It monitors the users as well as the endpoints and provides data for that. It basically studies the activities, tries to understand the activities, and then does a little bit baseline for that. It then monitors the user or the endpoint to see if there is any deviation. If there is any deviation, it triggers an alarm.
Cyber Security Analyst at Pacific Propeller
A solid, dependable, and well-recognized SIEM tool with excellent support
Pros and Cons
- "It is an AI technology because it is using machine learning technology. So far, there is nothing better out there for UEBA in terms of monitoring endpoints and user activity. It is using machine learning language, so it is right at the top. It provides that capability and monitors all the activities. It devises a baseline and monitors if there is any deviation from the baseline."
- "In terms of functionality, it is very good. The only issue is the documentation. Its documentation should be improved."
What is our primary use case?
What is most valuable?
It is an AI technology because it is using machine learning technology. So far, there is nothing better out there for UEBA in terms of monitoring endpoints and user activity. It is using machine learning language, so it is right at the top. It provides that capability and monitors all the activities. It devises a baseline and monitors if there is any deviation from the baseline.
What needs improvement?
In terms of functionality, it is very good. The only issue is the documentation. Its documentation should be improved.
For how long have I used the solution?
We installed it on our system about six months ago. We also integrated UEBA with it.
Buyer's Guide
Logpoint
January 2025
Learn what your peers think about Logpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is very stable. It is recognized by Gartner in the Quad evaluation of SIEM tools. They are a strong player, and their product is very solid and stable.
What do I think about the scalability of the solution?
It is being used by 150 people in three different locations in two states.
How are customer service and support?
They have excellent tech support. That's the whole thing. Even though their documentation is lacking, their tech support is excellent.
Which solution did I use previously and why did I switch?
We didn't use any. We didn't have any in place.
How was the initial setup?
Setting up a SIEM tool is never easy. It is very complex because of the components that are involved. You have to onboard all the devices that will be communicating with the tool. It is tedious. You need to get it right. That's the whole strategy.
For its maintenance, we have a two-man IT department, which includes me and somebody else.
What other advice do I have?
It is highly recommended. It is a solid SIEM tool. It is very dependable and well-recognized. In terms of functionality, the queries work in the same way as Splunk. The only drawback is they are predominantly a European provider. Their headquarter is in Denmark and not in the US. Most of their market is in the European Union, but nonetheless, their customer service is excellent. You can get answers to any issue or question that you have related to the implementation right away.
The learning curve is kind of on the medium side, and you need somebody on a full-time basis for UEBA.
I would rate LogPoint a nine out of 10. It only needs better documentation.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
SOC Analyst at a comms service provider with 201-500 employees
Cost-effective and has better dashboards and a good use case creation feature, but its UI needs to be user-friendly, and it needs to be better in processing multiple logs
Pros and Cons
- "What I like best about LogPoint is its cost-effectiveness compared to other solutions. LogPoint also has better dashboards which I find valuable. I also like that you can create use cases based on your assets."
- "What could be improved in LogPoint is its UI because it's less friendly to users than LogRhythm. The UI could be more aesthetically appealing to users. It's completely outdated."
What is our primary use case?
I'm using LogPoint as a commercial product. My company uses LogPoint for data aggregation, which is also used for creating custom use cases based on organizational leads. Then, my company triggers and escalates to the IT team responsible for solving loopholes and problems seen via LogPoint.
What is most valuable?
What I like best about LogPoint is its cost-effectiveness compared to other solutions.
LogPoint also has better dashboards which I find valuable. I also like that you can create use cases based on your assets. For example, if you have some servers. DMZs, or different types of servers, such as core banking servers, you can apply the use cases to the targeted groups or the whole system.
What needs improvement?
What could be improved in LogPoint is its UI because it's less friendly to users than LogRhythm. The UI could be more aesthetically appealing to users. It's completely outdated. For example, it lacks color. IBM QRadar and LogRhythm have better UI than LogPoint. The solution needs a custom dashboard feature to make it better.
LogPoint also needs to improve its network hierarchy diagram. You can't create the whole network diagram if you have the entire subnet system of your server form or your DMZs. This means that in LogPoint, it's pretty difficult to visualize the network hierarchy diagrams, so this is another area for improvement in the solution.
Handling multiple types of logs also has room for improvement in LogPoint. Sometimes, it discards logs, and it has difficulty processing various logs.
An additional feature I'd like the product to have in its next release is the multiple log processing feature.
