The advanced intelligence engine -- in fact, the whole suit -- is very powerful. It depends how you use it. Security management is what it's best at. As far I’m concerned, it’s one of the best.
IT Security Specialist at a manufacturing company with 1,001-5,000 employees
Security management is what it's best at, but it's generally for medium-sized companies.
Pros and Cons
- "The advanced intelligence engine, in fact the whole suite, is very powerful and as far as I’m concerned, it’s one of the best for security management."
- "This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them."
What is most valuable?
What needs improvement?
This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them. The solution is not robust. It depends on the size of the companies and the size of the firewalls you have which will determine if it will work for you. Thus product is really good and easy to use for medium sized companies.
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
Initially we had a lot of issues. Today it has improved dramatically, and it has no issues in deployment.
Buyer's Guide
LogRhythm SIEM
March 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is very stable, but we have to work with it and identify which logs we need. If we don’t, it doesn't handle the traffic well.
Every tool is different, and you just have to work with it.
How are customer service and support?
It’s one of the best customer services you could find. Everyone is very knowledgeable and helpful. You aren’t waiting around for tickets to be resolved. If they can’t resolve it, they escalate and resolve quickly.
What was our ROI?
Absolutely we have made a ROI. It resolves a lot of issues. It helps a lot of our infrastructure and everyone is benefiting. It’s absolutely worth the money spent.
What's my experience with pricing, setup cost, and licensing?
They are very transparent about the licensing. They are upfront. They tell you what can handle what. They are honest people.
What other advice do I have?
I have been invited to user group meetings and we have had good conversations. They have been very helpful and they understand my needs. They listen to our input and really take it seriously. They really work with us on different issues.
Everything is fantastic.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Systems Administrator at a financial services firm with 501-1,000 employees
We selected it based on the ability to comply with regulations and its advanced features, but support needs to be improved.
Pros and Cons
- "It’s a very powerful and robust device and application."
- "I don’t have a lot of confidence in their support. The support is not first class."
Valuable Features
The log aggregation is what we use it for.
We don’t have a lot of the reporting configured or the advanced analytics. When the time is right, we will we will make the most of these features.
Improvements to My Organization
We need to improve our internal training and use of it. We use it, but we don’t use it to its potential. It’s a very powerful and robust device and application. We don’t use it how we could.
Room for Improvement
I don’t have a lot of confidence in their support. The support is not first class. I am still working with them with follow ups with the numerous issues we have had. The appliance itself seems to be doing what it’s supposed to, but the support is lacking.
Use of Solution
I've used it for six years.
Deployment Issues
We went through research of multiple products that were similar in nature and selected LogRhythm based on the ability to comply with regulations and the advanced features that it offered. It’s a really deep product and you can do a lot with it, but it just hasn't been realized.
Stability Issues
It handles what we throw at it.
Customer Service and Technical Support
I have mixed feelings. We have had some issues with their internal support.
We lost our ability to access the support portal, and it took them around three weeks to resolve it. We had a new upgraded appliance implemented and professional services set it up. They failed to take all of the alerts and bring it to the new appliance.
Implementation Team
We implemented it in-house.
Pricing, Setup Cost and Licensing
The licensing has improved. It has gone down because it is no longer individual monitoring licensing, whereas before it was licensed per collection manager. They have given us decent pricing, they gave us credit for the old appliance.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
LogRhythm SIEM
March 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Security Analyst at a retailer with 1,001-5,000 employees
We are able to manage the items we have coming in with one product; however, if the client doesn't have a customer in their system, they can’t use it.
Pros and Cons
- "The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot."
- "The main area of improvement is that the client must be installed on the computer for all of the functions to work."
What is most valuable?
I find that the ease of installation is a valuable part of the solution.
How has it helped my organization?
The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot.
What needs improvement?
The main area of improvement is that the client must be installed on the computer for all of the functions to work. So if the client doesn't have a customer in their system, they can’t use it.
For how long have I used the solution?
I have been directly responsible for this install around two years. I worked with LogRhythm at another company for around three years.
What was my experience with deployment of the solution?
We didn’t encounter any issues that were not fixable.
What do I think about the stability of the solution?
I can’t remember the last time it was down. It’s very stable.
What do I think about the scalability of the solution?
The way it’s set up with agents, we can scale very well and if we need to we can just add more hardware to the system. The only limit is the hardware. We have been happy with it.
How are customer service and technical support?
Very knowledgeable, though I wouldn’t say proactive. When you speak with technical support you don’t actual speak with someone: you leave a message, which I do not like, although they respond pretty quickly.
Which solution did I use previously and why did I switch?
The scalability was the main reason for switching. You never know how much you may need and the ability to quickly adapt is great.
