System Administrator at GOLDENWEST FEDERAL CREDIT UNION
Real User
2022-10-18T09:15:00Z
Oct 18, 2022
One of the main features that I like about LogRhythm NextGen SIEM is that there are a lot of pre-built pieces. Like with our AV, we didn't have to tell it how to read the logs; they already had it pre-made. So, we essentially just had to follow their guide to get the logs imported in and set up some rules for it. We've only had to manually create the parsing rules for a few of our vendors so that we could interpret the logs correctly. Most of them had already been pre-created for us.
The most useful feature that I've found so far is the search function. I like all the different ways you're able to search through metadata and the different ways you're able to correlate or search through logs to find out what's going on.
Senior Security Analyst at a transportation company with 501-1,000 employees
Real User
2022-10-16T09:09:00Z
Oct 16, 2022
The dashboards in the LogRhythm SIEM really help us as a starting point. It gives us a starting point we can go to every day. We walk through several dashboards to see anomalous activity for further investigation.
This solution has improved our organization in many different ways. The biggest benefit is being able to view all information in one dashboard instead of having to look at several different applications and dashboards. I can see information across our entire environment and every aspect of our network.
FSE at a computer software company with 1,001-5,000 employees
Reseller
2022-07-24T07:16:36Z
Jul 24, 2022
As a SIEM, probably the best feature is that it can be tuned effectively. There are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed.
SOAR is integrated with the dashboard that we use for threat management. Because it's all integrated, it is useful for us when we deploy something on-prem.
LogRhythm NextGen SIEM covers all our primary security analysis needs. It makes it easier for us to analyze threats and improves our response times. It's a versatile platform that performs queries fast compared to other SIEM solutions.
Information Security Analyst at a financial services firm with 1,001-5,000 employees
Real User
2022-02-06T07:20:05Z
Feb 6, 2022
LogRhythm NextGen SIEM is customizable, simple to manage, and there are many features. The solution does not require an expert to be able to use it, anyone can use it.
security solutions integrator at a consultancy with 1-10 employees
Real User
2021-12-27T19:55:08Z
Dec 27, 2021
LogRhythm's GUI is easy to explore. We also like other features, such as its integration with other security solutions, log correlation, and the deployment of use cases.
Systems Administrators at a tech services company with 201-500 employees
Real User
2020-12-31T17:15:06Z
Dec 31, 2020
File Integrity Monitoring is really valuable because we have it set up on our core assets. This is one of the key features that I utilize. We also use it quite a lot for event management to do reporting.
Information Security Officer, Network Analyst at a university with 1,001-5,000 employees
Real User
2020-12-03T23:38:34Z
Dec 3, 2020
Automations are very valuable. It provides the ability to automate some of our small use cases.
The ability to integrate with other products that use an API is also very useful. LogRhythm has a plugin for it that we can connect and start to move down towards the path of a single pane of glass instead of having multiple or different tools.
Senior Cyber Security Engineer at a individual & family service with 10,001+ employees
Real User
2020-10-05T14:30:00Z
Oct 5, 2020
I have found the Advanced Intelligence Engine has provided the most value to us because we can customize alarms based on our requirements and have created hundreds of alarms that notify different people for different scenarios.
Information Security Engineer at Seminole Tribe of Florida
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
It has allowed us to dive deeper into our network and figure out what is going on by parsing logs properly and being able to reduce the time it takes to work cases down from seven days to approximately two days.
Senior Architect at a energy/utilities company with 201-500 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
We have NetFlow information going into it, so we can examine a lot of traffic patterns and anomalies, especially if something stands out and is not the baseline. This helps a lot.
Its benefits are broad. The solution isn't necessarily made to do any one thing, but it can do anything you tell it to. It is able to tackle any different type or size of job.
Systems CSO at a manufacturing company with 1,001-5,000 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
The alarm functions have helped us cut down on the manual work. They bubble things up to us instead of our having to go look for stuff. Also, from an operational perspective, day to day, the Case Management functions are really useful for us. They allow us to track what we see in the incidents that we have.
