Try our new research platform with insights from 80,000+ expert users

Grafana Loki vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Grafana Loki
Ranking in Log Management
3rd
Average Rating
8.2
Reviews Sentiment
7.8
Number of Reviews
18
Ranking in other categories
No ranking in other categories
LogRhythm SIEM
Ranking in Log Management
13th
Average Rating
8.4
Reviews Sentiment
6.4
Number of Reviews
175
Ranking in other categories
Security Information and Event Management (SIEM) (8th)
 

Mindshare comparison

As of October 2025, in the Log Management category, the mindshare of Grafana Loki is 7.9%, up from 6.5% compared to the previous year. The mindshare of LogRhythm SIEM is 2.3%, down from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Market Share Distribution
ProductMarket Share (%)
Grafana Loki7.9%
LogRhythm SIEM2.3%
Other89.8%
Log Management
 

Featured Reviews

Volodymyr Bondarchuk - PeerSpot reviewer
Integrations enhance monitoring but problem-solving proves challenging
Different types of integrations with various sources are the most helpful and useful features of Grafana Loki that I found for myself. As part of Kubernetes technology, I noticed benefits from using this product such as availability, configuration balancing, high availability solutions for high performance, and failover clustering. It provides a clear picture about the state of the system and gives needed information for taking action and quickly fixing problems.
SumitKumar20 - PeerSpot reviewer
Tool consistently aids in effective threat detection and monitoring but could benefit from improved log source management and resource optimization
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments. This information is crucial for planning future storage needs and scalability. The system monitor (collector) agent has issues with resource consumption. Even when not actively collecting data, the agent continues to consume significant CPU and memory resources, which can be particularly problematic for small business environments with limited resources. LogRhythm SIEM could improve by adding more default device support. While they have good default settings for devices such as Palo Alto firewalls, custom log sources often require extensive work. Increasing the number of supported devices with built-in policies and functionality would reduce the need for custom work. Competitive SIEM tools often provide more comprehensive coverage for various devices and vendors.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable part of Loki is the ability to filter logs by keywords and devices."
"I appreciate the capability to process logs from microservices and seamlessly integrate them into Grafana."
"Grafana Loki is easy to monitor and detect errors."
"We are using Grafana Loki as a database for real-time metrics."
"There are new features like that pilot code and things like that for profiling."
"Grafana agent is very lightweight and does not cost significant resources of our cluster."
"The best feature of Grafana Loki is that it integrates well with our other tool."
"The log collection feature is good and the solution is easily understandable. v"
"The product is great for medium to large-scale organizations."
"The initial setup process is very user-friendly."
"SOAR is integrated with the dashboard that we use for threat management. Because it's all integrated, it is useful for us when we deploy something on-prem."
"I see LogRhythm SIEM as value for money; I would rate it eight out of ten."
"It's reliable and the performance is good."
"I would say the most valuable feature of LogRhythm is that it has built-in UEBA functionality, among other basic Windows packages."
"I find LogRhythm's log management capabilities to be beneficial."
"LogRhythm's dashboard is very good compared to other SIEM solutions since it shows many details."
 

Cons

"There is a need for some change in the alerting types of the product. In short, a few changes in the alert area are needed due to minor shortcomings."
"In Grafana Loki, the creation of metrics is not so easy, making it an area that could be made easier."
"The solution has shortcomings regarding security monitoring-oriented features that need improvement."
"My main concern is the recommended production-grade setup. They suggest using tools like Tanka or Jsonnet. They should simplify the process to increase adoption."
"I would rate Grafana Loki a seven out of ten because it is open source, and sometimes there can be problems that are difficult to fix without official support."
"The correlation of requests is not simple in Grafana Loki and can be improved."
"Enhancing speed could be a game-changer, and while it might vary depending on the application, it's a factor worth exploring."
"The solution's scalability depends on the team managing the Grafana instance."
"It will definitely help if the parsing side would be much easier, meaning it would be better if we could easily make adjustments on the parser, both on standard and non-standard log sources."
"I would like to suggest that they should improve their usage of third party tools for making dashboards and reports. If they would create their own tools for dashboard and report, it would be much better in terms of security purposes."
"It should have some more message monitoring features. It can also have some free message monitoring tools."
"There is room for improvement with separate running sources or better integration."
"LogRhythm NextGen SIEM could improve by adding more applications for the banking sector. There are not any custom applications at this time."
"Move it to Linux. I would like to see it get off the SQL Server."
"LogRhythm NextGen SIEM is currently based only on the Windows platform. This means that some of our customers have to purchase a Windows license elsewhere. If LogRhythm can move to a Linux platform or a proprietary platform, it would be very helpful."
"One thing we have mentioned to them before is that we'd like to be able to do searches, or drill-downs, directly from an alarm. When you click it and the Inspector tab slides out, that might be a good place to be able to click the host to search for the last 24 hours. I know the search is right there but it would be even nicer to just click that and then have an option to search something there."
 

Pricing and Cost Advice

"Grafana Loki is an open-source solution."
"The pricing structure varies based on the number of users; there might be specific taxes to pay for it."
"I use the open-source version of the product."
"My company doesn't need to pay for the licensing cost of the solution."
"I use the solution's open-source version. Grafana Loki is a completely free solution for me."
"Grafana Loki is a free, open-source solution."
"We use a free version."
"Since we are using the open-source version of Grafana Loki, we are not paying anything for the solution."
"We have seen a measurable decrease in the mean time to detect and respond to threats. As it comes out new features and new releases, the window is becoming a lot narrower because you can pivot a lot more with the data. Therefore, the new features and enhancements are reducing that."
"Everything is expensive with LogRhythm, and you don't get anything for free."
"I give the price a six out of ten."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"In the context of our country, the price of this solution is too high."
"I would rate the pricing 4 out of 5. There are no additional costs to the standard licensing fees."
"I would recommend talking to the rep. That's the biggest thing because they will know what questions to ask."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
868,759 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Comms Service Provider
10%
Financial Services Firm
10%
Manufacturing Company
9%
Computer Software Company
13%
Government
10%
Manufacturing Company
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise8
Large Enterprise3
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise38
Large Enterprise83
 

Questions from the Community

What do you like most about Grafana Loki?
We are using Grafana Loki as a database for real-time metrics.
What is your experience regarding pricing and costs for Grafana Loki?
Since it is an open source tool, there are no charges or fees.
What needs improvement with Grafana Loki?
I have no ideas at this moment about what could be improved in Grafana Loki.
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
 

Also Known As

No data available
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

Information Not Available
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about Grafana Loki vs. LogRhythm SIEM and other solutions. Updated: September 2025.
868,759 professionals have used our research since 2012.