For how long have I used the solution?
I've used LogPoint for two years, but the last time I used the solution was more than six months ago.
What do I think about the stability of the solution?
There were some glitches in LogPoint, so it wasn't as stable. For example, if we exceed our EPS, or if there are data not normalized by the editor, or logs generated by assets that LogPoint doesn't normalize, those logs won't be processed.
LogPoint can't handle multiple types of logs. For example, for IAS servers that generate various kinds of logs, such as system and security logs, at some point, LogPoint still needs to manage and understand the different logs. Sometimes, the solution discards the logs. This is why we moved to LogRhytm.
How are customer service and support?
I opened some tickets with LogPoint support when I was still using the product. It was easy to open tickets and connect with the LogPoint support team. The higher level team, the L2 group, was quite competitive, but the lower level team, the L1, needed work because the L1 staff sometimes failed to understand my problems with LogPoint.
The L1 support team usually escalates the issues to the L2 support team, so the level of escalations in LogPoint is higher than in IBM QRadar.
The IBM QRadar L1 team is more competitive than the LogPoint L1 team.
I feel that LogPoint has outsourced L1 issues. That should be done in-house.
On a scale of one to five, I rate LogPoint technical support as two.
Which solution did I use previously and why did I switch?
I've suspended using LogPoint because I shifted to LogRhythm. I'm now using LogRhythm because it's more user-friendly with a better UI than what LogPoint has. LogPoint also can't handle multiple log types. Though LogPoint is cost-friendly, LogRhythm provides features that both LogPoint and IBM QRadar and other solutions can't offer.
How was the initial setup?
The initial setup for LogPoint is pretty straightforward. It's relatively easy to learn and understand, especially for small organizations. I belong to a small organization that can't afford more expensive products. You won't see LogPoint in review site scoreboards, for example, in Gartner, and the product isn't found under Leaders and Visionaries, but it's still quite effective. It's comparable to going for open-source systems.
Deploying LogPoint was relatively easy. I've been deploying it for a long time. The process is easy, but it's based on how many systems you need to connect to LogPoint. For example, my company has more than fifty assets that need to be integrated with LogPoint, so that could take some time, though the deployment process is much easier. I was able to deploy it within one hour, though.
What about the implementation team?
LogPoint was implemented in-house. I also did some of the implementations, which was relatively easy.
What's my experience with pricing, setup cost, and licensing?
My company used to pay for LogPoint costs annually. It's a cost-effective solution.
I'm not part of the Finance team, though, so I'm not sure exactly what the licensing fee is or what license my company had.
Which other solutions did I evaluate?
I've evaluated IBM QRadar and LogRhythm.
What other advice do I have?
I have experience with IBM QRadar for more than three years. I also have experience with LogPoint. I've used LogRhythm as well for more than two years now.
My company is a partner of LogPoint, but first, it was a vendor, then it became a partner that collectively collaborated with LogPoint, recommending LogPoint seminars to customers.
Fifty percent of people in the organization use LogPoint, mostly security engineers. One person can handle the maintenance for LogPoint, specifically for a small organization.
As I've not used LogPoint in the last four to six months, I'm no longer updated on what changes were made to the product. If LogPoint works much better for you, then I'd recommend it. Still, if you're considering the product commercially, it's better to go with another solution that works better, with fewer issues, at least from a smaller organization standpoint.
My rating for LogPoint is four out of ten. I didn't give it a higher mark because it needs to improve in several areas, including the GUI, network hierarchy diagrams, and log optimization.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Logpoint
January 2025
Learn what your peers think about Logpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
CCO at Oduma Solutions Ltd
Responsive support, all in one platform, but dashboard lacking customization
Pros and Cons
- "The most valuable feature of LogPoint is that they have the SIEM and SOAR combined in one solution. They are not on a separate platform."
- "LogPoint can improve its dashboards. We are not able to customize the dashboard when creating them. They only have preset dashboards which do not have exactly what we are looking for."
What is our primary use case?
We are using LogPoint for MSSP.
What is most valuable?
The most valuable feature of LogPoint is that they have the SIEM and SOAR combined in one solution. They are not on a separate platform.
What needs improvement?
LogPoint can improve its dashboards. We are not able to customize the dashboard when creating them. They only have preset dashboards which do not have exactly what we are looking for.
For how long have I used the solution?
I have been using LogPoint for approximately two months.
What do I think about the stability of the solution?
LogPoint has had a few bugs, the stability could improve.
