My customers use the solution for user behavior analytics and as an anti-malware and anti-threat kind of tool. My customers are in finance-related areas. I deal with some gambling companies, and in my country, it is categorized under the finance sector.
Information Technology Security Engineer at a tech consulting company with 1-10 employees
Offers good visibility of events and is easy to use
Pros and Cons
- "In general, the visibility of events and advanced analysis of events are good."
- "The product's initial setup phase is pretty complex."
What is our primary use case?
What is most valuable?
The solution's features include good visibility of events, faster response to threats, and advanced ability to analyze events and data. In general, the visibility of events and advanced analysis of events are good.
What needs improvement?
The tool needs to improve the implementation part and have a virtual list of files for a virtual appliance or something like that because it is a very complicated area when it comes to implementation. There are a lot of pieces that need to be installed and prepared, and, of course, there is a need for virtual resources. The tool must offer better virtual resources and prepare some virtual appliances with some ISO or VMDK files. I don't care, but the solution must do something to improve the product. There are too many things that are complicated during the implementation phase.
For how long have I used the solution?
I have been using LogRhythm SIEM for a year. I use the solution as a partner.
Buyer's Guide
LogRhythm SIEM
March 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
It is a highly scalable solution. Scalability-wise, I rate the solution a ten out of ten.
From LogRhythm's perspective, my company deals with small to medium businesses.
How are customer service and support?
The solution technical support team provides quick answers to any request. The team's knowledge and way of resolving issues are also fast. We haven't had any problems reaching out and getting the support we need for the tool. I rate the technical support a ten out of ten.
How was the initial setup?
The product's initial setup phase is pretty complex. The tool offers good guidance, and everything else is clear, but there are a lot of steps involved in the implementation. From the client's end, there is a need to include a lot of people, like system admin, DB admin, and network admin. Sometimes, I think the tool needs to improve something in the area of the setup phase so that there aren't difficulties during the implementation process.
If ten means easy setup and one means difficult, I rate the product's installation phase a four out of ten.
The solution is deployed on an on-premises model.
If everything is prepared already, the solution can be deployed in one or two days. In the end, there are a lot of things that you need to prepare before starting the tool's use, so it takes two to five days for the initial deployment, but after that the installation processes take just two days.
What's my experience with pricing, setup cost, and licensing?
For my customer, I think the tool is reasonably priced. I think the tool is reasonably priced. There is a need to pay per year towards the licensing costs of the tool. From what I heard, the tool has a very reasonable price, and users pay on a yearly basis for its licensing charges.
What other advice do I have?
Speaking about how LogRhythm SIEM influences operational costs, or if it does have any security efficiency, I would say that I don't work with the tool every day to know what the operational cost benefit is. In any case, with fewer people, the tool has better visibility. There is a need for three or four people in a team for SIEM. The tool ensures better efficiency of the team by improving costs, but I am not very sure how to explain it as the tool has centralized events as it is spread out geographically with a lot of branches. We get a better understanding of the networks in different countries with the centralization part, improving the efficiency of the SIEM team.
With LogRhythm SIEM, there is a need to deal with a lot of customized services. The tool spends a lot of time with professional services for customization. The good part is that the support team finishes their job very quickly and offers very good responses when it comes to the area of customization. There was a little disappointment since the tool did not have some of the parsers for some systems in the environments, like IBM, which was a surprise. In any case, support did the job, as there were tons of customizations needed. We were able to deal with the customization area and resolve the issue around it, making it a very customizable tool. It is a very flexible tool. I spend a lot of time with the support team doing the customizations. Customizations take a lot of time, but they are still a plus.
I have not noticed any AI elements in LogRhythm SIEM.
I recommend the tool to others.
It is a perfect search engine, and every report is analyzed really quickly and in a straightforward manner. The tool has an easy GUI, and it is the perfect choice for security analysts. The tool has consoles, including an administrative console and a web console. For some people, that can be a problem. I think it is really good when you have administrative guys who deal only with the solution and analysts who deal only with the analyzed part without some preparation for the core configuration. Everyone can deal with the day job. For me, the tool is advanced, but maybe for others, it can be an issue. In any case, it is really visible to others for documentation. The tool is scalable and really operational. The tool is easy to use and for sizing. In the end, it is a good tool. In the Serbian market, most of the tools demanded are on-premises. When it comes to the on-premises solution, I think LogRhythm is one of the best tools. We are a little different than the other parts of the world. Everyone wants to go to the cloud, but here, everything wants to be kept on an on-premises model. The market in Serbia is very strange because we aren't a part of the European Union, and so, with regard to compliance, we always have some problems. The companies in Serbia like to have on-premises solutions because most financial institutions, banks, or government institutions have data centers, so they won't go to the cloud. In Serbia, we don't like to deal with cloud solutions, especially when the data needs to be consumed somewhere in the cloud because the biggest problem is the cost of cloud solutions for SIEM tools. Most of the applications and everything is also hosted on-premises in Serbia. Normally, the SIEM tools are used in an on-premises model.
