Try our new research platform with insights from 80,000+ expert users
it_user386685 - PeerSpot reviewer
Director of Information Technology at a university with 1,001-5,000 employees
Vendor
I like that it allows me to get a quick scan of what happened in the last 24 hours. We also use it for compliance reasons since we are audited frequently by our state.

What is most valuable?

It allows me, through the reporting functions, to take a quick scan of what's happened in the prior 24 hours.

Also, it's essential for our compliance. We're audited frequently and this is the piece that's essentially mandated by the State.

How has it helped my organization?

It creates a good feedback loop whereby I'm able to scan through and see what off-limits activities users have been doing. I think it improves the organization by letting them know that everything that they're doing is not invisible. It's a demonstration to them that they need to do what they say they're going to do and follow the policies that are in place here.

What needs improvement?

I'd like to see a real-time dashboard of events. I know it's available, but it needs work. I haven't been able to put in the 20 or 30 hours that it would take to really become an expert with it. I rely on the PDF reports which guide my day, but having the information in real time in the dashboard would be nice.

To me, the best additional feature would be, much like you see with a firewall or with an antivirus scan or intrusion prevention, a real-time console for activity and almost sort of automatic updates for certain features. That would be helpful.

For how long have I used the solution?

We got our first unit here in 2009.

Buyer's Guide
LogRhythm SIEM
June 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.

What was my experience with deployment of the solution?

We've had no issues with deployment.

What do I think about the stability of the solution?

Stability has been fine. There were some problems in earlier versions, but I wouldn't put that all on LogRhythm. Part of it was that we needed and equipment upgrade and it was literally a year and a half or two years where it was optimally built for that we had to continue using the old version, the old appliance, and it took us a long time to get upgraded. So we were dealing with some rather clunky situations, running out of disk space, that kind of thing.

What do I think about the scalability of the solution?

I really can't comment on scalability because we're a rather small organization. We only have 50 or 60 staff members and no plans to really grow or extend the use of it out to another organization. From the beginning, it's handled all of our work and again, without any real big plans to grow, it's hard for me to comment on that.

How are customer service and support?

Their support team is very good. As IT organizations go, I can only think of maybe one time when I had to request a second person to look at a problem. They provide timely responses, and they provide really good training. I have no complaints.

How was the initial setup?

The setup requires an agent to be installed on all the machines and we have an in-house intrusion prevention system server base. We did a fair amount of finagling with that. I would say in an organization without those types of software running, it would be a piece of cake. I think it would be excellent. With us, we had a few extra hurdles to jump through just because of the fact that we had to be so secure in-house here.

What about the implementation team?

LogRhythm sent the appliance, we hooked it up, and we plugged it in. From there, they gave us 10-15 hours of time with a setup team via WebEx. They took control of the machine and taught us the basics. Then we took it from there.

What's my experience with pricing, setup cost, and licensing?

We've maintained the same base of licenses since we began, and it was sized properly. I would say they gave us good advice on how much to spend on licensing. We've been able to collect all the logs we really need here for that issue.

Which other solutions did I evaluate?

We evaluated the freeware alternatives, but we needed a turnkey solution and we just didn't have hundreds of hours to put into a starter box, so we went with a commercial buy.

We didn't perform an exhaustive search, but the result was somewhat fortuitous. I began the search and found someone at LogRhythm I felt I got along with. This person was very knowledgeable beyond the salesman-type of knowledge. He was able to relate with our needs here.

What other advice do I have?

I would recommend them. I think that their product has evolved over time. I think there were a couple of years in the very beginning when I was a little frustrated with them, but now, and especially, we just bought a new box last year, the newer version, it seems to have a lot of the kinks worked out, and so I wouldn't have any problem recommending them.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user375531 - PeerSpot reviewer
Information Security Analyst at a financial services firm with 1,001-5,000 employees
Vendor
The most valuable feature is the AI engine and we're able to have all of our logs in one place.

What is most valuable?

The most valuable feature is the AI engine, as well as the usual SIEM product stuff. The ability to have all of our logs in one place is a big thing for me.

How has it helped my organization?