What do I think about the scalability of the solution?
We have six people using this solution.
How are customer service and support?
The support is good for LogPoint, they are very responsive.
How was the initial setup?
We did the Azure setup of LogPoint and it was very easy and straightforward. The process took us less than 15 minutes.
What's my experience with pricing, setup cost, and licensing?
When we were evaluating other solutions LogPoint was the least expensive solution in the market.
Which other solutions did I evaluate?
We evaluated other options and it made sense for us to choose LogPoint because they have both the SIEM and SOAR together.
What other advice do I have?
My recommendation would be for others to try LogPoint out before making a decision, because it's a fairly new company, and you'll want to give them a try before you decide to purchase.
I rate LogPoint a seven out of ten.
There are some bugs that need to be fixed.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CEO at a tech consulting company with 1-10 employees
Improves security, offers insightful technical support, and has attractive pricing
Pros and Cons
- "The solution's most valuable aspect is the combination of the software and the support that they have."
- "One of the downsides is it is not a SaaS solution. It must be on-premises."
What is our primary use case?
The use case with the business case actually is using LogPoint as a full-blown team system. And actually to orchestrate incident responses.
It's a SIEM system and if you incorporate detection rules and can set alerts, severities, stuff like that. It's the center of a SOC, basically. That's the main use case for it. Of course, it's also sued to fulfill regulatory compliance, which is making a report every week, every day, every month, according to the auditor, what he wants. That's the basic use case.
How has it helped my organization?
It improves security. You have more oversight of security incidents and everything that's wrong with the infrastructure you can see in LogPoint if you do it right. You can also document it. You can document the state of your organizational security. If you look at your report, your quarterly or monthly report, it gives you an overview of what's the current status, and then it gives you a delta of the status for the last month. That's actually very, very nice. For a CSO, they can track the improvements.
What is most valuable?
The solution's most valuable aspect is the combination of the software and the support that they have. If you use SIEM systems, you always have a problem. You want to onboard an application, yet the logs from that application cannot be understood by the SIEM system. You sometimes have that. If you want to onboard, let's say, a common application to your SIEM system, it usually just works out of the box. However, if you have an exotic application that no one knows, the SIEM system most of the time cannot understand it. But LogPoint offers a translation service. You ship the log files to them and their guys make sure that LogPoint is able to translate it and ingest it. That service is actually really, really nice. And you don't pay for that.
What needs improvement?
One of the downsides is it is not a SaaS solution. It must be on-premises. It's a downside for the industry as it makes no sense to have just the solution as deployable via on-prem hardware. Nowadays, it must come as a solution that you can deploy in the cloud, either in Google, AWS, or Microsoft. It is possible, however, it's not cloud-native. That's a downside and that's a problem. When you can deploy a SaaS, cloud-native solution, then it's much easier than spinning that thing up with an image and stuff like that. SaaS is easier to manage and there are cost savings involved.
It needs to improve performance. That's somehow something that others do better. They need pure speed. Just speed. How they process data, it's not top-notch. It's just average.
For how long have I used the solution?
I've been using the solution for half a year or so, about six months.
What do I think about the stability of the solution?
The solution is pretty stable. However you can crash the system if you did not do the math to calculate the right sizing of the hardware. LogPoint doesn't forgive any undersized storage, memory or compute power.
How are customer service and support?
The support itself was good, however, it was sometimes a bit on the slower side. They were too slow yet the answers were brilliant.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I'm with another company right now. Those guys where we used LogPoint, yes, they used something else, which was called AlienVault at the time. I'm not even sure if this still exists as AlienVault anymore.
LogPoint comes with a scheme that goes with endpoints, which, if you have an IP that gives logs business, one counts as one. And if you have 100 servers, you pay just for the 100 servers. How much data they log is just, they do not care. You pay for the three endpoints. If you have one server in, let's say Splunk, and it logs one bite a day, you pay almost nothing. And if you have that same server logging one terabyte, you go bankrupt basically since you have to pay so much with something like AlienVault. They switched due to the fact that LogPoint does not care about the data. They just use the endpoint - which is good for security operation centers.
Another company I worked for used DataDog, which is flexible and cloud-native. They are still with that solution.
How was the initial setup?
The initial setup was straightforward. It was very easy, however, in the beginning, there were some errors and those errors were based on some bugs in the software. It's been worked on and so now it's fixed, however, beyond that, it was pretty straightforward, pretty easy.