I rate the tool a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Associate Team Lead - IT Service Desk at a tech services company with 51-200 employees
Offers good features for internal security and deals with phishing email attacks
Pros and Cons
- "We raise a ticket to LogRhythm, and they will give us their support."
- "The pricing is the only problem."
What is our primary use case?
We operate a Security Operations Center. We have to provide internal security to our client base and intel. That's why we use it.
How has it helped my organization?
We mostly deal with phishing email attacks from our Intel-related clients. So, most of the cases are related to using the SIEM. And we receive the logs in our database to do all those things.
What is most valuable?
In Sri Lanka, we have a local SIEM supplier. And in addition to that, if we need some more calibration or help with incidents, we raise a ticket to LogRhythm, and they will give us their support.
It is good for us.
What needs improvement?
The price could be improved.
In future releases, I suppose if they can give us some training related to LogRhythm, that would be very beneficial. I suppose the training is not enough.
And the product might be a little bit complex for non-experienced people
For how long have I used the solution?
I have been using it for two and a half years.
How are customer service and support?
It is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Our Security Operations Center (SOC) and our SIEM use LogRhythm. We have to renew our license and are looking for another SIEM. We are doing a comparison with Elastic.
How was the initial setup?
The initial setup is complex. There's a complexity, actually. We have received some training in the last two and a half years. We got training from our local supplier. Actually, we haven't received any training before from [LogRhythm], so I suppose they should provide training for that.
What's my experience with pricing, setup cost, and licensing?
I suppose there's a very high cost in that. So that's the main reason we are trying another solution.
What other advice do I have?
I would recommend it to others. Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
LogRhythm SIEM
March 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
CEO/Consultant at CIL
Scalable product with good technical support services
Pros and Cons
- "The initial setup process is very user-friendly."
- "The product's stability needs improvement."
What is our primary use case?
We use the product for server and event management for the financial sector.
What needs improvement?
The product's stability needs improvement.
For how long have I used the solution?
We have been using LogRhythm SIEM since last year.
What do I think about the stability of the solution?
We encountered some system downtime issues.
What do I think about the scalability of the solution?
The product is scalable. Its scalability is based on specific licensing plans. It is suitable for enterprises. It has a lot of advantageous features for SIEM.
How are customer service and support?
The technical support services are good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used SolarWinds before. We switched to LogRhythm because of specific requirements regarding log information and SOC activities, particularly for government contracts. In comparison to products like IBM and HP, LogRhythm is a cost-effective alternative.
How was the initial setup?
The initial setup process is very user-friendly. It takes 15 days to complete.
What was our ROI?
Compared to other products, LogRhythm SIEM generates a return on investment in terms of ease of use.
What's my experience with pricing, setup cost, and licensing?
The product is inexpensive than other tools like IBM, QRadar, etc.
Which other solutions did I evaluate?
We evaluated six products as per our client’s requirements. They decided to go for LogRhythm, which solves business purposes and has economical pricing.
What other advice do I have?
I rate LogRhythm SIEM an eight out of ten. In comparison, IBM has more features that are essential at the moment. However, it costs three times more than LogRhythm SIEM.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partners
Co-Founder at First Defense WLL
Intuitive GUI, easy to set up, and stable
Pros and Cons
- "The GUI is very intuitive and the solution has good integration."
- "The built-in functionality of the solution for NDR, SOAR, SIEM, and EDS has room for improvement."
What is our primary use case?
There are multiple use cases for the solution, such as long log formatting, log consolidation, data isolation, malware detection, identifying suspicious attacks, and locating ISU records across the network.
What is most valuable?
The GUI is very intuitive and the solution has good integration.
What needs improvement?
The built-in functionality of the solution for NDR, SOAR, SIEM, and EDS has room for improvement.
The price of the solution has room for improvement.
For how long have I used the solution?
I have been using the solution for ten years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I give the scalability an eight out of ten.
How are customer service and support?
The technical support is good.
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
I give the price a six out of ten.
What other advice do I have?
I give the solution an eight out of ten.
