The web interface, especially since the move to the open source storage system in v7, allows almost instant access to detailed log data from across the platform.
Security Consultant and Co-Founder at a tech consulting company with 51-200 employees
The web interface, especially since the move to the open source storage system in v7, allows almost instant access to detailed log data from across the platform.
What is most valuable?
How has it helped my organization?
I work in the IT Security channel, reselling LogRhythm and associated consultancy services. The improvements from implementation of LogRhythm are to my clients' organizations.
What needs improvement?
The reporting engine is poor in comparison to other areas. It should be moved to the web interface to improve its functionality and usability.
For how long have I used the solution?
I've been using it for over four years, since v3.
Buyer's Guide
LogRhythm SIEM
October 2025

Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,019 professionals have used our research since 2012.
What was my experience with deployment of the solution?
We have had no issues with the deployment.
What do I think about the stability of the solution?
We have had no issues with the stability. We haven't experienced instability.
What do I think about the scalability of the solution?
The scalability before v7 was sometimes difficult due to the hardware performance required. Since v7 was released, the clustering and scalability options have improved significantly.
How are customer service and support?
The UK-based technical support is good, and the engineering and lab teams based in the US are great.
Which solution did I use previously and why did I switch?
I have experience with Splunk and ArcSight. LogRhythm's correlation capabilities (part of the AIE component) is much better than Splunk's, and the solution as a whole is generally cheaper and easier to implement than ArcSight.
How was the initial setup?
The initial setup is straightforward. Follow the initial setup guide and the solution works within hours. Easy to use configuration tools are included.
What about the implementation team?
I work for a reseller and consultancy firm in the IT security channel. I would recommend using a vendor or reseller to assist in the deployment, as although the basic build and set up is easy, on-boarding log sources and setting up the system to report and alarm on events requires experience and expertise.
What other advice do I have?
As part of your plan for SIEM, identify what you expect the SIEM to be able to do for you / your organization. SIEM is not a silver bullet. SIEM will take a considerable amount of use by a security analyst or similar to get the best out of it. SIEM managed services offered by resellers or system integrators may be good value and should be seriously considered to ensure the best outcomes from the SIEM.
Disclosure: My company has a business relationship with this vendor other than being a customer. I work for an independent IT Security Consultancy firm, and work with LogRhythm and their partners in the UK IT Security Channel. I have previously worked for a LogRhythm partner.

Director of Information Technology at a university with 1,001-5,000 employees
I like that it allows me to get a quick scan of what happened in the last 24 hours. We also use it for compliance reasons since we are audited frequently by our state.
Valuable Features
It allows me, through the reporting functions, to take a quick scan of what's happened in the prior 24 hours.
Also, it's essential for our compliance. We're audited frequently and this is the piece that's essentially mandated by the State.
Improvements to My Organization
It creates a good feedback loop whereby I'm able to scan through and see what off-limits activities users have been doing. I think it improves the organization by letting them know that everything that they're doing is not invisible. It's a demonstration to them that they need to do what they say they're going to do and follow the policies that are in place here.
Room for Improvement
I'd like to see a real-time dashboard of events. I know it's available, but it needs work. I haven't been able to put in the 20 or 30 hours that it would take to really become an expert with it. I rely on the PDF reports which guide my day, but having the information in real time in the dashboard would be nice.
To me, the best additional feature would be, much like you see with a firewall or with an antivirus scan or intrusion prevention, a real-time console for activity and almost sort of automatic updates for certain features. That would be helpful.
Use of Solution
We got our first unit here in 2009.
Deployment Issues
We've had no issues with deployment.
Stability Issues
Stability has been fine. There were some problems in earlier versions, but I wouldn't put that all on LogRhythm. Part of it was that we needed and equipment upgrade and it was literally a year and a half or two years where it was optimally built for that we had to continue using the old version, the old appliance, and it took us a long time to get upgraded. So we were dealing with some rather clunky situations, running out of disk space, that kind of thing.
Scalability Issues
I really can't comment on scalability because we're a rather small organization. We only have 50 or 60 staff members and no plans to really grow or extend the use of it out to another organization. From the beginning, it's handled all of our work and again, without any real big plans to grow, it's hard for me to comment on that.
