No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Observability vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Observability
Ranking in Log Management
23rd
Average Rating
8.0
Reviews Sentiment
4.9
Number of Reviews
8
Ranking in other categories
No ranking in other categories
LogRhythm SIEM
Ranking in Log Management
14th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Security Information and Event Management (SIEM) (14th)
 

Mindshare comparison

As of August 2026, in the Log Management category, the mindshare of CrowdStrike Observability is 0.8%, up from 0.5% compared to the previous year. The mindshare of LogRhythm SIEM is 3.1%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM3.1%
CrowdStrike Observability0.8%
Other96.1%
Log Management
 

Featured Reviews

HectorRios - PeerSpot reviewer
IT COMMUNICATIONS AND NETWORKS at Américas BPS
Has provided reliable alerts and helped identify infrastructure issues through detailed reporting
The best features of CrowdStrike Observability include the way they show issues to the client or agent, and their data collection method is interesting because they use an agent-less approach in some cases, collecting data from infrastructure such as firewalls. Additionally, they have the agent, but the presentation in the management console is excellent as we have observability end-to-end with the servers and all the services configured in the use cases. The intelligent alerting feature is excellent and configured on our console, being highly effective as it detects real alerts and just warnings or real issues. Identifying performance bottlenecks is important because they collect numerous MD5 or hash keys including movements or playbooks. The way they organize that in the console is excellent, allowing you to have reports detecting issues, which not only includes detection but also provides solutions to those issues.
SumitKumar20 - PeerSpot reviewer
Security Engineer at Granicus Inc.
Tool consistently aids in effective threat detection and monitoring but could benefit from improved log source management and resource optimization
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments. This information is crucial for planning future storage needs and scalability. The system monitor (collector) agent has issues with resource consumption. Even when not actively collecting data, the agent continues to consume significant CPU and memory resources, which can be particularly problematic for small business environments with limited resources. LogRhythm SIEM could improve by adding more default device support. While they have good default settings for devices such as Palo Alto firewalls, custom log sources often require extensive work. Increasing the number of supported devices with built-in policies and functionality would reduce the need for custom work. Competitive SIEM tools often provide more comprehensive coverage for various devices and vendors.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The price is worth it."
"CrowdStrike Observability offers strong predictive analytics capabilities, and the intelligent alerting system helps minimize noise and optimize IT resources effectively."
"I find the most effective feature of CrowdStrike Observability to be its cloud vision and attack surface vision, which enhance network traffic analysis."
"The intelligence database provided by CrowdStrike is very impressive."
"CrowdStrike Observability is a signature-less solution where you don't need to update your endpoints or the CrowdStrike Observability agents regularly, and it is completely based on AI and ML search engines."
"The log aggregation and correlation of data are notable features that enhance our operations."
"The dashboard and user interface of CrowdStrike Observability are quite good, and the support is responsive."
"The intelligent alerting feature is excellent and configured on our console, being highly effective as it detects real alerts and just warnings or real issues."
"It's definitely given us a lot of visibility into areas that we probably wouldn't have normal visibility into, such as code execution and things like that."
"So far we're pretty happy with the overall functionality of the system."
"From a security standpoint, it's the solution to have, in regards to LogRhythm."
"We should be able to response to threats and gain visibility into our environment that we don't currently have."
"Being able to see when one of our assets is down and being able to restart it really quickly has been a definite benefit."
"The most valuable part of the solution is being to view all of the logs whenever you want."
"The dashboards in the LogRhythm SIEM really help us as a starting point. It gives us a starting point we can go to every day. We walk through several dashboards to see anomalous activity for further investigation."
"Support after implementation is probably the biggest."
 

Cons

"For reporting or log management, having a longer duration for backup without needing to purchase a paid subscription would be beneficial. Currently, there is a default ninety-day backup period."
"Integration with Huawei should be more straightforward."
"The pricing is very high and small companies cannot afford it. They should reduce the price because the backend infrastructure is the same."
"The customer service is not satisfactory for me. The support is only available in English, and my users in LATAM regions such as Peru and Colombia require local language support, which is not currently provided."
"The areas of CrowdStrike Observability that have room for improvement include the approach towards customer issues, where resolution takes time."
"We had some difficulties at the beginning, but at this moment they are improving, so probably in some months I will give them a ten."
"Technical support received a rating of 4 out of 10."
"From the different deployments I have worked with, the shortcomings of CrowdStrike Observability are often because of what clients are able to share with CrowdStrike."
"My biggest challenge always come back to log sources."
"After a year-and-a-half, we're not stable yet. Every time we think we're stable for a week or two, we wake up the next morning to another million logs backlogged somewhere."
"I would like to see our vulnerabilities counter. We will be using Tenable to fill that void right now."
"In the canned reports, I would like to see, rather than a blank report come out, for it to say something like, "No logs found," or "No log sources available." I don’t like blank reports."
"In terms of the product, what really needs to improve are the metrics that you can get from it."
"The reporting on the dashboard should be improved from a management perspective. It would be helpful if they adjusted the colors and the presentation to make things clearer and easier to read."
"We don't get much use out of this product because people around here consider it to be unreliable, and it's hard to do searches."
"If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically."
 

Pricing and Cost Advice

Information not available
"Look closely at the cost of licensing of other products. This should include setups and the need for support services. I did a RFQ to 2 other vendors before choosing this product."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"NextGen SIEM's pricing is moderate."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"In comparison to the competition, they are more affordable. This allows us to do more with less."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"I would rate the pricing 4 out of 5. There are no additional costs to the standard licensing fees."
"I would recommend talking to the rep. That's the biggest thing because they will know what questions to ask."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Construction Company
13%
Financial Services Firm
12%
Outsourcing Company
6%
Construction Company
13%
Financial Services Firm
9%
Outsourcing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise3
Large Enterprise3
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
 

Questions from the Community

What needs improvement with CrowdStrike Observability?
From the different deployments I have worked with, the shortcomings of CrowdStrike Observability are often because of what clients are able to share with CrowdStrike. If there are limitations in wh...
What is your primary use case for CrowdStrike Observability?
We are currently using a complete suite of anti-malware software and other security products in our company. I have worked with both the on-premises version and the cloud version, but I am more fam...
What advice do you have for others considering CrowdStrike Observability?
I am probably familiar with CrowdStrike Observability. I first heard of CrowdStrike Observability a couple of years ago, and I only really started looking into it about a year ago. I cannot comment...
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
 

Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

Information Not Available
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about CrowdStrike Observability vs. LogRhythm SIEM and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.