Associate Senior Engineer - Network & Security at Connex Information Technologies (Pvt) Ltd.
Reseller
Enables us to alternate incident automations but reporting needs improvement
Pros and Cons
  • "The most valuable feature is that we can alternate incident automations."
  • "We need to get better training for things like creating code and playlists. The way it's done now takes a long time."

What is our primary use case?

Our primary use case is for financial companies and telcos.

What is most valuable?

The most valuable feature is that we can alternate incident automations.

What needs improvement?

We need to get better training for things like creating code and playlists. The way it's done now takes a long time. 

For how long have I used the solution?

I have been using LogRhythm NextGen SIEM for two years. 

Buyer's Guide
LogRhythm SIEM
March 2024
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,924 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability depends on the client we installing or integrating for based on the server's requirements. We can create them according to that defined time period. It's not that difficult but depending on the customer or the other server requirements.

We can have a dashboard in a single platform, we can get notifications via email or SMS, and we have Smart Response actions. So that kind of possibility is there.

What do I think about the scalability of the solution?

Our clients are mostly on a larger scale. 

How are customer service and support?

You can request support and they respond immediately. They're really good. 

How was the initial setup?

The initial setup is easy. It can take two hours. The first day of deployment is easy. Then depending on the devices and log servers, it can take time. We can give them predefined or pre-created devices and logs. The deployment depends on the devices and systems we are integrating. But the initial stage is easy.

What's my experience with pricing, setup cost, and licensing?

Because we are a developing country, the costs depend on country development. We implement it for large-scale companies because normal companies, startup companies, can't afford products at that price. We mainly focus on large-scale companies.

What other advice do I have?

I would definitely recommend this solution if you can afford it. 

We get customized reports and we get reports including all the details, but when we start using them we couldn't start with the Outlook editor. We can customize a document and we can write a report. The dashboards are very user-friendly and very attractive. But when it comes to the reporting part, I think that could use improvement in the next release. 

I would rate it a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
PeerSpot user
it_user769656 - PeerSpot reviewer
Information Security Architect at a healthcare company with 1,001-5,000 employees
Video Review
Vendor
We can constantly add logs into our system without any issues; find and fix problems fast

What is most valuable?

I believe the most valuable feature for us has been that we have all the logs together. We can query them, we can find all kinds of different situations that are going on in our network that we wouldn't have knowledge of without searching many different servers and logs.

How has it helped my organization?

Quicker ability to troubleshoot the problem, find the problem, get it fixed, and get the customers back up and using our system. 

What needs improvement?

I'm sure there are always areas, in stability and scaling, that need improvement. I don't have anything right off that I can say I know needs improvement right at this point.

What do I think about the stability of the solution?

We installed in 2009, and the stability has improved over the years. I consider it to be quite a stable product now. It seems to work day after day, week after week.

What do I think about the scalability of the solution?

With version 7, we feel the scaling improved a lot. We are a large health system and we are quite often adding new businesses, new healthcare offices, new hospitals to our system. We we are able to add those extra logs into our system without causing any issues.

How is customer service and technical support?

Tech support has always been good from the very first. In most cases the first response is a good one. It does the job, and if not, then you get back to them and they stay with you until they get it fixed.

How was the initial setup?

We thought the setup was very quick and easy, of course we didn't try to boil the ocean all at once. We've been, over the years, adding more and more phases to our system, completed it in phases.

What other advice do I have?

Really figure out what you want it to do for you, because it is very flexible and can be used for many different purposes. Determine what you want to use it for, and then get the assistance from LogRhythm to help implement it in that way. Then you can always expand it and take in other areas. But your primary goals need to be met right up front.

We are very happy with it.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
LogRhythm SIEM
March 2024
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,924 professionals have used our research since 2012.
it_user756348 - PeerSpot reviewer
IT Security Analyst at a financial services firm with 201-500 employees
Real User
It has helped tremendously when following up on investigations and logs

How has it helped my organization?