Customer Service and Technical Support
Their support team is very good. As IT organizations go, I can only think of maybe one time when I had to request a second person to look at a problem. They provide timely responses, and they provide really good training. I have no complaints.
Initial Setup
The setup requires an agent to be installed on all the machines and we have an in-house intrusion prevention system server base. We did a fair amount of finagling with that. I would say in an organization without those types of software running, it would be a piece of cake. I think it would be excellent. With us, we had a few extra hurdles to jump through just because of the fact that we had to be so secure in-house here.
Implementation Team
LogRhythm sent the appliance, we hooked it up, and we plugged it in. From there, they gave us 10-15 hours of time with a setup team via WebEx. They took control of the machine and taught us the basics. Then we took it from there.
Pricing, Setup Cost and Licensing
We've maintained the same base of licenses since we began, and it was sized properly. I would say they gave us good advice on how much to spend on licensing. We've been able to collect all the logs we really need here for that issue.
Other Solutions Considered
We evaluated the freeware alternatives, but we needed a turnkey solution and we just didn't have hundreds of hours to put into a starter box, so we went with a commercial buy.
We didn't perform an exhaustive search, but the result was somewhat fortuitous. I began the search and found someone at LogRhythm I felt I got along with. This person was very knowledgeable beyond the salesman-type of knowledge. He was able to relate with our needs here.
Other Advice
I would recommend them. I think that their product has evolved over time. I think there were a couple of years in the very beginning when I was a little frustrated with them, but now, and especially, we just bought a new box last year, the newer version, it seems to have a lot of the kinks worked out, and so I wouldn't have any problem recommending them.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
LogRhythm SIEM
October 2025

Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,019 professionals have used our research since 2012.
Information Security Analyst at a financial services firm with 1,001-5,000 employees
The most valuable feature is the AI engine and we're able to have all of our logs in one place.
What is most valuable?
The most valuable feature is the AI engine, as well as the usual SIEM product stuff. The ability to have all of our logs in one place is a big thing for me.
How has it helped my organization?
It’s brought all of our devices into one area, so I am able to understand and manage all of our devices and understand what is going on with an individual device.
What needs improvement?
The reporting aspect is difficult to use and very difficult to get your own reports. So far this is it; they have a web UI and we had a recent update which fixed a lot of bugs and added a lot of great features. But the reporting is lackluster.
For how long have I used the solution?
I've used it for 10 months.
What was my experience with deployment of the solution?
We've had no issues with deployment.
What do I think about the stability of the solution?
Since we purchased one of their boxes, we've had 99% uptime. The only downtime has been for updates and upgrades. So we've had no issues with instability.
What do I think about the scalability of the solution?
We foresee that it's scalable for our future developments. At the moment, we are using half of what it’s able to do.
How are customer service and technical support?
I've been happy with the support in the initial setup. The support in our environment was well done. For any issues, we have had someone on the phone on that day, so there have been no downtime issue. They are super nice.
Which solution did I use previously and why did I switch?
We didn’t have a solution before. It's usable out-of-the-box and it covers a lot of holes. It's done its job.
Which other solutions did I evaluate?
We looked at AlienVault and Qradar.
What other advice do I have?
Definitely do a test run, a proof of concept, so it’s understood how it’s going to work in your environment. Also, take the training that they provide; i t's super valuable.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VP, Information Systems Security Officer at a financial services firm with 501-1,000 employees
The AI engine correlates the events that it is receiving, taking a lot of guesswork away from the analyst. I’d prefer that it didn’t use the Microsoft Windows platform.
What is most valuable?
The AI engine is what I like the most. It’s all in how LogRhythm correlates the events that it is receiving. It takes a lot of guesswork away from the analyst. We don’t have to reinvent the wheel. Out of the box, it's very easy and intuitive to get started. It’s easy to see the impact of the event in which you are receiving.
What needs improvement?
For me right now, I have not used it long enough to give an evaluation of what the product is lacking. As far as room for improvement, I would like to see the solution be a more hardened operating system other than Windows. I’d prefer that they didn’t use the Microsoft Windows platform. I think that they lose a lot of efficiency and performance that way.
What do I think about the stability of the solution?