The ability to add something quickly is very important. It's more complete than a lot of products, such as Splunk, but you have to put in a lot of work.
With LogRhythm, security feeds and security alerts are just built in.
What about the implementation team?
We did migrate recently and had help from LogRhythm.
What was our ROI?
I’d say we have an ROI. It helps us identity problems before they become issues.
What's my experience with pricing, setup cost, and licensing?
Always plan for more logs than you think you have. Once you start collecting you will realize that you need more than you thought.
What other advice do I have?
My relationship has been very good. When we updated our software we set up weekly meetings which really helped us with reporting. We don’t directly get in touch with support but when we do they solve our problems.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Manager, Distributed Systems at a insurance company with 501-1,000 employees
It's reduced the time and effort necessary to manage and review logs and produce reports for regulatory compliance, though their professional services hourly rate is above average.
Pros and Cons
- "The vendor team was one of the best we have ever worked with and they were able to work through issues not covered in their implementation manuals quickly and without further support."
What is most valuable?
- SIEM
- File Integrity Monitoring
- Danned compliance reports (PCI, GLBA, HIPAA).
How has it helped my organization?
The solution has significantly reduced the time and effort necessary to manage and review logs and produce reports for regulatory compliance.
What needs improvement?
No current suggestions.
For how long have I used the solution?
I've used it for six years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
8/10
Technical Support:10/10
Which solution did I use previously and why did I switch?
No previous solution was in place.
How was the initial setup?
Our entire implementation was completed in one day.
What about the implementation team?
The vendor team was one of the best we have ever worked with. They were able to work through issues not covered in their implementation manuals quickly, and without further support.
What was our ROI?
No ROI. The solution is in place to meet PCI compliance and improve our overall security posture.
What's my experience with pricing, setup cost, and licensing?
While LogRhythm's professional services are one of the best we have ever worked with, their hourly rate is generally quoted at a much higher rate than the industry standard. Additionally, the hours necessary for an engagement are also regularly over estimated.
Which other solutions did I evaluate?
Several other solutions were considered including Q1 Labs (now IBM), EMC, and HP.
What other advice do I have?
There were two primary reasons we selected LogRhythm. First was the ease of implementation, which was extremely simple and straight forward. Second, was the integration of file integrity monitoring. LogRhythm at the time, and I believe still today, was the only vendor that provided a solution that included integrated SIEM and FIM.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Information Systems Specialist at a manufacturing company with 1,001-5,000 employees
Our team has been able to correlate security events and react quicker to incidents, though retrieving logs that have been archived can be difficult and time consuming.
Pros and Cons
- "The product was easy to deploy and easy to learn how to use, and the web console is the best I have seen when compared to other SIEMs."
- "Retrieving logs that have been archived can be a difficult and time consuming process."
What is most valuable?
The product was easy to deploy and easy to learn how to use. The web console is the best I’ve seen when compared to other SIEMs.
How has it helped my organization?
This product has made it easier for our team to correlate security events and react quicker to incidents.
What needs improvement?
Retrieving logs that have been archived can be a difficult and time consuming process. The module which performs this, called the Second Look Wizard is not very well integrated into the rest of the product. It would be nice if you had the ability to right click on a log and search the archives for more data like it (you can do this with non-archived logs) and then after restoring archived logs, easily pivot to an investigation for that data. Currently, those 3 steps all have to be run separately.
For how long have I used the solution?
I've used it for five months.
What was my experience with deployment of the solution?
The deployment was very smooth.
What do I think about the stability of the solution?
There were occasional stability problems, but they were resolved by support in a timely fashion.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
Excellent, everyone I have worked with at LogRhythm has been courteous and helpful.
Technical Support:Technical support has been very good, and they will often go out of their way to help correct an issue, even if it is not a technical issue with the product.
Which solution did I use previously and why did I switch?
This is our first SIEM.
How was the initial setup?
The initial setup was done with the help of LogRhythm Professional Services and was fairly straightforward. Our version of the software is integrated into one hardware unit which made it easy to setup and understand.
What about the implementation team?
We implemented with LogRhythm Professional Services and the engineer I worked with was very thorough and knowledgable.
What's my experience with pricing, setup cost, and licensing?
Pricing was on the higher end when compared to other products we looked at. However, we felt the advantages with LogRhythm justified the price premium. Licensing is fair and straightforward. We evaluated SIEMs from AlienVault, Tripwire, and Solarwinds.
Which other solutions did I evaluate?
We evaluated SIEMs from AlienVault, Tripwire, and Solarwinds.
What other advice do I have?
