Try our new research platform with insights from 80,000+ expert users
it_user331431 - PeerSpot reviewer
Senior Information Systems Specialist at a manufacturing company with 1,001-5,000 employees
Vendor
Our team has been able to correlate security events and react quicker to incidents, though retrieving logs that have been archived can be difficult and time consuming.

What is most valuable?

The product was easy to deploy and easy to learn how to use. The web console is the best I’ve seen when compared to other SIEMs.

How has it helped my organization?

This product has made it easier for our team to correlate security events and react quicker to incidents.

What needs improvement?

Retrieving logs that have been archived can be a difficult and time consuming process. The module which performs this, called the Second Look Wizard is not very well integrated into the rest of the product. It would be nice if you had the ability to right click on a log and search the archives for more data like it (you can do this with non-archived logs) and then after restoring archived logs, easily pivot to an investigation for that data. Currently, those 3 steps all have to be run separately.

For how long have I used the solution?

I've used it for five months.

Buyer's Guide
LogRhythm SIEM
June 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.

What was my experience with deployment of the solution?

The deployment was very smooth.

What do I think about the stability of the solution?

There were occasional stability problems, but they were resolved by support in a timely fashion.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and support?

Customer Service:

Excellent, everyone I have worked with at LogRhythm has been courteous and helpful.

Technical Support:

Technical support has been very good, and they will often go out of their way to help correct an issue, even if it is not a technical issue with the product.

Which solution did I use previously and why did I switch?

This is our first SIEM.

How was the initial setup?

The initial setup was done with the help of LogRhythm Professional Services and was fairly straightforward. Our version of the software is integrated into one hardware unit which made it easy to setup and understand.

What about the implementation team?

We implemented with LogRhythm Professional Services and the engineer I worked with was very thorough and knowledgable.

What's my experience with pricing, setup cost, and licensing?

Pricing was on the higher end when compared to other products we looked at. However, we felt the advantages with LogRhythm justified the price premium. Licensing is fair and straightforward. We evaluated SIEMs from AlienVault, Tripwire, and Solarwinds.

Which other solutions did I evaluate?

We evaluated SIEMs from AlienVault, Tripwire, and Solarwinds.

What other advice do I have?

If implementing a SIEM for the first time, it is very important to have members of the network and server teams involved from the beginning. Also, strong change management policies are necessary to keep the SIEM implemented properly.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user326751 - PeerSpot reviewer
VP, Information Security Officer with 501-1,000 employees
Real User
Custom rules/alerts in LRM and AIE provide insight into network for internal users and InfoSec, although adding an entity could be much faster.

What is most valuable?

  • Advanced Intelligence Engine (AIE) for threat intelligence, 9/10
  • LRM for logging and compliance, 8/10

How has it helped my organization?

Custom rules/alerts in LRM and AIE provide insight into network for internal users as well as InfoSec. Proactive account lockout alerts for SecAdmin, alerts to DBAs on domain admin access to SQL servers, PCI and GLBA compliance alerts/reports for InfoSec and Audit.

What needs improvement?

Adding an entity (should be able to create a template and/or eliminate locations) could be much faster/streamlined. The wizard could be improved to specify OU/Groups to search for new entities.

For how long have I used the solution?

  • LRM – four years
  • AIE – three years

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

There have been issues with the hardware which has resulted in the LRM going down a few times.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's the best there is.

Technical Support:

It's the best there is.

Which solution did I use previously and why did I switch?

We had Tripwire, but we needed logging and SIEM, not just logging.

How was the initial setup?

It was straightforward as the training provided all the tools. Also, the UI has gotten better with time.

What about the implementation team?

We had a mix of an in-house team with one from LogRhythm.

What was our ROI?

Literally impossible to quantify. We haven’t had any events or deficiencies in audits, which is invaluable.

What's my experience with pricing, setup cost, and licensing?

Pricing (especially considering feature sets) is best in the market, though HA/DR is tough to justify for a SMB. Even with two outages due to hardware we haven’t invested in a backup.

Which other solutions did I evaluate?

  • QRadar
  • RSA
  • Tripwire

What other advice do I have?