It has helped tremendously when following up on investigations and logs. We often get bogged down with many tasks during the day. We can actually come back to a particular scenario that we are looking into, so it has been very beneficial for that.

Key challenges are our users and network. In our network, we get logs from a particular product called a NetScaler, which hides our source IPs, so that makes it a little challenging. Our goals are to tune LogRhythm further and utilize all the different modules that they do offer us. It is a challenge to get it all done.

What is most valuable?

  • The web console
  • The case management

What needs improvement?

I did hear about the new playbook edition coming up and I am excited about it.

What do I think about the scalability of the solution?

It is excellent.

How is customer service and technical support?

I have used the tech support and think they are great. I have many vendors that I deal with for other tools and hands down LogRhythm has been the best SIEM solution.

What other advice do I have?

It is a big project, but very worthwhile, and LogRhythm has plenty of documentation, support people, professional services, and classes that can help get a business implemented and push them all the way to completion. I definitely think it is worthwhile.

It is very important for me that the solution be a unified end-to-end platform.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user341220 - PeerSpot reviewer
Systems Administrator at a financial services firm with 501-1,000 employees
Vendor
We selected it based on the ability to comply with regulations and its advanced features, but support needs to be improved.

Valuable Features

The log aggregation is what we use it for.

We don’t have a lot of the reporting configured or the advanced analytics. When the time is right, we will we will make the most of these features.

Improvements to My Organization

We need to improve our internal training and use of it. We use it, but we don’t use it to its potential. It’s a very powerful and robust device and application. We don’t use it how we could.

Room for Improvement

I don’t have a lot of confidence in their support. The support is not first class. I am still working with them with follow ups with the numerous issues we have had. The appliance itself seems to be doing what it’s supposed to, but the support is lacking.

Use of Solution

I've used it for six years.

Deployment Issues

We went through research of multiple products that were similar in nature and selected LogRhythm based on the ability to comply with regulations and the advanced features that it offered. It’s a really deep product and you can do a lot with it, but it just hasn't been realized.

Stability Issues

It handles what we throw at it.

Customer Service and Technical Support

I have mixed feelings. We have had some issues with their internal support.

We lost our ability to access the support portal, and it took them around three weeks to resolve it. We had a new upgraded appliance implemented and professional services set it up. They failed to take all of the alerts and bring it to the new appliance.

Implementation Team

We implemented it in-house.

Pricing, Setup Cost and Licensing

The licensing has improved. It has gone down because it is no longer individual monitoring licensing, whereas before it was licensed per collection manager. They have given us decent pricing, they gave us credit for the old appliance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user341262 - PeerSpot reviewer
Security Analyst at a retailer with 1,001-5,000 employees
Vendor
We are able to manage the items we have coming in with one product; however, if the client doesn't have a customer in their system, they can’t use it.

What is most valuable?

I find that the ease of installation is a valuable part of the solution.

How has it helped my organization?

The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot.

What needs improvement?

The main area of improvement is that the client must be installed on the computer for all of the functions to work. So if the client doesn't have a customer in their system, they can’t use it.

For how long have I used the solution?

I have been directly responsible for this install around two years. I worked with LogRhythm at another company for around three years.

What was my experience with deployment of the solution?

We didn’t encounter any issues that were not fixable.

What do I think about the stability of the solution?

I can’t remember the last time it was down. It’s very stable.

What do I think about the scalability of the solution?

The way it’s set up with agents, we can scale very well and if we need to we can just add more hardware to the system. The only limit is the hardware. We have been happy with it.

How are customer service and technical support?

Very knowledgeable, though I wouldn’t say proactive. When you speak with technical support you don’t actual speak with someone: you leave a message, which I do not like, although they respond pretty quickly.

Which solution did I use previously and why did I switch?

The scalability was the main reason for switching. You never know how much you may need and the ability to quickly adapt is great.