When I first deployed the product, I did find some issues with log consumption. The appliance we had was rated at 25,000 messages per second and we run an average of 1,204 messages per second. We are seeing performance issues with the appliance. It appears that there are some inconsistencies that are running with the hardware of the solution.
How are customer service and technical support?
It seems pretty good, but they do seem to be plagued with what a lot of new companies are plagued with -- their internal staff are still learning the product as well. Some of the sessions I’ve had were with technical support, not professional services. We have discovered some answers together instead of the technical support person knowing it off-hand. Some things we stumbled on by accident, some things I had to point out to the agent. Seeing as I have only used the product for two months, that person should know more than I do.
Which solution did I use previously and why did I switch?
I previously used McAfee ESM, QRadar, and ArcSight. McAfee is by far my favorite SIEM to utilize. It is very robust, very quick. The ability to query is much faster than all other popular SIEM tools. Now that it requires a lot more hardware investment, it almost requires a developer mentality to massage the tool to make it do exactly what you want. This is where LogRhythm really outshines McAfee.
What about the implementation team?
It was done in-house. A person from a different state logged on and helped me via web conference and helped me through the initial configuration.
What was our ROI?
I foresee a ROI. You need to understand what an ROI is. We are trying to buy peace of mind. It’s almost an insurance policy. It’s really measured in soft dollars.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Lead Specialist - Information Security at a hospitality company with 1,001-5,000 employees
It quickly allows me to get into forensic data, but while I have some of the beefiest data that they provide, I can still overrun the system. 
What is most valuable?
The speed at which I can get into forensic data is the most useful thing.
What needs improvement?
It’s very easy to overwhelm the system. I have some of the beefiest data that they provide, and I can still overrun the system.
The native ability to identify the correct time of logs and data also needs work, e.g. if I bring in a system log data stream, LogRhythm's ability to natively say it's a Cisco firewall or a Palo Alto firewall -- sometimes it struggles to identify the device.
For how long have I used the solution?
I've used it for 18 months.
How are customer service and technical support?
I love the tech support people. Everyone I have worked with knows their stuff, which is great. I have worked with other SIEM products before and it was hard to find a knowledgeable person. At LogRhythm, everyone I have talked to has been incredibly good.
Which solution did I use previously and why did I switch?
We were a RSA Envision customer. Our platform was going away, so that’s one of the reasons we switched. We weren’t really impressed with the security analytics platform that they wanted us to move to. We didn’t want to make the investment they wanted. For our industry they were lacking.
I had seen LogRhythm before, and back then a few years ago, they weren’t a player in the market. Since then they have moved to a much better security analytics platform. For what we need, LogRhythm is a perfect fit.
How was the initial setup?
It was very straightforward.
What about the implementation team?
We did it in-house.
What was our ROI?
We have had the production environment up now for over a year. I foresee a ROI. The thing about a SIEM, is that it allows you to get a visibility quicker. It’s hard to quantify that soft cost. I’d say we are there or about to be there.
What's my experience with pricing, setup cost, and licensing?
I'm not a fan of the big names in the space. I recommend it as a solution for medium to large business.
What other advice do I have?
I’m in contact with them on a very frequent basis. I work with my contact a few times per month. I can’t complain about them at all.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT Security Specialist at a manufacturing company with 1,001-5,000 employees
Security management is what it's best at, but it's generally for medium-sized companies.
Valuable Features:
The advanced intelligence engine -- in fact, the whole suit -- is very powerful. It depends how you use it. Security management is what it's best at. As far I’m concerned, it’s one of the best.
Room for Improvement:
This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them. The solution is not robust. It depends on the size of the companies and the size of the firewalls you have which will determine if it will work for you. Thus product is really good and easy to use for medium sized companies.
Use of Solution:
I've used it for three years.
Deployment Issues:
Initially we had a lot of issues. Today it has improved dramatically, and it has no issues in deployment.
Stability Issues:
It is very stable, but we have to work with it and identify which logs we need. If we don’t, it doesn't handle the traffic well.
Every tool is different, and you just have to work with it.
Customer Service:
It’s one of the best customer services you could find. Everyone is very knowledgeable and helpful. You aren’t waiting around for tickets to be resolved. If they can’t resolve it, they escalate and resolve quickly.