Implementation time, hygene/maintenance time, functionality, and cost make it the clear choice in a competitive market.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
LogRhythm SIEM
June 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
it_user326481 - PeerSpot reviewer
Sr. Mgr of Network Operations at a comms service provider with 501-1,000 employees
Vendor
It allows us to detect and remediate Advanced Persistent Threats, but the log management database needs to be more efficient.

Valuable Features

  • Investigation
  • Advanced Intelligence Engine
  • Alarming and Response

Improvements to My Organization

We have made this the foundation of our security intelligence within our organization. It has allows us to detect and remediate Advanced Persistent Threats.

Room for Improvement

I would like to the log management database perform more efficiently.

Use of Solution

I've used it for five years.

Stability Issues

Some minor bugs with the mediator. Those have been fixed in patch releases a long time ago.

Customer Service and Technical Support

Customer Service:

9/10.

Technical Support:

9/10.

Initial Setup

Setup was fairly straightforward. We were up and running with coverage of most log sources within two days.

Implementation Team

We implemented it in-house. Active Directory import makes initial configuration quick and easy.

Other Solutions Considered

We also evaluated Splunk, and we chose LogRhythm as the correlation rules performed it handled clients on DHCP better.

Other Advice

We recommend that people implementing it choose to log everything, including logs from desktops, laptops, servers, switches and routers.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user313884 - PeerSpot reviewer
Contract Sr. Security Engineer, LogRhythm Analysis/Forensics at a financial services firm with 1,001-5,000 employees
Vendor
It provides reports on the Cardholder Data Environment at 95% effectiveness, but to operate at the 99.99% level, it needs to have uninterrupted reporting host connections to the Log Mediator.

LogRhythm is a perfect example of "Garbage In, Garbage Out" in Information Security—LogRhythm reports on the Cardholder Data Environment (CDE) activity are only as reliable as the data coming in.

If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically. Even when reporting at 95% effectiveness, critical information regarding Threat Agent activity is probably still missing.

To operate at the 99.99% level, LogRhythm needs to have uninterrupted reporting host connections to LogRhythm’s Log Mediator(s) for optimal LogRhythm device functioning, complete and valid CDE host presence in LogRhythm’s log records, the minimization of false positives (Trash Traffic), the use of dedicated LogRhythm Appliances (not VMs), and flexibility in LogRhythm Change Management procedures that accommodate swiftly to LogRhythm-specific needs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

like :dude - Speciallyyyy LogRhythm Change Management

it_user320625 - PeerSpot reviewer
Senior Security Engineer at a tech vendor with 10,001+ employees
Real User
The Advanced Intelligence Engine alerts the SOC to potential security issues, though File Integrity Monitoring needs improvement.

What is most valuable?

Its Security Information and Event Management (SIEM) capabilities (security analysis, forensics) are the most valuable features for us.

How has it helped my organization?

The LogRhythm AIE (Advanced Intelligence Engine) is very good at alerting my SOC to events of interest and potential security issues without flooding my team with noise.

What needs improvement?

There is room for improvement in the area of File Integrity Monitoring.

For how long have I used the solution?

I've used it for 15 months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's excellent.

Technical Support:

It's excellent.

Which solution did I use previously and why did I switch?

I have used Tripwire, which was a poor SIEM solution.

What about the implementation team?

We used a vendor team. I recommend using LogRhythm's professional services for assistance with implementation.

What other advice do I have?

I highly recommend LogRythm for SIEM.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Information Security Engineer at a tech vendor with 501-1,000 employees
Vendor
Searches can be performed using any known value, IP address, hostname, username, or event, though report-building is limited by its use of Crystal Reports.

What is most valuable?

The Web UI is perhaps the most valuable feature in the solution.

How has it helped my organization?

LogRhythm allows our IT/IS teams to quickly identify issues across the enterprise. Searches can be performed using any known value, IP address, hostname, username, event. The results are then used to "open a case". The case is assigned to an analyst, who can add additional info during the research and remediation efforts.

What needs improvement?