The solution can meet the most mature customer's requirements.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
SOC Manager at Infratech Co
It's easy to use and has improved a lot, but the web and on-prem console should be unified
Pros and Cons
- "I like LogRhythm's ease of use. The solution has improved compared to previous versions. It had many issues before, like integration, the console, creating reports, false positives, etc. The AI engine has made it stronger in the latest version."
- "The web and on-premise console interface should be the same instead of having a separate engine for each."
What is our primary use case?
We are consultants providing governance solutions for the banking sector. We have a lot of use cases. We have more than 400 use cases for the client side.
What is most valuable?
Its ease of use is valuable. It has improved a lot from the previous versions. It had a lot of issues before, but now, it's way better in terms of integration, the console part, report creation for use cases, false positive numbers, and so on. Its AI engine is a lot more advanced in the latest version.
What needs improvement?
The web and on-premise console interface should be the same instead of having a separate engine for each.
I hope that they remove the console and have only one GUI. There should be one engine for both the web and the console. They shouldn't have two different engines for each one of them.
There should be easier deployment status, and like Splunk, there should be a more professional way to write the search. There shouldn't be only a drop-down menu. It'll be a good thing to add.
For how long have I used the solution?
I have used LogRhythm for about three years now.
What do I think about the stability of the solution?
LogRhythm SIEM is stable.
What do I think about the scalability of the solution?
LogRhythm SIEM is highly scalable. We have more than nine users working with this solution.
How are customer service and support?
The technical support depends on the technician you get. Some are good, but some aren't. We had multiple sessions with one person for over a year with no results. Other engineers are excellent.
How was the initial setup?
Setting up LogRhythm is complex. It took our team more than a month to deploy. We have a large team in my company because we are working with dozens of clients. Our BS team is almost 15 people.
What about the implementation team?
Its implementation is handled by a different team. We have a very big team in our company because we are working with a lot of clients. Our implementation team has almost 15 people.
What's my experience with pricing, setup cost, and licensing?
There don't seem to be any costs in addition to standard licensing.
What other advice do I have?
I'd recommend LogRhythm SIEM to others. I'd rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Engineer - Network and Security at Connex Information Technologies
Is very easy to create correlation rules and has good performance
Pros and Cons
- "It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable."
- "It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable."
- "LogRhythm NextGen SIEM is currently based only on the Windows platform. This means that some of our customers have to purchase a Windows license elsewhere. If LogRhythm can move to a Linux platform or a proprietary platform, it would be very helpful."
- "LogRhythm NextGen SIEM is currently based only on the Windows platform. This means that some of our customers have to purchase a Windows license elsewhere."
What is our primary use case?
Mostly, the use cases involve detecting lateral movements, malware infections, and insider threats.
We serve small, medium, and large companies, mostly in the finance sector, here in Sri Lanka.
What is most valuable?
It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable.
What needs improvement?
LogRhythm NextGen SIEM is currently based only on the Windows platform. This means that some of our customers have to purchase a Windows license elsewhere. If LogRhythm can move to a Linux platform or a proprietary platform, it would be very helpful.
For how long have I used the solution?
I've been working with LogRhythm NextGen SIEM for around five years now.
We have deployed both to the cloud and on-premies, but we've mostly deployed on-premises.
What do I think about the stability of the solution?
It's very stable, unless something happens on the Windows storage side.
The performance is good, and we don't often get any complaints from our customers.
What do I think about the scalability of the solution?
LogRhythm NextGen SIEM is horizontally and vertically scalable, so scalability is not an issue.
We have six people working with LogRhythm directly in our organization.
How are customer service and support?
The technical support has been very good. They are very supportive, and I'd give them a rating of ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
When compared to other SIEM solutions, LogRhythm is very easy to use, and I like the correlation rule building.
How was the initial setup?
The initial setup is a bit complex because we need to be certified first. Otherwise, we have to get their PS for the deployment process. Even if you're certified, they shadow us. There are some processes for which we need to obtain their advice.
The initial setup and configuration can take around half a day. That is, a single box deployment can take 6 hours.
If I were to rate my deployment experience, I would give it a four out of five.
What's my experience with pricing, setup cost, and licensing?
LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM.
What other advice do I have?
When you implement, you need to know LogRhythm's architecture because it is quite difficult and different from that of other SIEM solutions. So, you need to know the architecture, how the processes work, and how the logs are processed.
Overall, I would rate LogRhythm at eight on a scale from one to ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
CEO/Consultant at CIL
User-friendly with an excellent security operation center
Pros and Cons
- "The security operation center is excellent."