The ability to add something quickly is very important. It's more complete than a lot of products, such as Splunk, but you have to put in a lot of work.

With LogRhythm, security feeds and security alerts are just built in.

What about the implementation team?

We did migrate recently and had help from LogRhythm.

What was our ROI?

I’d say we have an ROI. It helps us identity problems before they become issues.

What's my experience with pricing, setup cost, and licensing?

Always plan for more logs than you think you have. Once you start collecting you will realize that you need more than you thought.

What other advice do I have?

My relationship has been very good. When we updated our software we set up weekly meetings which really helped us with reporting. We don’t directly get in touch with support but when we do they solve our problems.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user313884 - PeerSpot reviewer
Contract Sr. Security Engineer, LogRhythm Analysis/Forensics at a financial services firm with 1,001-5,000 employees
Vendor
It provides reports on the Cardholder Data Environment at 95% effectiveness, but to operate at the 99.99% level, it needs to have uninterrupted reporting host connections to the Log Mediator.

LogRhythm is a perfect example of "Garbage In, Garbage Out" in Information Security—LogRhythm reports on the Cardholder Data Environment (CDE) activity are only as reliable as the data coming in.

If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically. Even when reporting at 95% effectiveness, critical information regarding Threat Agent activity is probably still missing.

To operate at the 99.99% level, LogRhythm needs to have uninterrupted reporting host connections to LogRhythm’s Log Mediator(s) for optimal LogRhythm device functioning, complete and valid CDE host presence in LogRhythm’s log records, the minimization of false positives (Trash Traffic), the use of dedicated LogRhythm Appliances (not VMs), and flexibility in LogRhythm Change Management procedures that accommodate swiftly to LogRhythm-specific needs.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

like :dude - Speciallyyyy LogRhythm Change Management

Consultant at a tech services company with 11-50 employees
Consultant
Top 10
User-friendly security solution
Pros and Cons
  • "NextGen SIEM's most valuable feature is its user-friendliness."
  • "NextGen SIEM's integration with other software is good but could be improved."

What is our primary use case?

NextGen SIEM is primarily used by the SOC team to detect attacks. 

What is most valuable?

NextGen SIEM's most valuable feature is its user-friendliness.

What needs improvement?

NextGen SIEM's integration with other software is good but could be improved.

For how long have I used the solution?

I've been working with LogRhythm NextGen SIEM for three years.

What do I think about the stability of the solution?

NextGen SIEM is stable.

How was the initial setup?

The initial setup was straightforward.

What other advice do I have?

I would recommend NextGen SIEM to those considering implementing it and would rate it eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Real User
Great dashboards at a competitive price
Pros and Cons
  • "NextGen SIEM's best feature is how it presents logs."
  • "NextGen SIEM has separate rules for AI, advanced intelligence, and MP rules - it would be better to have a centralized way to write the rules and create alarms."

What is most valuable?

NextGen SIEM's best feature is how it presents logs. For example, the dashboard view is detachable from other things.

What needs improvement?

NextGen SIEM has separate rules for AI, advanced intelligence, and MP rules - it would be better to have a centralized way to write the rules and create alarms. In the next release, I would like to see the network hierarchy diagram that QRadar offers.

For how long have I used the solution?

I've been using LogRhythm NextGen SIEM for one year.

What do I think about the stability of the solution?

NextGen SIEM's performance is quite good.

What do I think about the scalability of the solution?

NextGen SIEM is easy to scale.

Which solution did I use previously and why did I switch?

I previously used QRadar SIEM.

How was the initial setup?

The initial setup was simple, and it took two days to deploy.

What's my experience with pricing, setup cost, and licensing?

NextGen SIEM's pricing is moderate. There are additional costs for different applications.

What other advice do I have?

I would recommend NextGen SIEM to other users as it is a leading solution with new features at a better price than competitors like Splunk and QRadar.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partners
PeerSpot user
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.