The advanced intelligence engine -- in fact, the whole suit -- is very powerful. It depends how you use it. Security management is what it's best at. As far I’m concerned, it’s one of the best.
IT Security Specialist at a manufacturing company with 1,001-5,000 employees
Security management is what it's best at, but it's generally for medium-sized companies.
What is most valuable?
What needs improvement?
This product is in general for medium-sized companies. For bigger companies with millions of logs coming in, it just cannot support them. The solution is not robust. It depends on the size of the companies and the size of the firewalls you have which will determine if it will work for you. Thus product is really good and easy to use for medium sized companies.
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
Initially we had a lot of issues. Today it has improved dramatically, and it has no issues in deployment.
Buyer's Guide
LogRhythm SIEM
January 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is very stable, but we have to work with it and identify which logs we need. If we don’t, it doesn't handle the traffic well.
Every tool is different, and you just have to work with it.
How are customer service and support?
It’s one of the best customer services you could find. Everyone is very knowledgeable and helpful. You aren’t waiting around for tickets to be resolved. If they can’t resolve it, they escalate and resolve quickly.
What was our ROI?
Absolutely we have made a ROI. It resolves a lot of issues. It helps a lot of our infrastructure and everyone is benefiting. It’s absolutely worth the money spent.
What's my experience with pricing, setup cost, and licensing?
They are very transparent about the licensing. They are upfront. They tell you what can handle what. They are honest people.
What other advice do I have?
I have been invited to user group meetings and we have had good conversations. They have been very helpful and they understand my needs. They listen to our input and really take it seriously. They really work with us on different issues.
Everything is fantastic.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Sec Eng at a financial services firm
Video Review
I don't have to log in to six or seven different appliances and hunt for data
What is most valuable?
What I found most helpful out of it is the ability to see all of the same data, that I would get from my appliances, in one place. I don't have to log in to six or seven different appliances and hunt for that kind of information. I can just do some queries within LogRhythm and it tells me the same information.
What needs improvement?
One of the things I find that would be helpful is the GLPR information, to be able to understand what is actually being processed. I've got, say, 20 different rules, but I don't know which one is getting more of the data, which is getting none of the data, because there's not really a good interface for that.
What do I think about the stability of the solution?
The stability, it's pretty high, there were some early issues, we were overrunning it with data, and part of it was a sizing issue. Once we got through that it's been running a lot better and it's been more stable. We haven't had to worry about it falling over on itself.
What do I think about the scalability of the solution?
At this point we're still using a single XM appliance. The scaling that we've had is really just upgrading from an older-series to a newer-series XM appliance.
How is customer service and technical support?
There were a lot of support calls we went through, and they would tweak and change a few settings here and there. Then eventually, what we did was we upgraded to different hardware because there wasn't anything else we could remove. We had to continue to keep getting those same logs.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
LogRhythm SIEM
January 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
SYM Engineer Specialist at FIS
Provides huge visibility into your network, you see everything and you see it easily
What is most valuable?
Visibility. Being able to see the system, see what's coming in, and being able to report on the logs coming in. Seeing what other people are doing and being able to track down quickly what is going on in your network.
How has it helped my organization?
We're a worldwide company with 50,000 employees, in probably 15 locations, three SOCs and four or five data centers.
It's made it quicker for us to see threats. It's an easier platform to work with. Its more user friendly, GUI based.
What needs improvement?
Easier creation of rules and parsing, and more user-friendly. A more user-friendly basis of using the tool to create rules and alarms to be able to report off of, and quickly stop any attacks and the like.
Also, more in-depth training on how the security platform works with other pieces of software like Sequel, firewalls, or PowerShell.
What do I think about the scalability of the solution?
A ten again. It's very easy to scale.
How are customer service and technical support?
Great. They respond quickly and are very knowledgeable and they also allow us to be hands-on. Instead of them doing it for us, they actually teach us how to do it. So better knowledge transfer.
Which solution did I use previously and why did I switch?
We were using RSA Security Analytics and, before that, we were using RSA enVision. The challenges behind them were that they were very clunky, not very user-friendly, and you had to know coding, and you had to know command-line interfaces to even use them. Even on their GUI side. With LogRhythm we don't have to.
How was the initial setup?
It was straightforward and, like I said, a lot of good knowledge transfer on what to do and how to proceed.
Which other solutions did I evaluate?
IBM QRadar and RSA Security Analytics, but LogRhythm stood out because of their scalability and their interface and their user friendliness. Being able to easily navigate through the system.
What other advice do I have?
It is very important that our solution to be a unified end-to-end platform. Very important. We wanted a one-stop shop with LogRhythm. We didn't want to use anything else to record our logs and stop threats.