You only need one person to do a deployment, however, I recommend three, it depends on your organization You basically need a system administrator that can deploy it. Configuration needs to be done by a security analyst.
There is continued maintenance required. Both of the roles that I just described are needed for maintenance, constant maintenance.
What about the implementation team?
We did the installation ourselves. That said, we had decent training on that. Decent training is necessary and I highly recommended it. You basically cannot do this by yourself with no training. Back in the day, the training we received was facilitated by LogPoint. Nowadays, you can choose big consulting companies as well.
What was our ROI?
I did see an ROI when using the solution. The company that I work for, which is utilizing LogPoint, was using that as a basis for their SOC. They offered the SOC, the security operation services, to other companies. They generated revenue with that.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty attractive. If you look, they have of course list prices, which are moderate. However, if you really go to them and say, "Hey, I need a discount and I am a public organization." YOu might be able to get lower prices. For an NGO or a foundation or something they likely offer a discount. They give you a special discount and they give good discounts. Also, if you say, okay, "Hey, your business model doesn't work for me as the break-even is 50 endpoints" they give you a decent discount and they're good.
Which other solutions did I evaluate?
I've looked into other SIEM solutions. In comparison, LogPoint works better in the European and German markets due to some unique features in data protection, compared to Splunk or some of the others, even Sentinel.
LogPoint is a very good product for mid-sized companies, especially in Europe. However, for big data chunks, big companies that are either in the cloud or not should use a solution like Splunk or an ELK-like elastic search-based SIEM solution due to the speed.
What other advice do I have?
I am just a customer and end-user.
We use various versions of the solution. The latest version was the one I was using, however, I can't recall the exact version number.
I'd rate the product eight out of ten.
I'd advise potential new users to make sure that their use cases are designed beforehand. When you do a POC, then you need to have a success factor. People sometimes want to have a SIEM solution and then just look at the dashboard, which is total garbage. You need to know exactly what you want from that solution and if this is determined beforehand, then you can do a POC and then you will understand if the solution can deliver what you need - or not.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Stable, with good reporting and technical support
Pros and Cons
- "The most valuable features are the ones that we use the most, which are the search and report facilities."
- "I know that they have user behavior analytics, but it's an extra cost for this feature. It would be nice if it was in with the standard products."
What is most valuable?
The most valuable features are the ones that we use the most, which are the search and report facilities.
What needs improvement?
There is room for improvement on both our side and on the side of LogPoint.
We could improve on what we decided to put into LogPoint for it to work on and LogPoint Is improving with its addition of the MITRE ATT&CK framework.
I know that they have user behavior analytics, but it's an extra cost for this feature. It would be nice if it was in with the standard products.
If there were one price that you paid and that included all of the features, instead of having to pay a bit more to get advanced features. It would make things simpler when you purchase.
For how long have I used the solution?
I have been using LogPoint for approximately six years.
We're currently migrating from version 6.6 to 6.9.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
It's a scalable solution. We can add more LogPoint boxes, repositories, and sources.
We have 20 or 30 people who are using the information from it, in our organization.
How are customer service and technical support?
Technical support is very good.
Which solution did I use previously and why did I switch?
We used to use LogRhythm.
We made a significant investment in LogRhythm, and it didn't cope with the size of our estate, so we decided to go elsewhere.
How was the initial setup?
The initial setup was quite straightforward.
It took us a couple of weeks to set up all of the log sources and to configure them.
To maintain this solution it's one person and half their time to work on it.
What about the implementation team?
The implementation was very good from our point of view, but we had one of the top people come out and install it with us.
I think we were the first local authority and the council in the country to touch the LogPoint.
They came out and made sure that it was installed properly and that it worked properly with us, which I'm not sure everybody would get.
What's my experience with pricing, setup cost, and licensing?
It's getting more expensive, which is one of the reasons we're looking around just to see if there's anything better value. It's still good, but it's I think it's becoming more expensive.
Which other solutions did I evaluate?
We are looking to see what else may be available. There might be something better that we are not aware of yet.
What other advice do I have?
I would say that it's a good product. It's very stable, and the support is very good. We use it a lot.
As I say, I'm looking to see whether or not it's still the product that we should be using or whether there's something out there now.
I would rate LogPoint an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Engineer at IshanTech (M) Sdn Bhd
An user-friendly solution that needs to improve flexibility and documentation
Pros and Cons
- "The solution is user-friendly."
- "Logpoint is not flexible. Its documentation is not user-friendly."