ROI:
Absolutely we have made a ROI. It resolves a lot of issues. It helps a lot of our infrastructure and everyone is benefiting. It’s absolutely worth the money spent.
Cost and Licensing Advice:
They are very transparent about the licensing. They are upfront. They tell you what can handle what. They are honest people.
Other Advice:
I have been invited to user group meetings and we have had good conversations. They have been very helpful and they understand my needs. They listen to our input and really take it seriously. They really work with us on different issues.
Everything is fantastic.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Systems Administrator at a financial services firm with 501-1,000 employees
We selected it based on the ability to comply with regulations and its advanced features, but support needs to be improved.
Valuable Features
The log aggregation is what we use it for.
We don’t have a lot of the reporting configured or the advanced analytics. When the time is right, we will we will make the most of these features.
Improvements to My Organization
We need to improve our internal training and use of it. We use it, but we don’t use it to its potential. It’s a very powerful and robust device and application. We don’t use it how we could.
Room for Improvement
I don’t have a lot of confidence in their support. The support is not first class. I am still working with them with follow ups with the numerous issues we have had. The appliance itself seems to be doing what it’s supposed to, but the support is lacking.
Use of Solution
I've used it for six years.
Deployment Issues
We went through research of multiple products that were similar in nature and selected LogRhythm based on the ability to comply with regulations and the advanced features that it offered. It’s a really deep product and you can do a lot with it, but it just hasn't been realized.
Stability Issues
It handles what we throw at it.
Customer Service and Technical Support
I have mixed feelings. We have had some issues with their internal support.
We lost our ability to access the support portal, and it took them around three weeks to resolve it. We had a new upgraded appliance implemented and professional services set it up. They failed to take all of the alerts and bring it to the new appliance.
Implementation Team
We implemented it in-house.
Pricing, Setup Cost and Licensing
The licensing has improved. It has gone down because it is no longer individual monitoring licensing, whereas before it was licensed per collection manager. They have given us decent pricing, they gave us credit for the old appliance.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Analyst at a retailer with 1,001-5,000 employees
We are able to manage the items we have coming in with one product; however, if the client doesn't have a customer in their system, they can’t use it.
What is most valuable?
I find that the ease of installation is a valuable part of the solution.
How has it helped my organization?
The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot.
What needs improvement?
The main area of improvement is that the client must be installed on the computer for all of the functions to work. So if the client doesn't have a customer in their system, they can’t use it.
For how long have I used the solution?
I have been directly responsible for this install around two years. I worked with LogRhythm at another company for around three years.
What was my experience with deployment of the solution?
We didn’t encounter any issues that were not fixable.
What do I think about the stability of the solution?
I can’t remember the last time it was down. It’s very stable.
What do I think about the scalability of the solution?
The way it’s set up with agents, we can scale very well and if we need to we can just add more hardware to the system. The only limit is the hardware. We have been happy with it.
How are customer service and technical support?
Very knowledgeable, though I wouldn’t say proactive. When you speak with technical support you don’t actual speak with someone: you leave a message, which I do not like, although they respond pretty quickly.
Which solution did I use previously and why did I switch?
The scalability was the main reason for switching. You never know how much you may need and the ability to quickly adapt is great.
The ability to add something quickly is very important. It's more complete than a lot of products, such as Splunk, but you have to put in a lot of work.
With LogRhythm, security feeds and security alerts are just built in.
What about the implementation team?
We did migrate recently and had help from LogRhythm.
What was our ROI?
I’d say we have an ROI. It helps us identity problems before they become issues.
What's my experience with pricing, setup cost, and licensing?
Always plan for more logs than you think you have. Once you start collecting you will realize that you need more than you thought.
What other advice do I have?
My relationship has been very good. When we updated our software we set up weekly meetings which really helped us with reporting. We don’t directly get in touch with support but when we do they solve our problems.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
        sharing their opinions. 
Updated: October 2025
Popular Comparisons
CrowdStrike Falcon
Dynatrace
Datadog
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Grafana Loki
Security Onion
Graylog Enterprise
Rapid7 InsightIDR
Fortinet FortiSIEM
Amazon CloudWatch
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
        sharing their opinions. 
Quick Links
Learn More: Questions:
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- Does LogRhythm NextGen SIEM offer good security?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?


