I would give LogRythm a 10 out of 10 just purely on the fact they are very helpful, very knowledgeable. The software is very easy to use. Easy to learn. I came into security with no knowledge of security or how to do anything, and within a year I'm an administer of the software. So it's pretty good.
I would say go with it. Hands down, one of the best security platforms I've seen. Easy to use, ease to scale, huge visibility into your network. You just see everything and you see it easily. You don't have to go search for things.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Lead Info Security Architect with 501-1,000 employees
We have used its alert capabilities to help us mitigate issues more rapidly
How has it helped my organization?
It helps by collecting logs from a lot of different security items, like firewalls and IPSs. It helps to give us alerts to let us know if something is happening on our network. It has really good log collection and event and alerting capabilities, so we have used those alerts to help us mitigate issues more rapidly.
We have been able to stop ransomware by being alerted through LogRhythm. That was probably one of the biggest things. Also, malware events and things like that.
What is most valuable?
Using the web console to get a quick look at what's happening on the network, so the different dashboards that are available. Those are probably the things I look at first. Probably very useful at really analyzing what's going on.
What do I think about the stability of the solution?
We haven't seen issues with the product itself. There are updates which are now automatic through the knowledge-base. So, I'd say it's a stable product.
What do I think about the scalability of the solution?
We have not had issues with scalability as far as LogRhythm's concerned. We're not big enough to have issues of scalability with it. It is a much bigger product than that. We're not a huge global organization, so it's more than enough for a company our size.
Our environment is about a 1000 users, about 900 workstations, and a couple 100 servers. It is a Windows and Cisco shop.
How are customer service and technical support?
They are really good. Whenever I've needed their help, opened up a ticket, I haven't had any issues getting help from them. We have a guy right now who is really excellent, and will go out of his way to help us with making sure we are getting things setup properly, so that's really been a big help. They have really smart people there. When you work with them over the course of a number of years, you see how bright these guys are, so it's nice.
Which solution did I use previously and why did I switch?
We're fairly close to Boulder, so buying something that was local, I like to do that, and it is a great product. We're happy with it. I think it is one of the best SIEM tools out there. So, no regrets about going local, and it's nice to have them down the road if we need to get to them.
What other advice do I have?
It is a great product. We brought it in initially as a central event log for PCI compliance. It's been really good for PCI compliance, but then we leveraged it for security across the network, so it has been really good that way. It really requires somebody to be able to dedicate a lot of time to getting sources into it. It's hard if you're a partial user of it. It takes a lot longer to really understand the product, because it's big. There's a lot to it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Information Security Analyst 2 at a non-profit with 1,001-5,000 employees
Gives us visibility into areas we wouldn't have seen, such as code execution; allows us to drill down on servers
What is most valuable?
- Visibility
- The AI Engine for rule generation
How has it helped my organization?
We have two facilities, a combination of all different platforms, Linux, Windows, etc. It's just all across the board.
It's definitely given us a lot of visibility into areas that we probably wouldn't have normal visibility into, such as code execution and things like that. It allows us to really drill down as to what's happening on the servers as they are being used in production, to where we can really get in and figure out what's going on.
What needs improvement?
It's pretty effective. In some cases we have run into some issues: The way that the rules work, and the alarms trigger. We get a good number of false positives.
I wish that there were more instructional videos on how to do different things and more walk-throughs.
Also, easier generation of AIE rules, or custom ones.
What do I think about the stability of the solution?
So far it's been really good.
What do I think about the scalability of the solution?
Scalability is very good.
How is customer service and technical support?
I've used LogRhythm tech support. I would rate it as very good, not excellent. For instance, we were trying to deal with pass the hash, which is a very common exploit and LogRhythm tech support told us they were just going turn that rule off, that we can't use it. We had to keep pushing until we had someone in another department push to an upper level of tech support to finally get it to where it was working.
What other advice do I have?
It's very important for a solution to be a unified, end-to-end platform for us.
It's a really good solution. It's been very stable. At the same time, we have had some issues, some false positives.
And that issue I told you with tech support, there have been some challenges getting it to be where we wanted it to be, for a solution, like LogRhythm, that is supposedly best in the industry. I just thought it was kind of poor that they would take a common exploit that's been in use for years and say we can't get it to work when, obviously, they could get it work. It was kind of lazy.
Still, I would say go with LogRhythm.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Junior Information Security Analyst at a financial services firm with 51-200 employees
All logs in one place; we can quickly determine if there is a threat actor, from internal to external
What is most valuable?
The fact that I can quickly determine if there is a threat actor from internal to external. That's our primary goal. We have a lot of traders and a lot of developers, internal, so that's generally where our presence is. We don't have a whole lot of online presence. We're not so much worried about external actors.