IT Security Administrator at a energy/utilities company with 1,001-5,000 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
We integrated Azure logs with it and that makes it simpler. Rather than having to log into the portal, we can just check everything in one place. We can compare those to our Windows and host logs to see if any problems correlate between them.
Security Engineer at Managed Technology Services, LLC fka LexisNexis
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
We have to be able to show the evidence, and LogRhythm does a great job of putting it forward and making it easy to create reports with nice looking dashboards, which show off what we are doing as a security program.
SOC Analyst at a financial services firm with 1,001-5,000 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
Even other products we have that feed into it, instead of having to watch all of them we only have to watch one. For example, we have CrowdStrike, so instead of having to pay attention that solution - because their dashboard doesn't really pop when an alarm comes up - we can see issues with the red on the LogRhythm alarm. That is very nice.
Senior Security Engineer at a manufacturing company with 5,001-10,000 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
The AI Engine can take an event and correlate it into something else giving us meaningful context regarding what is going on. We integrated it in with our ticketing system, so if an alarm fires, it raises a ticket in our system.
When it comes to dealing with support, all my interactions have been great. Everyone has known what they're doing and have been quick to respond. They seem to always know the answer. I haven't stumped anybody yet.
Manager of Information Security at a real estate/law firm with 51-200 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
The ability to drill down and pivot from an event is one of the biggest advantage the product has compared to other things that I have seen in the market.
Security Engineer Analyst Admin at a aerospace/defense firm with 1,001-5,000 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
Alarms are the most valuable feature. We also like the dashboard and how things are at your fingertips. The fact that we can now edit the report templates is going to be a great thing.
Principal Security Analyst at a healthcare company with 501-1,000 employees
Real User
2018-10-28T08:38:00Z
Oct 28, 2018
We take in around 750 million logs a day. We have a lot of products and that would be a lot of different panes of glass that we would have to look through otherwise. By centralizing, we can triage and take steps much more quickly than if we tried to man that many interfaces that come with the products.
LogRhythm SIEM Platform is an award-winning platform in security analytics. With more than 4,000 customers globally, LogRhythm SIEM is an integrated platform that helps security operations teams protect critical infrastructure and information from emerging cyberthreats. Ultimately, LogRhythm SIEM is an integrated set of modules that contribute to the security team’s fundamental mission: rapid threat monitoring, threat detection, threat investigation, and threat neutralization. LogRhythm SIEM...
LogRhythm does a very good job of helping SOCs manage their workflows.
One of the main features that I like about LogRhythm NextGen SIEM is that there are a lot of pre-built pieces. Like with our AV, we didn't have to tell it how to read the logs; they already had it pre-made. So, we essentially just had to follow their guide to get the logs imported in and set up some rules for it. We've only had to manually create the parsing rules for a few of our vendors so that we could interpret the logs correctly. Most of them had already been pre-created for us.
The most useful feature that I've found so far is the search function. I like all the different ways you're able to search through metadata and the different ways you're able to correlate or search through logs to find out what's going on.
The dashboards in the LogRhythm SIEM really help us as a starting point. It gives us a starting point we can go to every day. We walk through several dashboards to see anomalous activity for further investigation.
This solution has improved our organization in many different ways. The biggest benefit is being able to view all information in one dashboard instead of having to look at several different applications and dashboards. I can see information across our entire environment and every aspect of our network.
It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable.
NextGen SIEM's most valuable feature is its user-friendliness.
As a SIEM, probably the best feature is that it can be tuned effectively. There are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed.
SOAR is integrated with the dashboard that we use for threat management. Because it's all integrated, it is useful for us when we deploy something on-prem.
LogRhythm NextGen SIEM covers all our primary security analysis needs. It makes it easier for us to analyze threats and improves our response times. It's a versatile platform that performs queries fast compared to other SIEM solutions.
