The product was easy to deploy and easy to learn how to use. The web console is the best I’ve seen when compared to other SIEMs.
Senior Information Systems Specialist at a manufacturing company with 1,001-5,000 employees
Our team has been able to correlate security events and react quicker to incidents, though retrieving logs that have been archived can be difficult and time consuming.
What is most valuable?
How has it helped my organization?
This product has made it easier for our team to correlate security events and react quicker to incidents.
What needs improvement?
Retrieving logs that have been archived can be a difficult and time consuming process. The module which performs this, called the Second Look Wizard is not very well integrated into the rest of the product. It would be nice if you had the ability to right click on a log and search the archives for more data like it (you can do this with non-archived logs) and then after restoring archived logs, easily pivot to an investigation for that data. Currently, those 3 steps all have to be run separately.
For how long have I used the solution?
I've used it for five months.
Buyer's Guide
LogRhythm SIEM
June 2025

Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What was my experience with deployment of the solution?
The deployment was very smooth.
What do I think about the stability of the solution?
There were occasional stability problems, but they were resolved by support in a timely fashion.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and support?
Customer Service:
Excellent, everyone I have worked with at LogRhythm has been courteous and helpful.
Technical Support:Technical support has been very good, and they will often go out of their way to help correct an issue, even if it is not a technical issue with the product.
Which solution did I use previously and why did I switch?
This is our first SIEM.
How was the initial setup?
The initial setup was done with the help of LogRhythm Professional Services and was fairly straightforward. Our version of the software is integrated into one hardware unit which made it easy to setup and understand.
What about the implementation team?
We implemented with LogRhythm Professional Services and the engineer I worked with was very thorough and knowledgable.
What's my experience with pricing, setup cost, and licensing?
Pricing was on the higher end when compared to other products we looked at. However, we felt the advantages with LogRhythm justified the price premium. Licensing is fair and straightforward. We evaluated SIEMs from AlienVault, Tripwire, and Solarwinds.
Which other solutions did I evaluate?
We evaluated SIEMs from AlienVault, Tripwire, and Solarwinds.
What other advice do I have?
If implementing a SIEM for the first time, it is very important to have members of the network and server teams involved from the beginning. Also, strong change management policies are necessary to keep the SIEM implemented properly.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
VP, Information Security Officer with 501-1,000 employees
Custom rules/alerts in LRM and AIE provide insight into network for internal users and InfoSec, although adding an entity could be much faster.
What is most valuable?
- Advanced Intelligence Engine (AIE) for threat intelligence, 9/10
- LRM for logging and compliance, 8/10
How has it helped my organization?
Custom rules/alerts in LRM and AIE provide insight into network for internal users as well as InfoSec. Proactive account lockout alerts for SecAdmin, alerts to DBAs on domain admin access to SQL servers, PCI and GLBA compliance alerts/reports for InfoSec and Audit.
What needs improvement?
Adding an entity (should be able to create a template and/or eliminate locations) could be much faster/streamlined. The wizard could be improved to specify OU/Groups to search for new entities.
For how long have I used the solution?
- LRM – four years
- AIE – three years
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There have been issues with the hardware which has resulted in the LRM going down a few times.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's the best there is.
Technical Support:It's the best there is.
Which solution did I use previously and why did I switch?
We had Tripwire, but we needed logging and SIEM, not just logging.
How was the initial setup?
It was straightforward as the training provided all the tools. Also, the UI has gotten better with time.
What about the implementation team?
We had a mix of an in-house team with one from LogRhythm.
What was our ROI?
Literally impossible to quantify. We haven’t had any events or deficiencies in audits, which is invaluable.
What's my experience with pricing, setup cost, and licensing?
Pricing (especially considering feature sets) is best in the market, though HA/DR is tough to justify for a SMB. Even with two outages due to hardware we haven’t invested in a backup.
Which other solutions did I evaluate?
- QRadar
- RSA
- Tripwire
What other advice do I have?