Being able to determine what a user is doing is really helpful for us.
How has it helped my organization?
We've got two facilities. We pretty much have one setup, the DX. We don't have any failover, just because it doesn't work for us.
Our key challenge is weeding out who is actually trying to be a threat. Now, LogRhythm certainly helps us, but it's still very difficult because we've got not a super high turnover, but high enough that you're constantly going through them looking at stuff.
Being able to actually track somebody down and figure out what they're doing. Before, we didn't really have these insights, we were going by the the seat of our pants and trying to pull whatever logs we could, whatever Unix logs we could find, and it wasn't really helpful that way. Now it pulls it all into one spot and we're actually able to correlate data and say, "Hey look, this person's really actually being shady," and go from there.
We've been able to identify certain individuals and not have issues past that.
What needs improvement?
There is a Group-By field that they're breaking out, which stopped me from being able to have certain events. They're breaking it out in 7.3, so they've already got it. That was the one thing that bothered me, so I'm happy about that.
What do I think about the stability of the solution?
Stability is not great but I think that's our issue. Qualys seems to blow it up all the time, but that's more on us to stop Qualys from scanning LogRhythm.
What do I think about the scalability of the solution?
Scalability is pretty good. We rolled it out at our primary company and then rolled it out past, to our sister company, which went really, really well.
How is customer service and technical support?
It's awesome.
What other advice do I have?
It's fairly important that a solution be end-to-end unified. The fact that LogRhythm is, is working out very well for us.
I gave it eight out of 10 because of some of the issues we've had with the system actually going down but, again, that might be entirely on us. We're still in the defining phase of that.
One thing that surprised me over the course of our deployment is the amount of logs that I didn't realize we had, different log sources that we're seeing pop up, pending, being brought into the system and we haven't even seen them before. People are standing them up left and right and I'm thinking, "Guys, stop it."
Make sure that your operations guys, your network guys can actively search through it well. Get them training. Don't do half a job with it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network Engineer at a transportation company
SmartResponse, alarming, and being able to write our own rule set allow us to delegate alarm monitoring
What is most valuable?
- The SmartResponse and the alarming
- The ability to write your own rule set
How has it helped my organization?
It allows us to delegate some of the alarming, where there's not just one person looking at it all the time. Some lower-level techs can handle basic alarming.
What needs improvement?
Sometimes our rules don't fire correctly, events don't get created correctly, but that's mostly just because we have to write custom regex.
Also, moving from away from the fat console, more into the web console for log sources and tuning and things like that, would be helpful.
At times It gets a little clunky, or resource-intensive, but it works.
What do I think about the scalability of the solution?
It works pretty well. It's somewhat hard to delete something out of the system. That's probably our only challenge, because we reuse an IP address and then it's difficult.
How are customer service and technical support?
We've used them a few times. They were pretty good.
Which solution did I use previously and why did I switch?
We actually weren't using anything before. It was a conglomerate of a firewall and the Windows logs. But we had an IT architect that was more into security.
How was the initial setup?
It was pretty easy.
What other advice do I have?
Regarding a solution being a unified, end-to-end platfrom, it helps, but it's not completely necessary.
For what it does, LogRhythm works pretty well.
If I were to advise a colleague who is looking into a this solution, I would say train someone, as their full-time, job to use it. It's not an easy product to get around.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at Guitar Center
Enables us to feed in logs from other solutions and build dashboards to show us what we need to see
What is most valuable?
AI Engine
How has it helped my organization?
It's got intelligence. Does a lot of the heavy lifting, you can create custom AI rules. I'm looking forward to this CloudAI.
It definitely complements all of the other solutions we have. We can feed all the logs into our system, build dashboards that the products themselves cannot provide. For example, we have web filtering, their dashboards aren't so great for that product. But when we feed it into LogRhythm, we can build dashboards that really show us what we need to see.
What do I think about the scalability of the solution?
Pretty scalable. We were on an HA setup. Got about 2000 messages per second. It's pretty scalable.
How are customer service and technical support?
They're top-notch. Every time I call, there's somebody willing to pick up the phone, somebody willing to jump on a WebEx, so I have nothing but good things to say about LogRhythm. Compared to every other product we have, LogRhythm support is the best. Without a doubt.
Which solution did I use previously and why did I switch?
I've used Symantec SIM, which wasn't so great. This is a real breath refresher, because it's more scalable, and I feel it's a better product overall.
What other advice do I have?
The most important factor, for me, when selecting a solution is that it needs to be lightweight.
Advice I would give to a colleague at another company who is researching this sort of solution: Talk to me first.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Exabeam
USM Anywhere
ManageEngine Log360
Google Chronicle Suite
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- Does LogRhythm NextGen SIEM offer good security?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?