Try our new research platform with insights from 80,000+ expert users

LogRhythm SIEM vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Ranking in Log Management
12th
Ranking in Security Information and Event Management (SIEM)
9th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
No ranking in other categories
NetWitness Platform
Ranking in Log Management
34th
Ranking in Security Information and Event Management (SIEM)
33rd
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Log Management category, the mindshare of LogRhythm SIEM is 2.6%, up from 2.2% compared to the previous year. The mindshare of NetWitness Platform is 0.8%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.6%
NetWitness Platform0.8%
Other96.6%
Log Management
 

Featured Reviews

SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I really like about LogRhythm is that they're always innovating, new ideas."
"LogRhythm was really the first major product that we bought and the installation was awesome; it went as expected, moved along quickly, and provided value as soon as we were done with the installation."
"In general, the visibility of events and advanced analysis of events are good."
"Within three hours of installation of LogRhythm, we were pulling error reports that actually indicated we had a switch about to fail, and it saved us about ten thousand dollars of a potential failed switch."
"The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot."
"We have NetFlow information going into it, so we can examine a lot of traffic patterns and anomalies, especially if something stands out and is not the baseline. This helps a lot."
"As a healthcare company, what we use it for is compliance, then to protect our data from exaltation."
"We have to be able to show the evidence, and LogRhythm does a great job of putting it forward and making it easy to create reports with nice looking dashboards, which show off what we are doing as a security program."
"This solution has a very good dashboard with a separate tab for incidents and alerts."
"The most valuable feature is the correlation. It can report in real-time and monitor the management."
"NetWitness Platform offers flexibility for deployment and robust integration capabilities."
"Once it is deployed and you are used to it, you can do whatever you want."
"Since the solution has been under way we have seen a large decrease of threats and proactive reactions to incidents."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"Their customer service is excellent, one of the best."
"The development of use cases on the SSA console is quite user friendly. This means that the security analyst or the researcher does not have to learn another language."
 

Cons

"Right now there is the concern about being able to gather all of the data into the system."
"Scalability-wise, it's not that great."
"We have run into problems with stability going through upgrade processes. Recently, we have been on the front edge of the upgrade path."
"In the canned reports, I would like to see, rather than a blank report come out, for it to say something like, "No logs found," or "No log sources available." I don’t like blank reports."
"More help and assistance with some of the open source products, everything seems to be focused on Windows versus giving some guidance and some documentation on how to use it."
"There are other security technologies outside of this SIEM that should be inside of this SIEM."
"Granted, we haven't enabled the UEBA module, but we're forwarding all our proxy logs to LogRhythm and we have a really hard time pulling those proxy logs back out of LogRhythm. However, when we take LogRhythm and forward the same logs into somebody else's user-based analytics software, we get the majority of what we were missing... If we've got all our proxy logs and I go out to Google or Facebook or the like, we should be able to go in and pull that information out ten minutes later, but it's a big challenge to do that."
"It should have some more message monitoring features. It can also have some free message monitoring tools."
"An area for improvement would be better automation and more inbuilt use cases."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"The product's licensing models are complex to understand. This particular area needs improvement."
"The initial setup is very complex and should be simplified."
"We have encountered issues with unresolved crashes."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"The initial setup was complex because it took a lot of time to complete the implementation."
 

Pricing and Cost Advice

"The license cost is around $10 per MPS."
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"I would rate the tool's pricing around eight out of ten."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"It is a very cost-effective solution."
"In the context of our country, the price of this solution is too high."
"I would rate the pricing 4 out of 5. There are no additional costs to the standard licensing fees."
"We have seen a measurable decrease in the mean time to detect and respond to threats. As it comes out new features and new releases, the window is becoming a lot narrower because you can pivot a lot more with the data. Therefore, the new features and enhancements are reducing that."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"It’s cheaper to run virtual machines in a VMware environment."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The product is expensive."
"It is cheap."
"We are on an annual license for the use of the solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
8%
Government
7%
Manufacturing Company
7%
Financial Services Firm
11%
Performing Arts
8%
Computer Software Company
7%
Marketing Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise38
Large Enterprise83
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
RSA Security Analytics
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Los Angeles World Airports, Reply
Find out what your peers are saying about LogRhythm SIEM vs. NetWitness Platform and other solutions. Updated: March 2026.
884,933 professionals have used our research since 2012.