It’s brought all of our devices into one area, so I am able to understand and manage all of our devices and understand what is going on with an individual device.

What needs improvement?

The reporting aspect is difficult to use and very difficult to get your own reports. So far this is it; they have a web UI and we had a recent update which fixed a lot of bugs and added a lot of great features. But the reporting is lackluster.

For how long have I used the solution?

I've used it for 10 months.

What was my experience with deployment of the solution?

We've had no issues with deployment.

What do I think about the stability of the solution?

Since we purchased one of their boxes, we've had 99% uptime. The only downtime has been for updates and upgrades. So we've had no issues with instability.

What do I think about the scalability of the solution?

We foresee that it's scalable for our future developments. At the moment, we are using half of what it’s able to do.

How are customer service and technical support?

I've been happy with the support in the initial setup. The support in our environment was well done. For any issues, we have had someone on the phone on that day, so there have been no downtime issue. They are super nice.

Which solution did I use previously and why did I switch?

We didn’t have a solution before. It's usable out-of-the-box and it covers a lot of holes. It's done its job.

Which other solutions did I evaluate?

We looked at AlienVault and Qradar.

What other advice do I have?

Definitely do a test run, a proof of concept, so it’s understood how it’s going to work in your environment. Also, take the training that they provide; i t's super valuable.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
LogRhythm SIEM
June 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
it_user338868 - PeerSpot reviewer
VP, Information Systems Security Officer at a financial services firm with 501-1,000 employees
Vendor
The AI engine correlates the events that it is receiving, taking a lot of guesswork away from the analyst. I’d prefer that it didn’t use the Microsoft Windows platform.

What is most valuable?

The AI engine is what I like the most. It’s all in how LogRhythm correlates the events that it is receiving. It takes a lot of guesswork away from the analyst. We don’t have to reinvent the wheel. Out of the box, it's very easy and intuitive to get started. It’s easy to see the impact of the event in which you are receiving.

What needs improvement?

For me right now, I have not used it long enough to give an evaluation of what the product is lacking. As far as room for improvement, I would like to see the solution be a more hardened operating system other than Windows. I’d prefer that they didn’t use the Microsoft Windows platform. I think that they lose a lot of efficiency and performance that way.

What do I think about the stability of the solution?

When I first deployed the product, I did find some issues with log consumption. The appliance we had was rated at 25,000 messages per second and we run an average of 1,204 messages per second. We are seeing performance issues with the appliance. It appears that there are some inconsistencies that are running with the hardware of the solution.

How are customer service and technical support?

It seems pretty good, but they do seem to be plagued with what a lot of new companies are plagued with -- their internal staff are still learning the product as well. Some of the sessions I’ve had were with technical support, not professional services. We have discovered some answers together instead of the technical support person knowing it off-hand. Some things we stumbled on by accident, some things I had to point out to the agent. Seeing as I have only used the product for two months, that person should know more than I do.

Which solution did I use previously and why did I switch?

I previously used McAfee ESM, QRadar, and ArcSight. McAfee is by far my favorite SIEM to utilize. It is very robust, very quick. The ability to query is much faster than all other popular SIEM tools. Now that it requires a lot more hardware investment, it almost requires a developer mentality to massage the tool to make it do exactly what you want. This is where LogRhythm really outshines McAfee.

What about the implementation team?

It was done in-house. A person from a different state logged on and helped me via web conference and helped me through the initial configuration.

What was our ROI?

I foresee a ROI. You need to understand what an ROI is. We are trying to buy peace of mind. It’s almost an insurance policy. It’s really measured in soft dollars.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user341256 - PeerSpot reviewer
Lead Specialist - Information Security at a hospitality company with 1,001-5,000 employees
Vendor
It quickly allows me to get into forensic data, but while I have some of the beefiest data that they provide, I can still overrun the system.

What is most valuable?

The speed at which I can get into forensic data is the most useful thing.

What needs improvement?

It’s very easy to overwhelm the system. I have some of the beefiest data that they provide, and I can still overrun the system.

