."

What is our primary use case?

LogRhythm SIEM is a cybersecurity solution that we use to protect our network and devices from external and internal threats or attacks. It's part of our overall cybersecurity strategy, which includes SIEM, EDR, and DLP solutions.

What is most valuable?

LogRhythm SIEM offers advanced features such as AI engine modules, machine learning, and threat intelligence integration, which help reduce false positives. Advanced analytics streamlines incident response processes, enabling incident responders to prioritize and automate alerts.

What needs improvement?

LogRhythm SIEM can improve its user interface. The current interface is quite complex and can be challenging to navigate. While it offers many valuable features, understanding how to access and utilize them efficiently takes time. Simplifying the client console's user interface would significantly enhance the user experience and make it more user-friendly.

For how long have I used the solution?

I have been using LogRhythm SIEM for the past five years.

What do I think about the stability of the solution?

I would give it a nine out of ten in terms of stability, as the support and tech teams are reliable and efficient in resolving issues.

What do I think about the scalability of the solution?

Considering its capacity and ability to meet requirements, I would rate LogRhythm SIEM around seven out of ten.  As a service provider, we cater to multiple users and organizations.

How are customer service and support?

The technical support for LogRhythm SIEM is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup for LogRhythm SIEM can be rated eight out of ten in terms of ease. It's an on-premises deployment and typically takes about ten to fifteen days for a basic setup. Still, depending on the complexity of log sources and integration needs, it could extend to twenty and twenty-five days.

What's my experience with pricing, setup cost, and licensing?


What other advice do I have?

We’ve integrated LogRhythm SIEM with various systems, such as Cisco switches, databases, PAM solutions, and Trend Micro ADA solutions. AI integration plays a significant role in enhancing security monitoring efforts by automating tasks and detecting zero-day attacks.

I would rate LogRhythm SIEM an eight out of ten and recommend it to others.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Security Analyst at a computer software company with 501-1,000 employees
MSP
Nov 24, 2023
The user interface is pretty good compared to other tools, but the product fails if we run big queries
Pros and Cons
  • "The user interface is pretty good compared to other SIEM tools."
  • "Sometimes, the tool fails to get the correlated events that triggered the alerts."

What is our primary use case?

It is an SIEM tool. It gathers logs, parses and normalizes them, and correlates the logs with the rules we write. For example, if an account tries to log in multiple times with the same username, I can write a rule for it. The SIEM tool would analyze the logs and generate alerts based on the rule.

What is most valuable?

The user interface is pretty good compared to other SIEM tools. The log search capabilities are good. It gives results pretty fast.

What needs improvement?

The correlation can be improved. If an alert is generated, we want to know the related events. We often have to search for the drill-down option. Sometimes, it is not available. Sometimes, the tool fails to get the correlated events that triggered the alerts. Searching logs is a bit difficult compared to other tools.

For how long have I used the solution?

I have been using the solution for one year.

What do I think about the stability of the solution?

I rate the tool’s stability a seven out of ten. The tool fails if we run big queries. The search breaks down even if we put a limit on the number of events.

What do I think about the scalability of the solution?

I rate the tool’s scalability a seven out of ten. It generates alerts but doesn’t give us the related events that generated them. Sometimes, we need to mess with the configuration to get it back up. The security team uses the tool to analyze the logs.

Which solution did I use previously and why did I switch?

I used QRadar before. I prefer QRadar over LogRhythm.

How was the initial setup?

The initial setup is easy. It is not that difficult.

What other advice do I have?

People who want to use the solution must not do any big searches. Overall, I rate the product a six out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
MohamedKarram - PeerSpot reviewer
SOC Manager at a tech services company with 11-50 employees
Real User
Jan 27, 2023
It's easy to use and has improved a lot, but the web and on-prem console should be unified
Pros and Cons
  • "I like LogRhythm's ease of use. The solution has improved compared to previous versions. It had many issues before, like integration, the console, creating reports, false positives, etc. The AI engine has made it stronger in the latest version."
  • "The web and on-premise console interface should be the same instead of having a separate engine for each."

What is our primary use case?

We are consultants providing governance solutions for the banking sector. We have a lot of use cases. We have more than 400 use cases for the client side.

What is most valuable?

Its ease of use is valuable. It has improved a lot from the previous versions. It had a lot of issues before, but now, it's way better in terms of integration, the console part, report creation for use cases, false positive numbers, and so on. Its AI engine is a lot more advanced in the latest version.

What needs improvement?

The web and on-premise console interface should be the same instead of having a separate engine for each. 

I hope that they remove the console and have only one GUI. There should be one engine for both the web and the console. They shouldn't have two different engines for each one of them.

There should be easier deployment status, and like Splunk, there should be a more professional way to write the search. There shouldn't be only a drop-down menu. It'll be a good thing to add.

For how long have I used the solution?

I have used LogRhythm for about three years now.

What do I think about the stability of the solution?

LogRhythm SIEM is stable.

What do I think about the scalability of the solution?

LogRhythm SIEM is highly scalable. We have more than nine users working with this solution.

How are customer service and support?

The technical support depends on the technician you get. Some are good, but some aren't.  We had multiple sessions with one person for over a year with no results. Other engineers are excellent. 

How was the initial setup?

Setting up LogRhythm is complex. It took our team more than a month to deploy. We have a large team in my company because we are working with dozens of clients. Our BS team is almost 15 people. 

What about the implementation team?

Its implementation is handled by a different team. We have a very big team in our company because we are working with a lot of clients. Our implementation team has almost 15 people.

What's my experience with pricing, setup cost, and licensing?

There don't seem to be any costs in addition to standard licensing.

What other advice do I have?

I'd recommend LogRhythm SIEM to others. I'd rate it an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.