

LogRhythm SIEM and Devo offer robust security information and event management solutions. Users favor Devo for its advanced features and overall satisfaction, despite higher pricing.
Features: LogRhythm SIEM is praised for its comprehensive threat detection, response capabilities, and integration flexibility. Devo stands out with strong analytics, scalability, and real-time data processing.
Room for Improvement: LogRhythm SIEM users suggest enhancements in integration flexibility, simpler configuration, and user interface. Devo users note the need for improved documentation, streamlined update processes, and better customer training.
Ease of Deployment and Customer Service: LogRhythm SIEM deployment is considered straightforward but time-consuming, with responsive customer service. Devo's deployment is quick and efficient, with excellent support.
Pricing and ROI: LogRhythm SIEM has lower initial setup costs and satisfactory ROI. Devo, more expensive, is seen as worth the investment due to superior performance and long-term benefits.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
The automated responses and detections of LogRhythm SIEM are much better and faster compared to others.
Customer support is very helpful and effectively solves my problems.
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
Integrations with other sandboxes could be improved to better interpret data using AI and machine learning models.
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity.
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
The license cost is around $10 per MPS.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
| Product | Mindshare (%) |
|---|---|
| LogRhythm SIEM | 2.5% |
| Devo | 1.2% |
| Other | 96.3% |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 4 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 38 |
| Midsize Enterprise | 39 |
| Large Enterprise | 83 |
Devo offers powerful visual analytics, real-time data querying, and log integration capabilities within a cloud-native, multi-tenant architecture, supporting extended data retention ideal for long-term analysis and compliance.
Devo is recognized for its Activeboards, which facilitate visual analytics. High-speed search capabilities and real-time analytics enable efficient data manipulation and querying. Its multi-tenant architecture supports effective data segregation and customization tailored to distinct business needs, enhancing its value for handling complex log integrations. With extended data retention of 400 days and a cloud-native architecture, Devo is a robust platform for long-term analysis and compliance requirements. Though opportunities exist to improve browser stability on large searches, SOAR integrations, and its parser capabilities, Devo remains essential for incident response and security monitoring, offering centralized data storage and analysis.
What are Devo's most important features?Devo is extensively used in industries focused on incident response and digital forensics, centralizing data for security monitoring across hybrid environments. Organizations benefit from its ability to store and analyze aggregated logs, creating alerts and dashboards to enhance visibility for network and endpoint activities in multi-domain settings.
LogRhythm SIEM offers advanced threat intelligence, scalable deployment, and streamlined log management. It enhances security posture with AI-driven threat detection and comprehensive monitoring.
LogRhythm SIEM stands out for its AI-driven threat correlation, ease of log aggregation, and robust reporting. Offering real-time visibility and analytics through consistent navigation and dashboards, it integrates with security components for enhanced monitoring and response. Advanced threat intelligence and customizable alerts streamline processes and bolster security. While it faces challenges with log parsing, reporting, and dashboard intuitiveness, plans to enhance cloud integration and transition to Linux are noted.
What are the standout features?In industries like banking and finance, organizations utilize LogRhythm SIEM for centralized log management, security monitoring, and compliance. It helps detect insider threats, analyze server logs, correlate events, and monitor user behaviors. Appreciated for log ingestion and anomaly identification, it ensures robust cybersecurity and incident response by integrating data from multiple sources.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.