

LogRhythm SIEM and USM Anywhere compete in the SIEM category. LogRhythm SIEM holds the upper hand due to its advanced user behavior analytics and customizable dashboards, providing an advantage in complex threat environments.
Features: LogRhythm SIEM offers advanced intelligence for threat detection, user behavior analytics, and comprehensive log management. Its dashboards and drill-down capabilities are highly efficient. USM Anywhere provides integrated vulnerability assessment, centralized logging, and extensive network visibility, simplifying the setup process.
Room for Improvement: LogRhythm SIEM can improve in automation, alarm management, and reporting. It faces challenges with log parsing and third-party integrations requiring a more user-friendly interface. USM Anywhere needs better threat intelligence integration, faster search speeds, and improvements in alert customization and the correlation engine.
Ease of Deployment and Customer Service: LogRhythm SIEM suits on-premise deployments with support for private clouds, earning praise for customer service quality, though with varied expertise. USM Anywhere simplifies cloud-based deployments, appealing to organizations with limited resources, despite some variability in customer service experiences.
Pricing and ROI: LogRhythm SIEM is considered expensive, often requiring professional services, but offers long-term affordability advantages through perpetual licensing. It suits medium-sized organizations seeking comprehensive solutions. USM Anywhere's competitive pricing is more suitable for smaller networks or moderate budgets, providing robust SIEM features. Both deliver ROI through security improvements, with LogRhythm's higher initial investment appealing to large organizations needing extensive features, whereas USM Anywhere offers a balanced cost-sensitive solution.
Customers see ROI as they save on staff and other resources.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
The automated responses and detections of LogRhythm SIEM are much better and faster compared to others.
Customer support is very helpful and effectively solves my problems.
USM Anywhere faces scalability issues because of a 60 TB limit.
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks.
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity.
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
The pricing is amazing and really cheap.
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
The license cost is around $10 per MPS.
The 365-day block query is a major feature.
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
| Product | Mindshare (%) |
|---|---|
| LogRhythm SIEM | 2.7% |
| USM Anywhere | 1.5% |
| Other | 95.8% |

| Company Size | Count |
|---|---|
| Small Business | 65 |
| Midsize Enterprise | 29 |
| Large Enterprise | 25 |
| Company Size | Count |
|---|---|
| Small Business | 38 |
| Midsize Enterprise | 39 |
| Large Enterprise | 83 |
USM Anywhere provides centralized logging, vulnerability scanning, and real-time event correlation, enhancing cybersecurity management and compliance with standards like PCI DSS and ISO 27001. It integrates smoothly with third-party applications and offers diverse, flexible deployment options.
USM Anywhere stands out for its integrated network and host IDS, asset management, and intuitive deployment that enhances efficiency. The platform simplifies security tasks by offering a comprehensive view that aids in compliance and aligns with security regulations such as PCI and GDPR. Despite its strengths, areas like IPv6 support, custom rule creation, and reporting require attention. Users note awkward reporting features and limited integration options. Enhancements are needed in threat detection and vulnerability scanning for faster response times and better support.
What are the key features of USM Anywhere?
What benefits and ROI can users expect?
In industries such as cloud services and enterprise security, USM Anywhere is used extensively for SIEM, managing logs, and detecting security incidents. It supports AWS environment monitoring, providing managed services to clients and facilitating compliance with standards like PCI and GDPR.
LogRhythm SIEM offers advanced threat intelligence, scalable deployment, and streamlined log management. It enhances security posture with AI-driven threat detection and comprehensive monitoring.
LogRhythm SIEM stands out for its AI-driven threat correlation, ease of log aggregation, and robust reporting. Offering real-time visibility and analytics through consistent navigation and dashboards, it integrates with security components for enhanced monitoring and response. Advanced threat intelligence and customizable alerts streamline processes and bolster security. While it faces challenges with log parsing, reporting, and dashboard intuitiveness, plans to enhance cloud integration and transition to Linux are noted.
What are the standout features?In industries like banking and finance, organizations utilize LogRhythm SIEM for centralized log management, security monitoring, and compliance. It helps detect insider threats, analyze server logs, correlate events, and monitor user behaviors. Appreciated for log ingestion and anomaly identification, it ensures robust cybersecurity and incident response by integrating data from multiple sources.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.