The native ability to identify the correct time of logs and data also needs work, e.g. if I bring in a system log data stream, LogRhythm's ability to natively say it's a Cisco firewall or a Palo Alto firewall -- sometimes it struggles to identify the device.

For how long have I used the solution?

I've used it for 18 months.

How are customer service and technical support?

I love the tech support people. Everyone I have worked with knows their stuff, which is great. I have worked with other SIEM products before and it was hard to find a knowledgeable person. At LogRhythm, everyone I have talked to has been incredibly good.

Which solution did I use previously and why did I switch?

We were a RSA Envision customer. Our platform was going away, so that’s one of the reasons we switched. We weren’t really impressed with the security analytics platform that they wanted us to move to. We didn’t want to make the investment they wanted. For our industry they were lacking.

I had seen LogRhythm before, and back then a few years ago, they weren’t a player in the market. Since then they have moved to a much better security analytics platform. For what we need, LogRhythm is a perfect fit.

How was the initial setup?

It was very straightforward.

What about the implementation team?

We did it in-house.

What was our ROI?

We have had the production environment up now for over a year. I foresee a ROI. The thing about a SIEM, is that it allows you to get a visibility quicker. It’s hard to quantify that soft cost. I’d say we are there or about to be there.

What's my experience with pricing, setup cost, and licensing?

I'm not a fan of the big names in the space. I recommend it as a solution for medium to large business.

What other advice do I have?

I’m in contact with them on a very frequent basis. I work with my contact a few times per month. I can’t complain about them at all.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user341232 - PeerSpot reviewer
IT Security Specialist at a manufacturing company with 1,001-5,000 employees
Vendor
Security management is what it's best at, but it's generally for medium-sized companies.

Valuable Features:

The advanced intelligence engine -- in fact, the whole suit -- is very powerful. It depends how you use it. Security management is what it's best at. As far I’m concerned, it’s one of the best.

Room for Improvement:

This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them. The solution is not robust. It depends on the size of the companies and the size of the firewalls you have which will determine if it will work for you. Thus product is really good and easy to use for medium sized companies.

Use of Solution:

I've used it for three years.

Deployment Issues:

Initially we had a lot of issues. Today it has improved dramatically, and it has no issues in deployment.

Stability Issues:

It is very stable, but we have to work with it and identify which logs we need. If we don’t, it doesn't handle the traffic well. 

Every tool is different, and you just have to work with it.

Customer Service:

It’s one of the best customer services you could find. Everyone is very knowledgeable and helpful. You aren’t waiting around for tickets to be resolved. If they can’t resolve it, they escalate and resolve quickly.

ROI:

Absolutely we have made a ROI. It resolves a lot of issues. It helps a lot of our infrastructure and everyone is benefiting. It’s absolutely worth the money spent.

Cost and Licensing Advice:

They are very transparent about the licensing. They are upfront. They tell you what can handle what. They are honest people.

Other Advice:

I have been invited to user group meetings and we have had good conversations. They have been very helpful and they understand my needs. They listen to our input and really take it seriously. They really work with us on different issues. 

Everything is fantastic.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user341220 - PeerSpot reviewer
Systems Administrator at a financial services firm with 501-1,000 employees
Vendor
We selected it based on the ability to comply with regulations and its advanced features, but support needs to be improved.

Valuable Features

The log aggregation is what we use it for.

We don’t have a lot of the reporting configured or the advanced analytics. When the time is right, we will we will make the most of these features.

Improvements to My Organization

We need to improve our internal training and use of it. We use it, but we don’t use it to its potential. It’s a very powerful and robust device and application. We don’t use it how we could.

Room for Improvement

I don’t have a lot of confidence in their support. The support is not first class. I am still working with them with follow ups with the numerous issues we have had. The appliance itself seems to be doing what it’s supposed to, but the support is lacking.

Use of Solution

I've used it for six years.

Deployment Issues

We went through research of multiple products that were similar in nature and selected LogRhythm based on the ability to comply with regulations and the advanced features that it offered. It’s a really deep product and you can do a lot with it, but it just hasn't been realized.

Stability Issues

It handles what we throw at it.