What is our primary use case?
I use the product for my research and development to enhance my work. We are transitioning to a new technology, and Logpoint has proven valuable for my purposes.
What is most valuable?
The solution is user-friendly.
What needs improvement?
Logpoint is not flexible. Its documentation is not user-friendly.
For how long have I used the solution?
I have been working with the product for six months.
What do I think about the stability of the solution?
I rate Logpoint's stability a seven out of ten.
What do I think about the scalability of the solution?
I rate the tool's scalability a nine out of ten.
How was the initial setup?
I rate the tool's deployment an eight out of ten.
What other advice do I have?
I rate Logpoint an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Information Security Specialist at Growth Arbor
A cost-efficient solution with a simple user interface, but the installation guide needs improvement
Pros and Cons
- "The solution's user interface is quite simple, and the integration is better than other products."
- "LogPoint must find a way to integrate the servers without agents."
What is our primary use case?
We used the solution to help our clients protect their environment by identifying users and the tools they access. Multiple users in our client's admin and HR departments were accessing critical financial documents. Our clients could not stop them from accessing these documents. So they wanted data on which users were accessing the files.
What is most valuable?
The solution's user interface is quite simple, and the integration is better than other products. The product is easier to work with when compared to open-source tools like Wazuh. The solution’s dashboard is exceptional. LogPoint is much easier to use than LogRhythm. LogPoint is cost-efficient.
What needs improvement?
The solution must improve its agent installation method, in which we must manually update IP addresses and codes. Most of our employees must install agents to integrate their systems into LogPoint. LogPoint must find a way to integrate the servers without agents.
The solution must improve its user and installation guides so anyone with basic knowledge can install and configure it.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
The stability is quite good. I didn’t notice any issues with the solution. I rate the stability a seven out of ten.
What do I think about the scalability of the solution?
I rate the scalability of the solution an eight out of ten. We have two large enterprise and two medium enterprise customers.
How are customer service and support?
The support provided by the solution for Asia is marvelous. The support is always active, and they respond within an hour.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was a little bit complex. However, it is not complex for users with experience using the solution. I rate the initial setup a six out of ten.
What about the implementation team?
It takes us six to seven days to deploy around 500 nodes. The deployment process depends on the logs of the employees.
What's my experience with pricing, setup cost, and licensing?
The solution’s pricing is competitive. I rate the pricing a seven out of ten.
What other advice do I have?
Integrations can be done using CSV files. My team is currently working on LogRhythm. The integration of LogRhythm is quite complicated. Most of the issues we faced while working on the solution were due to the customer’s system. Overall, I rate the solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Consultant at a government with 10,001+ employees
Enables ability to design drivers for log data collection which has improved efficiency
Pros and Cons
- "Log collection, dashboards and reporting are good."
- "Dashboards could be developed further."
What is our primary use case?
We're a health care organization and we had a specific case where LogPoint was able to help develop a special collector for an earlier version of our storage system, where we had issues with migration. Some files were missing when we migrated to the new system, and we had trouble finding out why. LogPoint was very helpful in designing some drivers which could collect the log data, so we could identify the problem. We're customers of LogPoint and I'm a security consultant.
What is most valuable?
The most valuable features for us have been the log collection, dashboards, and reporting.
What needs improvement?
My issues with the product are mainly with regard to how it handles collecting logs. I'm currently thinking about implementing a new lever feature.
Additional features I'd like to see would be standard help features in developing dashboards and reports, and some of the alerts you can setup.
For how long have I used the solution?
I've been using this solution for 10 years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution and we're currently expanding. We have 10 users but hoping to expand to 100.
How are customer service and technical support?
The technical support is comprehensive, but you have the same issues as every company that uses India as a support center.
How was the initial setup?
I believe the initial setup was straightforward but there have been some issues with some of the vendors we are using such as Dell EMC Isilon storage systems. They have a very cool setup for sending logs to a log management system.
What other advice do I have?
I would advise people to be aware of their needs, and test some specific use cases, so that you get the benefits from the start, because you don't gain anything out of a SIEM system, if you don't have the right amount of data, from the right sources.
I would rate this product an eight out of 10. I'm Danish so nobody gets a 10! There's always room for improvement.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Logpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR)Popular Comparisons
Wazuh
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Exabeam
USM Anywhere
Sentinel
ArcSight Enterprise Security Manager (ESM)
SolarWinds Security Event Manager
Buyer's Guide
Download our free Logpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?