Try our new research platform with insights from 80,000+ expert users

LogRhythm SIEM vs ZeroFOX comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
172
Ranking in other categories
Log Management (10th), Security Information and Event Management (SIEM) (7th)
ZeroFOX
Average Rating
8.0
Reviews Sentiment
8.2
Number of Reviews
2
Ranking in other categories
Threat Intelligence Platforms (9th), Digital Risk Protection (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. LogRhythm SIEM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 3.6%, down 4.9% compared to last year.
ZeroFOX, on the other hand, focuses on Digital Risk Protection, holds 17.9% mindshare, down 23.4% since last year.
Security Information and Event Management (SIEM)
Digital Risk Protection
 

Featured Reviews

Wail Khachfa - PeerSpot reviewer
Easy configuration and great user behaviour analysis and automation
The major feature of this solution is its easy configuration which helps different team members to work on it effectively. This kind of feature is not available in other solutions that need a special team dedicated to configure and extract reports. Another feature that I really admire is the significant improvement in the compliance in the auditing process by the solution. Our organisation-specific complaints require where the data needs to be forwarded, stored and searchable for a certain time period. This solution categorizes different types of data: cold, warm, and hot data. These features allow faster and easier extraction of any data even if the event was occurring several years ago. I also like other features, especially user behaviour analysis and automation. It studies the user behavior and if there is unusual traffic is recorded from a user, the solution flags it very effectively.
reviewer2384535 - PeerSpot reviewer
Provides information on leaks in the dark web, the deep web, and credit cards
ZeroFOX is deployed on the cloud in our organization. Before using ZeroFOX, users should also get demo sessions from other vendors. Then, you will get a better picture of ZeroFOX and how it works. ZeroFOX is a very good tool that will provide value if you can afford it. One of the key advantages of ZeroFOX is that it has a team where everyone is skilled in programming and scripting knowledge. If my team has some task, we don't have to go through the engineering. ZeroFOX is very easy for a beginner to learn. I would recommend ZeroFOX to other users. Overall, I rate the solution eight and a half out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The user interface is pretty good compared to other SIEM tools."
"We have to be able to show the evidence, and LogRhythm does a great job of putting it forward and making it easy to create reports with nice looking dashboards, which show off what we are doing as a security program."
"As a healthcare company, what we use it for is compliance, then to protect our data from exaltation."
"The AI Engine can take an event and correlate it into something else giving us meaningful context regarding what is going on. We integrated it in with our ticketing system, so if an alarm fires, it raises a ticket in our system."
"Currently, we are in the implementation phase. LogRhythm is better than QRadar from the point of view of collecting Windows events. It has a much higher view. You can enable monitoring by default."
"It supports most standard log sources."
"The daily alerts allow me to quickly find security and operations issues which need to be addressed."
"The ability for me to go into the Web UI, and just learn what's going on in my environment."
"The best thing about the tool is that its backend team is pretty good and has a strong engineering team."
"ZeroFOX has no language limitations. It can detect many languages."
 

Cons

"One thing we have mentioned to them before is that we'd like to be able to do searches, or drill-downs, directly from an alarm. When you click it and the Inspector tab slides out, that might be a good place to be able to click the host to search for the last 24 hours. I know the search is right there but it would be even nicer to just click that and then have an option to search something there."
"The user interface needs improvement. The more the user can slide around and know what's going on, the better it will be."
"LogRhythm NextGen SIEM is currently based only on the Windows platform. This means that some of our customers have to purchase a Windows license elsewhere. If LogRhythm can move to a Linux platform or a proprietary platform, it would be very helpful."
"The customer support system is time-consuming."
"Sometimes the error-logging is not altogether helpful. For example, on an upgrade, a systems data processor, a Windows box, was throwing an error code like 1083. Then it just stopped and it died right out of the installer and nobody looked. We searched through Google and what it means is the Windows Firewall wasn't turned on so that it could create a rule for the product. Why wouldn't they bubble up that description so that I wouldn't have to call support and I could just know, "Okay, the firewall wasn't turned on. Turn it back on. Re-run the installer and keep going.""
"The web and on-premise console interface should be the same instead of having a separate engine for each."
"It's not easy for someone new to the solution."
"We have run into problems with stability going through upgrade processes. Recently, we have been on the front edge of the upgrade path. When that happens we tend to run into issues either with certain functionality not working after the upgrades or stability issues because of the upgrades."
"ZeroFOX is not configured to grab the information automatically, including the news."
"Social media takedowns are a major issue. The takedowns should not take more than two to three hours."
 

Pricing and Cost Advice

"It is a very cost-effective solution."
"I think the tool is reasonably priced. There is a need to pay per year towards the licensing costs of the tool."
"I would rate the tool's pricing around eight out of ten."
"The support which allows more customized to the environment when we are deploying new systems is called Professional Service and is very expensive. The technical annual support and there is an annual fee."
"It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that."
"We work with French-speaking African countries, and it costs more than the average SIEM solution. Also, the pricing isn't too flexible. AlienVault, Splunk, and IBM QRadar are more suitable for customers on a tight budget."
"I would rate the pricing 4 out of 5. There are no additional costs to the standard licensing fees."
"The setup and licensing for small and medium size businesses is straightforward, though when it comes to the enterprise it pays to keep in mind the possibility for complications given all the extras and add-ons that may be required."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
831,020 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
45%
Computer Software Company
8%
Government
6%
Financial Services Firm
6%
Financial Services Firm
18%
Computer Software Company
17%
Government
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
The integration is slightly difficult with other assets, like EDR technologies or firewalls. Also, the back end is not as user-friendly as other solutions like IBM QRadar. The technical support is ...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
What do you like most about ZeroFOX?
The best thing about the tool is that its backend team is pretty good and has a strong engineering team.
What needs improvement with ZeroFOX?
ZeroFOX is not configured to grab the information automatically, including the news.
What is your primary use case for ZeroFOX?
ZeroFOX is a threat intelligence platform and a brand monitoring tool. It provides information on leaks in the dark web, the deep web, and credit cards. It also provides brand monitoring services t...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
LookingGlass Manage Intelligence, VigilanteATI
 

Learn More

 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Royal Farms, Hootsuite, BAE Systems, True Citrus
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: December 2024.
831,020 professionals have used our research since 2012.