Customer Service and Technical Support

I have mixed feelings. We have had some issues with their internal support.

We lost our ability to access the support portal, and it took them around three weeks to resolve it. We had a new upgraded appliance implemented and professional services set it up. They failed to take all of the alerts and bring it to the new appliance.

Implementation Team

We implemented it in-house.

Pricing, Setup Cost and Licensing

The licensing has improved. It has gone down because it is no longer individual monitoring licensing, whereas before it was licensed per collection manager. They have given us decent pricing, they gave us credit for the old appliance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user341262 - PeerSpot reviewer
Security Analyst at a retailer with 1,001-5,000 employees
Vendor
We are able to manage the items we have coming in with one product; however, if the client doesn't have a customer in their system, they can’t use it.

What is most valuable?

I find that the ease of installation is a valuable part of the solution.

How has it helped my organization?

The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot.

What needs improvement?

The main area of improvement is that the client must be installed on the computer for all of the functions to work. So if the client doesn't have a customer in their system, they can’t use it.

For how long have I used the solution?

I have been directly responsible for this install around two years. I worked with LogRhythm at another company for around three years.

What was my experience with deployment of the solution?

We didn’t encounter any issues that were not fixable.

What do I think about the stability of the solution?

I can’t remember the last time it was down. It’s very stable.

What do I think about the scalability of the solution?

The way it’s set up with agents, we can scale very well and if we need to we can just add more hardware to the system. The only limit is the hardware. We have been happy with it.

How are customer service and technical support?

Very knowledgeable, though I wouldn’t say proactive. When you speak with technical support you don’t actual speak with someone: you leave a message, which I do not like, although they respond pretty quickly.

Which solution did I use previously and why did I switch?

The scalability was the main reason for switching. You never know how much you may need and the ability to quickly adapt is great.

The ability to add something quickly is very important. It's more complete than a lot of products, such as Splunk, but you have to put in a lot of work.

With LogRhythm, security feeds and security alerts are just built in.

What about the implementation team?

We did migrate recently and had help from LogRhythm.

What was our ROI?

I’d say we have an ROI. It helps us identity problems before they become issues.

What's my experience with pricing, setup cost, and licensing?

Always plan for more logs than you think you have. Once you start collecting you will realize that you need more than you thought.

What other advice do I have?

My relationship has been very good. When we updated our software we set up weekly meetings which really helped us with reporting. We don’t directly get in touch with support but when we do they solve our problems.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user331482 - PeerSpot reviewer
Senior Manager, Distributed Systems at a insurance company with 501-1,000 employees
Vendor
It's reduced the time and effort necessary to manage and review logs and produce reports for regulatory compliance, though their professional services hourly rate is above average.

What is most valuable?

  • SIEM
  • File Integrity Monitoring
  • Danned compliance reports (PCI, GLBA, HIPAA).

How has it helped my organization?

The solution has significantly reduced the time and effort necessary to manage and review logs and produce reports for regulatory compliance.

What needs improvement?

No current suggestions.

For how long have I used the solution?

I've used it for six years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

8/10

Technical Support:

10/10

Which solution did I use previously and why did I switch?

No previous solution was in place.

How was the initial setup?

Our entire implementation was completed in one day.

What about the implementation team?

The vendor team was one of the best we have ever worked with. They were able to work through issues not covered in their implementation manuals quickly, and without further support.

What was our ROI?

No ROI. The solution is in place to meet PCI compliance and improve our overall security posture.

What's my experience with pricing, setup cost, and licensing?

While LogRhythm's professional services are one of the best we have ever worked with, their hourly rate is generally quoted at a much higher rate than the industry standard. Additionally, the hours necessary for an engagement are also regularly over estimated.

Which other solutions did I evaluate?

Several other solutions were considered including Q1 Labs (now IBM), EMC, and HP.

What other advice do I have?

There were two primary reasons we selected LogRhythm. First was the ease of implementation, which was extremely simple and straight forward. Second, was the integration of file integrity monitoring. LogRhythm at the time, and I believe still today, was the only vendor that provided a solution that included integrated SIEM and FIM.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.