LogRhythm NextGen SIEM is customizable, simple to manage, and there are many features. The solution does not require an expert to be able to use it, anyone can use it.
LogRhythm's GUI is easy to explore. We also like other features, such as its integration with other security solutions, log correlation, and the deployment of use cases.
The user interface is good.
I would say the most valuable feature of LogRhythm is that it has built-in UEBA functionality, among other basic Windows packages.
The product is great for medium to large-scale organizations.
File Integrity Monitoring is really valuable because we have it set up on our core assets. This is one of the key features that I utilize. We also use it quite a lot for event management to do reporting.
Automations are very valuable. It provides the ability to automate some of our small use cases.
The ability to integrate with other products that use an API is also very useful. LogRhythm has a plugin for it that we can connect and start to move down towards the path of a single pane of glass instead of having multiple or different tools.
In terms of security, LogRhythm NextGen SIEM is great.
The most valuable feature is that we can alternate incident automations.
The initial setup is pretty easy.
I have found the Advanced Intelligence Engine has provided the most value to us because we can customize alarms based on our requirements and have created hundreds of alarms that notify different people for different scenarios.
We use this solution to examine disparate log sources and provide a cohesive method to search for anomalous behavior.
The feature that makes it usable is the web interface.
The ability to investigate a particular period of time where you can analyze logs is its most valuable feature.
It has allowed us to dive deeper into our network and figure out what is going on by parsing logs properly and being able to reduce the time it takes to work cases down from seven days to approximately two days.
We have NetFlow information going into it, so we can examine a lot of traffic patterns and anomalies, especially if something stands out and is not the baseline. This helps a lot.
Its ability to work with all different sorts of log sources has been extremely valuable.
Its benefits are broad. The solution isn't necessarily made to do any one thing, but it can do anything you tell it to. It is able to tackle any different type or size of job.
The alarm functions have helped us cut down on the manual work. They bubble things up to us instead of our having to go look for stuff. Also, from an operational perspective, day to day, the Case Management functions are really useful for us. They allow us to track what we see in the incidents that we have.
We integrated Azure logs with it and that makes it simpler. Rather than having to log into the portal, we can just check everything in one place. We can compare those to our Windows and host logs to see if any problems correlate between them.
We have to be able to show the evidence, and LogRhythm does a great job of putting it forward and making it easy to create reports with nice looking dashboards, which show off what we are doing as a security program.
The most valuable features would be the automation, reporting, and the support.
Even other products we have that feed into it, instead of having to watch all of them we only have to watch one. For example, we have CrowdStrike, so instead of having to pay attention that solution - because their dashboard doesn't really pop when an alarm comes up - we can see issues with the red on the LogRhythm alarm. That is very nice.
The AI Engine can take an event and correlate it into something else giving us meaningful context regarding what is going on. We integrated it in with our ticketing system, so if an alarm fires, it raises a ticket in our system.
It seems like it will scale easily with the way our environment is set up.
When it comes to dealing with support, all my interactions have been great. Everyone has known what they're doing and have been quick to respond. They seem to always know the answer. I haven't stumped anybody yet.
The Web Console is my favorite. It enables me, at a glance, to see the health of the environments.
The ability to drill down and pivot from an event is one of the biggest advantage the product has compared to other things that I have seen in the market.
Alarms are the most valuable feature. We also like the dashboard and how things are at your fingertips. The fact that we can now edit the report templates is going to be a great thing.
We take in around 750 million logs a day. We have a lot of products and that would be a lot of different panes of glass that we would have to look through otherwise. By centralizing, we can triage and take steps much more quickly than if we tried to man that many interfaces that come with the products.
It allows us to automate a lot of things with a smaller team.
It has helped us centralize and have better visibility into devices on our network. We are better able to respond to threats in a timely manner.
It has centralized monitoring for our security operations. Therefore, it improves our analysts' work.