Implementation time, hygene/maintenance time, functionality, and cost make it the clear choice in a competitive market.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
LogRhythm SIEM
June 2025

Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Sr. Mgr of Network Operations at a comms service provider with 501-1,000 employees
It allows us to detect and remediate Advanced Persistent Threats, but the log management database needs to be more efficient.
Valuable Features
- Investigation
- Advanced Intelligence Engine
- Alarming and Response
Improvements to My Organization
We have made this the foundation of our security intelligence within our organization. It has allows us to detect and remediate Advanced Persistent Threats.
Room for Improvement
I would like to the log management database perform more efficiently.
Use of Solution
I've used it for five years.
Stability Issues
Some minor bugs with the mediator. Those have been fixed in patch releases a long time ago.
Customer Service and Technical Support
Customer Service:
9/10.
Technical Support:9/10.
Initial Setup
Setup was fairly straightforward. We were up and running with coverage of most log sources within two days.
Implementation Team
We implemented it in-house. Active Directory import makes initial configuration quick and easy.
Other Solutions Considered
We also evaluated Splunk, and we chose LogRhythm as the correlation rules performed it handled clients on DHCP better.
Other Advice
We recommend that people implementing it choose to log everything, including logs from desktops, laptops, servers, switches and routers.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Contract Sr. Security Engineer, LogRhythm Analysis/Forensics at a financial services firm with 1,001-5,000 employees
It provides reports on the Cardholder Data Environment at 95% effectiveness, but to operate at the 99.99% level, it needs to have uninterrupted reporting host connections to the Log Mediator.
LogRhythm is a perfect example of "Garbage In, Garbage Out" in Information Security—LogRhythm reports on the Cardholder Data Environment (CDE) activity are only as reliable as the data coming in.
If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically. Even when reporting at 95% effectiveness, critical information regarding Threat Agent activity is probably still missing.
To operate at the 99.99% level, LogRhythm needs to have uninterrupted reporting host connections to LogRhythm’s Log Mediator(s) for optimal LogRhythm device functioning, complete and valid CDE host presence in LogRhythm’s log records, the minimization of false positives (Trash Traffic), the use of dedicated LogRhythm Appliances (not VMs), and flexibility in LogRhythm Change Management procedures that accommodate swiftly to LogRhythm-specific needs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Engineer at a tech vendor with 10,001+ employees
The Advanced Intelligence Engine alerts the SOC to potential security issues, though File Integrity Monitoring needs improvement.
What is most valuable?
Its Security Information and Event Management (SIEM) capabilities (security analysis, forensics) are the most valuable features for us.
How has it helped my organization?
The LogRhythm AIE (Advanced Intelligence Engine) is very good at alerting my SOC to events of interest and potential security issues without flooding my team with noise.
What needs improvement?
There is room for improvement in the area of File Integrity Monitoring.
For how long have I used the solution?
I've used it for 15 months.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's excellent.
Technical Support:It's excellent.
Which solution did I use previously and why did I switch?
I have used Tripwire, which was a poor SIEM solution.
What about the implementation team?
We used a vendor team. I recommend using LogRhythm's professional services for assistance with implementation.
What other advice do I have?
I highly recommend LogRythm for SIEM.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a tech vendor with 501-1,000 employees
Searches can be performed using any known value, IP address, hostname, username, or event, though report-building is limited by its use of Crystal Reports.
What is most valuable?
The Web UI is perhaps the most valuable feature in the solution.
How has it helped my organization?
LogRhythm allows our IT/IS teams to quickly identify issues across the enterprise. Searches can be performed using any known value, IP address, hostname, username, event. The results are then used to "open a case". The case is assigned to an analyst, who can add additional info during the research and remediation efforts.
What needs improvement?
Report-building is in Crystal Reports and has a limitation. A non-editable template must be created, then the report is created against the template. OFI is this. The template needs a preview option, as well as an edit option.
For how long have I used the solution?
8 months
What was my experience with deployment of the solution?
None that were not easily overcome.
