

LogRhythm SIEM and Amazon CloudWatch cater to security and infrastructure monitoring, respectively. LogRhythm SIEM takes the lead in security analysis and compliance reporting, while Amazon CloudWatch excels in real-time monitoring within the AWS ecosystem.
Features: LogRhythm SIEM is known for comprehensive security monitoring, ease of use, and an intuitive web interface for centralized log management. Its strengths lie in security analysis and compliance reporting. Amazon CloudWatch is integrated within AWS, providing robust real-time monitoring of AWS resources with detailed metrics and seamless AWS service integration.
Room for Improvement: LogRhythm SIEM users suggest improvements in the complexity of customization and template configurations, along with better integration with diverse log sources. Amazon CloudWatch could enhance its dashboard visualization, third-party integration support, and expand its monitoring features beyond core AWS services.
Ease of Deployment and Customer Service: LogRhythm SIEM is usually deployed on-premises, which some find complex, but it is supported by responsive and knowledgeable customer support. Amazon CloudWatch is mostly deployed in the cloud, benefiting from easy setup and management within AWS, although flexibility in customer service is noted as lacking.
Pricing and ROI: LogRhythm SIEM is often seen as a more expensive solution with complex licensing based on log volume, justified by its strong feature set for larger enterprises. In contrast, Amazon CloudWatch offers cost-effective pay-as-you-go pricing within AWS, but costs can increase with data usage. It is considered affordable relative to the insights it provides.
Amazon CloudWatch offers cost-saving advantages by being an inbuilt solution that requires no separate setup or maintenance for monitoring tasks.
In recent years, due to business expansion, knowledge levels among support engineers seem to vary.
While using their cloud and cloud resources, if you have an issue with CloudWatch, you must pay additional monthly fees to get time from dedicated tech support.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
LogRhythm SIEM is quite complex, but that complexity allows us to specifically tailor a solution to the customer while some others are not as flexible.
Customer support is very helpful and effectively solves my problems.
It is already there as a managed service from AWS.
Amazon CloudWatch's scalability is managed by AWS.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
I sometimes notice slowness when Amazon CloudWatch agents are installed on machines with less capacity, causing me to use other monitoring tools.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
When using third-party dashboards such as Kibana or Grafana and other visualization tools, there should be a way to feed CloudWatch's data and logging capabilities into these visualization tools.
We are in a process of integrating Grafana, Loki, and Prometheus to have better visualization on Amazon CloudWatch.
Maybe Amazon Web Services can improve by providing a library for CloudWatch with some useful features.
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity.
Overall, the pricing of Amazon CloudWatch is very expensive.
Amazon CloudWatch charges more for custom metrics as well as for changes in the timeline.
The license cost is around $10 per MPS.
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
Amazon CloudWatch allows me to set up and view even historical logs, which is one of the features I find valuable.
If there is a CPU spike or system issues, we set alarms to notify us if the system is going down or not reachable.
I like its filtering capability and its ability to give the cyber engine insights.
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
| Product | Mindshare (%) |
|---|---|
| LogRhythm SIEM | 2.8% |
| Amazon CloudWatch | 1.6% |
| Other | 95.6% |

| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 9 |
| Large Enterprise | 24 |
| Company Size | Count |
|---|---|
| Small Business | 38 |
| Midsize Enterprise | 39 |
| Large Enterprise | 83 |
Amazon CloudWatch integrates seamlessly with AWS, providing real-time monitoring and alerting features. Its interface supports task automation, enhancing troubleshooting and analytics capabilities, while offering strong security and scalability at a cost-effective rate.
Amazon CloudWatch is an impactful platform for monitoring AWS resources and managing application performance. It simplifies infrastructure performance monitoring by providing comprehensive analytics capabilities, including application insights and event scheduling. Users appreciate CloudWatch for its detailed metrics, dashboards, and support in issuing alerts to detect anomalies. It efficiently tracks performance, optimizes resource utilization, and ensures service availability. CloudWatch is recognized for its robust alerting features and integration with other AWS services, further supporting its resource monitoring capabilities. However, there is room for improvement in dashboard customization, log streaming speed, and integration with non-AWS services. Enhancements in API integration, machine learning features, and support for third-party tools are also desired.
What features does Amazon CloudWatch offer?Industries implementing Amazon CloudWatch often focus on optimizing IT infrastructure. Companies in sectors like finance and e-commerce rely on its monitoring and alerting capabilities to ensure service uptime and performance. The platform's automation and analytics features empower teams to proactively manage performance and detect potential issues promptly.
LogRhythm SIEM offers advanced threat intelligence, scalable deployment, and streamlined log management. It enhances security posture with AI-driven threat detection and comprehensive monitoring.
LogRhythm SIEM stands out for its AI-driven threat correlation, ease of log aggregation, and robust reporting. Offering real-time visibility and analytics through consistent navigation and dashboards, it integrates with security components for enhanced monitoring and response. Advanced threat intelligence and customizable alerts streamline processes and bolster security. While it faces challenges with log parsing, reporting, and dashboard intuitiveness, plans to enhance cloud integration and transition to Linux are noted.
What are the standout features?In industries like banking and finance, organizations utilize LogRhythm SIEM for centralized log management, security monitoring, and compliance. It helps detect insider threats, analyze server logs, correlate events, and monitor user behaviors. Appreciated for log ingestion and anomaly identification, it ensures robust cybersecurity and incident response by integrating data from multiple sources.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.