- "The security operation center is excellent, and we can pick logs from any system, not only the IPS or firewall."
- "The customer support system is time-consuming."
- "The customer support system is time-consuming and needs to be improved because it is not very good."
What is our primary use case?
LogRhythm NextGen SIEM is great. We use it for log management for security purposes.
How has it helped my organization?
The security operation center is excellent, and we can pick logs from any system, not only the IPS or firewall. In addition, it has the capacity to accept logs and provide smart dashboards and analysis.
What is most valuable?
The most valuable feature is the SOC Security Operations Center feature. This solution has two types of systems, virtualization and the appliance. The appliance is ready and configured, so we use the IP addresses and trigger the endpoint. It's very user-friendly, and whenever anyone deploys a virtualization system, they can experience it.
What needs improvement?
The customer support system is time-consuming and needs to be improved because it is not very good. For other solutions, you can deliver whenever you have a customer problem. All you need to do is open a ticket, log into the system, and the issue is resolved. However, for LogRhytm, we have to flag the problem and then send the log, and we never know if we will receive a response in one hour or one week.
In addition, LogRhythm NextGen SIEM has one of the best analysis features, but it can still be improved. However, I believe they plan to make improvements since they're only selling the product for two systems currently.
For how long have I used the solution?
We have been using this solution for three years.
What do I think about the stability of the solution?
It is a very stable solution.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
I rate the customer support a four out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup was very easy. I rate the setup a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is very good, and it is very cheap compared to other solutions. If we compare it to SolarWind, SolarWind is not as advanced as LogRhythm NextGen SIEM.
I rate the price a nine out of ten. We always consider the features and quality before the price, but the cost is still very good. We get about 98% of the features we want.
What other advice do I have?
I rate LogRhythm NextGen SIEM a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
FSE at a computer software company with 1,001-5,000 employees
Cost-effective, good support, and can be effectively tuned to get meaningful information
Pros and Cons
- "As a SIEM, probably the best feature is that it can be tuned effectively. There are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed."
- "As a SIEM, probably the best feature is that it can be tuned effectively, as there are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed."
- "It should be improved for automated setup and auto-configuration. There should be ease of integration and ease of setup."
- "It should be improved for automated setup and auto-configuration. There should be ease of integration and ease of setup."
What is our primary use case?
Its primary use cases are log aggregation, security information, and event management correlation.
All of our clients use different versions across the board. In terms of deployment, some use it on-prem, and some use it in the cloud. It is all over the place.
What is most valuable?
As a SIEM, probably the best feature is that it can be tuned effectively. There are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed. It has the capability to do that, but it probably takes a little more time to do that.
What needs improvement?
It should be improved for automated setup and auto-configuration. There should be ease of integration and ease of setup.
For how long have I used the solution?
I have probably been using it since it has been around.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable.
How are customer service and support?
They provide very good support.
How was the initial setup?
It takes a little more time to get operationalized, but I haven't personally set it up. I'm only taking feedback from my customers when they say they've gone through the steps and the process of setting it up.
What's my experience with pricing, setup cost, and licensing?
It is a very cost-effective solution.
What other advice do I have?
Don't do it without managed services, but I would say that for any SIEM. In SIEM technology, the setup and maintenance side is different from the monitoring and alerting side. I recommend all of our customers to always go with a managed service provider to take care of the monitoring and alerting side, or at the very least, to fill in for off hours because you only have so many people on your staff. Small and medium-sized customers are our bread and butter, and most of our customers don't have the staffing for this.
If you don't have the expertise to set it up, manage it, or the time to learn it, a managed service can help you get it set up. For most SIEMs, LogRhythm included, for the first six months, you probably need one to one half of an FTE for doing the setup, getting it operationalized, and doing all the tuning. You're going to need one-quarter of an FTE for ongoing operations, maintenance, and support. That doesn't include monitoring of alerts and the response to the alerts. If you've got it well tuned, you don't need a lot of staff to do the monitoring and the alerting during the regular daytime hours. That's where having a managed service provider during off hours and weekends is handy. It is beneficial to have a managed service to do the operational work for maintenance.
It is good, but there is room for improvement. There are plenty of solutions on the market that do a lot of what it does. It is not a huge product differentiator or market differentiator.
I would rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Popular Comparisons
CrowdStrike Falcon
Datadog
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Grafana Loki
Security Onion
Graylog Enterprise
Rapid7 InsightIDR
Elastic Stack
Amazon OpenSearch Service
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- Does LogRhythm NextGen SIEM offer good security?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?



















