No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs Palo Alto Networks AutoFocus comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Log Management (11th), Security Information and Event Management (SIEM) (13th)
Palo Alto Networks AutoFocus
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
7
Ranking in other categories
Threat Intelligence Platforms (TIP) (20th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. LogRhythm SIEM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.7%, down 3.3% compared to last year.
Palo Alto Networks AutoFocus, on the other hand, focuses on Threat Intelligence Platforms (TIP), holds 1.4% mindshare, up 1.3% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.7%
Splunk Enterprise Security7.8%
IBM Security QRadar5.6%
Other83.9%
Security Information and Event Management (SIEM)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks AutoFocus1.4%
Recorded Future6.1%
Anomali3.9%
Other88.6%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

RS
Engineer Information Security at N-Able (Pvt) Ltd
Advanced threat detection has improved investigations but complexity and resource use need refinement
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat better and more matured in Wazuh compared to LogRhythm SIEM. Additionally, the parsers that I write for LogRhythm SIEM tend to get quite complex for log parsing, while with Wazuh, I can achieve a similar parser with much less complexity. Those are some of the pain points that some of our customers have been expressing. If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity. Therefore, they have been moved to Wazuh, which I am deploying for them. Even though LogRhythm SIEM has extremely good capabilities, their resource utilization is too heavy for certain customers, so if they could make a separate, lightweight version, that would be quite beneficial.
Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Seamless integration into existing ecosystem empowers effective threat detection
The most valuable feature of Palo Alto Networks AutoFocus is its seamless integration into the Palo Alto Networks ecosystem, allowing the threat intelligence feeds to be automatically consumed without manual effort. It uses the STIX format, which is automatically understood by the firewalls. AutoFocus also excels in behavioral analytics and reputation scoring, providing thorough threat analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The customer service team is excellent and they have resolved anything we have thrown at them in a timely fashion."
"Its ability to work with all different sorts of log sources has been extremely valuable."
"We have seen a massive increase in the amount of data that we can collect, the type of things that we can see, the way we can look at logs, the way we can get alerts, and the way can create our own customer roles, which has allowed us to customize the work in our environment."
"The Web Console is my favorite. It enables me, at a glance, to see the health of the environments."
"The security operation center is excellent, and we can pick logs from any system, not only the IPS or firewall."
"LogRhythm has shown to us, to this point in time, that it has the capabilities of being able to deliver actionable intelligence to the security engineers and analysts."
"LogRhythm SIEM gives us a sense of confidence that, during an investigation, it's a solid source of information that we can use to complement the investigation or perhaps complete the entire investigation within the SIEM."
"Automations are very valuable. It provides the ability to automate some of our small use cases. The ability to integrate with other products that use an API is also very useful. LogRhythm has a plugin for it that we can connect and start to move down towards the path of a single pane of glass instead of having multiple or different tools."
"It is very easy to install and set up AutoFocus."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
"The most valuable feature is alerting."
"It's a very good solution, it identifies critical attacks and alerts you."
"Palo Alto Networks AutoFocus has had a positive impact on my company as we can reduce the cost for the SOC investment, and we can also get good feedback on how to strengthen our network from the expertise people available."
"I would rate Palo Alto Networks AutoFocus a ten out of ten."
"The feature that I like best is the dashboard."
 

Cons

"We have run into problems with stability going through upgrade processes. Recently, we have been on the front edge of the upgrade path. When that happens we tend to run into issues either with certain functionality not working after the upgrades or stability issues because of the upgrades."
"At times it gets a little clunky, or resource-intensive, but it works."
"The main area of improvement is that the client must be installed on the computer for all of the functions to work."
"The initial setup is complex and I rate it a six out of ten."
"Better knowledge transfer during implementation. We definitely thought it was complex when we initially set it up, but that is usually just a single pain problem."
"Report-building is in Crystal Reports and has a limitation."
"If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically."
"For our market, the solution is quite expensive."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"Palo Alto Networks AutoFocus is not affordable."
"It must be on-premises as well; it must have a server on-premises. It is a completely cloud-based product at present."
"It would be helpful to have better documentation for configuring and installing the solution."
"There were one or two instances where firewalls were not getting the threat intelligence feeds."
 

Pricing and Cost Advice

"I would recommend talking to the rep. That's the biggest thing because they will know what questions to ask."
"The support which allows more customized to the environment when we are deploying new systems is called Professional Service and is very expensive. The technical annual support and there is an annual fee."
"The nice thing about LogRhythm is you can either use the agents, getting a certain number of agents with your license depending on how you want to go, and those agents do a lot of cool things, or you can use CIS Log host, then you have like an unlimited number of them."
"In the context of our country, the price of this solution is too high."
"I would rate the tool's pricing around eight out of ten."
"On a scale of one to ten, where one is low, and ten is high, I rate the pricing between six and seven."
"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"It is expensive."
"The solution is reasonably priced."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Outsourcing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Performing Arts
14%
Outsourcing Company
11%
Manufacturing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
By reviewers
Company SizeCount
Small Business5
Large Enterprise4
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
What needs improvement with Palo Alto Networks AutoFocus?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed Service feature, which is still not available with Palo Alto. The MDR feature i...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself. I use the threat data correlation feature, which correlates with Cortex. We can use it for data corre...
What advice do you have for others considering Palo Alto Networks AutoFocus?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager. I confirm that we will publish these reviews on peerspot.com in written or audio format...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
Palo Alto Threat Intelligence Management
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Telkom Indonesia
Find out what your peers are saying about Splunk, IBM, Microsoft and others in Security Information and Event Management (SIEM). Updated: September 2026.
913,683 professionals have used our research since 2012.