Report-building is in Crystal Reports and has a limitation. A non-editable template must be created, then the report is created against the template. OFI is this. The template needs a preview option, as well as an edit option.

For how long have I used the solution?

8 months

What was my experience with deployment of the solution?

None that were not easily overcome.

What do I think about the stability of the solution?

None

What do I think about the scalability of the solution?

No, we right sized the deployment and also deployed as a high-availability environment.

How are customer service and technical support?

Customer Service:

I have been very pleased with customer service. I have only had to contact my CS a couple of times, and he has done a great job of followup to insure my company's needs were met in a timely fashion.

Technical Support:

Great support team. Average call pickup time has been less than 1/2 hour. I have had a couple of "scheduled" appointments get delayed when the agent's previous call ran over.

Which solution did I use previously and why did I switch?

We previously used Juniper STRM, rebranded QRadar. We faced 1. Log processing could not keep up with collection, so events were being dropped. 2. Support was poor. 3. When a ($45 at Bestbuy) disk drive went out, we were sent an entirely new system. 4. When faced with upgrading to support our log collection demands, the estimated cost was several times greater than the LR deployment.

How was the initial setup?

Depending on the size and complexity of the deployment, i recommend paying for the Professional Services team to assist. All work was done in a remote session.

I also recommend not attending the training sessions until a few weeks of bake-in have occurred. Too many topics were covered to fully absorb all the information that was disseminated.

What about the implementation team?

Our internal security team performed the majority of the installation, again working with the PS group at LogRhythm.

What was our ROI?

We immediately saw benefit on our first investigation.

What's my experience with pricing, setup cost, and licensing?

Depending on the size, number of logs, I recommend deploying VM (or physical) collectors, and have the logs forwarded to the appliance. We are collecting logs from 2500+ systems, and did not want to impact the appliance with collection, but rather, analyzing logs. This solution has worked very well so far.

Which other solutions did I evaluate?

We reviewed several solutions including Alien Vault (not large enough for our needs), Splunk (would need a full time programmer to write queries), QRADAR (since we already had a previous version. We did a month long POC on Correlog, attempted to POC EIQ Networks.

What other advice do I have?

We are very pleased with the LR solution and are looking forward to the upcoming update.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user317892 - PeerSpot reviewer
Senior Information Security Manager with 1,001-5,000 employees
Vendor
It's simplified and clarified complex volumes of information, but customizing features could be improved.

Valuable Features

  • Clarity of information
  • Ease of deployment

Improvements to My Organization

The ability to provide insights and simplification for complex volumes of information.

Room for Improvement

The ability to customize certain features of the product.

Use of Solution

I've used it for one year.

Stability Issues

I find that the system is stable and handling our traffic very well.

Customer Service and Technical Support

Customer Service:

The customer service teams is excellent and have they resolved anything we have thrown at them in a timely fashion.

Technical Support:

The technical support team is excellent and have they resolved anything we have thrown at them in a timely fashion.

ROI

We do not have one yet, but we definitely foresee a ROI.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user290340 - PeerSpot reviewer
Vice President at a financial services firm with 1,001-5,000 employees
Vendor
We're able to create customized monitoring reports that extract info from event logs.

Valuable Features:

  • Reporting - we need to do a lot of security monitoring
  • It doesn't have a lot of forensics, but we appreciate fact that it has the capability
  • The ability to collect a lot of information, as we have 200 users and a lot of log sources

Improvements to My Organization:

The fact we're able to create customized monitoring reports that extract info from event logs, helps us a lot. We used to have ad hoc reports created by IT department, which meant they could manipualte content. if they ever wanted to tamper with output. Now, there's no risk for us to worry about.

Room for Improvement:

Lots of concern these days regarding vulnerability, and being able to interface with other tuypes of applications when creating event log. We have lots of other applications to monitor. Logrhythm can extract that info, but some require converting before LogRythem. Windows logs don't need converting, but SQL, & XML do require conversion and monitoring.

Other Advice:

You should consult with LogRhythm experts because there are lots of features and customizations, and you need to figure out what's needed for your specific environment, for example, regulatory compliance issues. They do great job of making clear what's needed.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.