If implementing a SIEM for the first time, it is very important to have members of the network and server teams involved from the beginning. Also, strong change management policies are necessary to keep the SIEM implemented properly.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
VP, Information Security Officer with 501-1,000 employees
Custom rules/alerts in LRM and AIE provide insight into network for internal users and InfoSec, although adding an entity could be much faster.
Pros and Cons
- "Customer Service: It's the best there is. Technical Support: It's the best there is."
- "There have been issues with the hardware which has resulted in the LRM going down a few times."
What is most valuable?
- Advanced Intelligence Engine (AIE) for threat intelligence, 9/10
- LRM for logging and compliance, 8/10
How has it helped my organization?
Custom rules/alerts in LRM and AIE provide insight into network for internal users as well as InfoSec. Proactive account lockout alerts for SecAdmin, alerts to DBAs on domain admin access to SQL servers, PCI and GLBA compliance alerts/reports for InfoSec and Audit.
What needs improvement?
Adding an entity (should be able to create a template and/or eliminate locations) could be much faster/streamlined. The wizard could be improved to specify OU/Groups to search for new entities.
For how long have I used the solution?
- LRM – four years
- AIE – three years
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There have been issues with the hardware which has resulted in the LRM going down a few times.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's the best there is.
Technical Support:It's the best there is.
Which solution did I use previously and why did I switch?
We had Tripwire, but we needed logging and SIEM, not just logging.
How was the initial setup?
It was straightforward as the training provided all the tools. Also, the UI has gotten better with time.
What about the implementation team?
We had a mix of an in-house team with one from LogRhythm.
What was our ROI?
Literally impossible to quantify. We haven’t had any events or deficiencies in audits, which is invaluable.
What's my experience with pricing, setup cost, and licensing?
Pricing (especially considering feature sets) is best in the market, though HA/DR is tough to justify for a SMB. Even with two outages due to hardware we haven’t invested in a backup.
Which other solutions did I evaluate?
- QRadar
- RSA
- Tripwire
What other advice do I have?
Implementation time, hygene/maintenance time, functionality, and cost make it the clear choice in a competitive market.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Sr. Mgr of Network Operations at a comms service provider with 501-1,000 employees
It allows us to detect and remediate Advanced Persistent Threats, but the log management database needs to be more efficient.
Pros and Cons
- "We have made this the foundation of our security intelligence within our organization, and it has allowed us to detect and remediate Advanced Persistent Threats."
- "I would like the log management database to perform more efficiently."
Valuable Features
- Investigation
- Advanced Intelligence Engine
- Alarming and Response
Improvements to My Organization
We have made this the foundation of our security intelligence within our organization. It has allows us to detect and remediate Advanced Persistent Threats.
Room for Improvement
I would like to the log management database perform more efficiently.
Use of Solution
I've used it for five years.
Stability Issues
Some minor bugs with the mediator. Those have been fixed in patch releases a long time ago.
Customer Service and Technical Support
Customer Service:
9/10.
Technical Support:9/10.
Initial Setup
Setup was fairly straightforward. We were up and running with coverage of most log sources within two days.
Implementation Team
We implemented it in-house. Active Directory import makes initial configuration quick and easy.
Other Solutions Considered
We also evaluated Splunk, and we chose LogRhythm as the correlation rules performed it handled clients on DHCP better.
Other Advice
We recommend that people implementing it choose to log everything, including logs from desktops, laptops, servers, switches and routers.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Contract Sr. Security Engineer, LogRhythm Analysis/Forensics at a financial services firm with 1,001-5,000 employees
It provides reports on the Cardholder Data Environment at 95% effectiveness, but to operate at the 99.99% level, it needs to have uninterrupted reporting host connections to the Log Mediator.
LogRhythm is a perfect example of "Garbage In, Garbage Out" in Information Security—LogRhythm reports on the Cardholder Data Environment (CDE) activity are only as reliable as the data coming in.
If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically. Even when reporting at 95% effectiveness, critical information regarding Threat Agent activity is probably still missing.
To operate at the 99.99% level, LogRhythm needs to have uninterrupted reporting host connections to LogRhythm’s Log Mediator(s) for optimal LogRhythm device functioning, complete and valid CDE host presence in LogRhythm’s log records, the minimization of false positives (Trash Traffic), the use of dedicated LogRhythm Appliances (not VMs), and flexibility in LogRhythm Change Management procedures that accommodate swiftly to LogRhythm-specific needs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Popular Comparisons
CrowdStrike Falcon
Datadog
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Grafana Loki
Security Onion
Graylog Enterprise
Rapid7 InsightIDR
Elastic Stack
Amazon OpenSearch Service
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- Does LogRhythm NextGen SIEM offer good security?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
















like :dude - Speciallyyyy LogRhythm Change Management