What do I think about the stability of the solution?
None
What do I think about the scalability of the solution?
No, we right sized the deployment and also deployed as a high-availability environment.
How are customer service and technical support?
Customer Service:
I have been very pleased with customer service. I have only had to contact my CS a couple of times, and he has done a great job of followup to insure my company's needs were met in a timely fashion.
Technical Support:Great support team. Average call pickup time has been less than 1/2 hour. I have had a couple of "scheduled" appointments get delayed when the agent's previous call ran over.
Which solution did I use previously and why did I switch?
We previously used Juniper STRM, rebranded QRadar. We faced 1. Log processing could not keep up with collection, so events were being dropped. 2. Support was poor. 3. When a ($45 at Bestbuy) disk drive went out, we were sent an entirely new system. 4. When faced with upgrading to support our log collection demands, the estimated cost was several times greater than the LR deployment.
How was the initial setup?
Depending on the size and complexity of the deployment, i recommend paying for the Professional Services team to assist. All work was done in a remote session.
I also recommend not attending the training sessions until a few weeks of bake-in have occurred. Too many topics were covered to fully absorb all the information that was disseminated.
What about the implementation team?
Our internal security team performed the majority of the installation, again working with the PS group at LogRhythm.
What was our ROI?
We immediately saw benefit on our first investigation.
What's my experience with pricing, setup cost, and licensing?
Depending on the size, number of logs, I recommend deploying VM (or physical) collectors, and have the logs forwarded to the appliance. We are collecting logs from 2500+ systems, and did not want to impact the appliance with collection, but rather, analyzing logs. This solution has worked very well so far.
Which other solutions did I evaluate?
We reviewed several solutions including Alien Vault (not large enough for our needs), Splunk (would need a full time programmer to write queries), QRADAR (since we already had a previous version. We did a month long POC on Correlog, attempted to POC EIQ Networks.
What other advice do I have?
We are very pleased with the LR solution and are looking forward to the upcoming update.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Security Manager with 1,001-5,000 employees
It's simplified and clarified complex volumes of information, but customizing features could be improved.
Valuable Features
- Clarity of information
- Ease of deployment
Improvements to My Organization
The ability to provide insights and simplification for complex volumes of information.
Room for Improvement
The ability to customize certain features of the product.
Use of Solution
I've used it for one year.
Stability Issues
I find that the system is stable and handling our traffic very well.
Customer Service and Technical Support
Customer Service:
The customer service teams is excellent and have they resolved anything we have thrown at them in a timely fashion.
Technical Support:The technical support team is excellent and have they resolved anything we have thrown at them in a timely fashion.
ROI
We do not have one yet, but we definitely foresee a ROI.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Vice President at a financial services firm with 1,001-5,000 employees
We're able to create customized monitoring reports that extract info from event logs.
Valuable Features:
- Reporting - we need to do a lot of security monitoring
- It doesn't have a lot of forensics, but we appreciate fact that it has the capability
- The ability to collect a lot of information, as we have 200 users and a lot of log sources
Improvements to My Organization:
The fact we're able to create customized monitoring reports that extract info from event logs, helps us a lot. We used to have ad hoc reports created by IT department, which meant they could manipualte content. if they ever wanted to tamper with output. Now, there's no risk for us to worry about.
Room for Improvement:
Lots of concern these days regarding vulnerability, and being able to interface with other tuypes of applications when creating event log. We have lots of other applications to monitor. Logrhythm can extract that info, but some require converting before LogRythem. Windows logs don't need converting, but SQL, & XML do require conversion and monitoring.
Other Advice:
You should consult with LogRhythm experts because there are lots of features and customizations, and you need to figure out what's needed for your specific environment, for example, regulatory compliance issues. They do great job of making clear what's needed.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Dynatrace
Datadog
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Grafana Loki
Graylog
Security Onion
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
syslog-ng
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- Does LogRhythm NextGen SIEM offer good security?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
like :dude - Speciallyyyy LogRhythm Change Management