No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs Palo Alto Networks AutoFocus comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Log Management (14th), Security Information and Event Management (SIEM) (14th)
Palo Alto Networks AutoFocus
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
7
Ranking in other categories
Threat Intelligence Platforms (TIP) (21st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. LogRhythm SIEM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.6%, down 3.1% compared to last year.
Palo Alto Networks AutoFocus, on the other hand, focuses on Threat Intelligence Platforms (TIP), holds 1.3% mindshare, up 1.1% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.6%
Splunk Enterprise Security7.6%
IBM Security QRadar5.5%
Other84.3%
Security Information and Event Management (SIEM)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks AutoFocus1.3%
Recorded Future6.4%
CrowdStrike Falcon4.4%
Other87.9%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

SumitKumar20 - PeerSpot reviewer
Security Engineer at Granicus Inc.
Tool consistently aids in effective threat detection and monitoring but could benefit from improved log source management and resource optimization
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments. This information is crucial for planning future storage needs and scalability. The system monitor (collector) agent has issues with resource consumption. Even when not actively collecting data, the agent continues to consume significant CPU and memory resources, which can be particularly problematic for small business environments with limited resources. LogRhythm SIEM could improve by adding more default device support. While they have good default settings for devices such as Palo Alto firewalls, custom log sources often require extensive work. Increasing the number of supported devices with built-in policies and functionality would reduce the need for custom work. Competitive SIEM tools often provide more comprehensive coverage for various devices and vendors.
Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Seamless integration into existing ecosystem empowers effective threat detection
The most valuable feature of Palo Alto Networks AutoFocus is its seamless integration into the Palo Alto Networks ecosystem, allowing the threat intelligence feeds to be automatically consumed without manual effort. It uses the STIX format, which is automatically understood by the firewalls. AutoFocus also excels in behavioral analytics and reputation scoring, providing thorough threat analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It seems like it will scale easily with the way our environment is set up."
"Technical support has always been helpful."
"The scalability is very good."
"Straight away it was fairly evident that the LogRhythm application itself, and the agent roll-out, was straight out of the box."
"The dashboards in the LogRhythm SIEM really help us as a starting point. It gives us a starting point we can go to every day. We walk through several dashboards to see anomalous activity for further investigation."
"LogRhythm has been really a good partner, they've reached out, they're always wanting information, "How we can improve? How can we do this or that?""
"Mostly for us the most valuable feature is its aggregation of all the logs into a single platform, and then doing the real-time monitoring based on that."
"Its ability to work with all different sorts of log sources has been extremely valuable."
"I would rate Palo Alto Networks AutoFocus a ten out of ten."
"It is very easy to install and set up AutoFocus."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"The feature that I like best is the dashboard."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
"The most valuable feature is alerting."
"The logs play a crucial role as they contribute to blocking unwanted Internet traffic."
"It's a very good solution, it identifies critical attacks and alerts you."
 

Cons

"Scalability-wise, it's not that great."
"I would really like to see some type of group or global management for RIM policies,"
"Their ticketing system for managing cases can be improved. The current system works and gets the job done, but it is very bare-bones and basic."
"The main challenge with setting up LogRhythm is you cannot just put LogRhythm in and let it run."
"Right now there is the concern about being able to gather all of the data into the system."
"Just integration into our ticketing system, which we're using service now."
"We were having some challenges initially, especially ingesting those standard log sources. We ran into issues where it was not parsing correctly."
"Sometimes, the tool fails to get the correlated events that triggered the alerts."
"There were one or two instances where firewalls were not getting the threat intelligence feeds."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"Palo Alto Networks AutoFocus is not affordable."
"It must be on-premises as well; it must have a server on-premises. It is a completely cloud-based product at present."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
"It would be helpful to have better documentation for configuring and installing the solution."
 

Pricing and Cost Advice

"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"It is a very cost-effective solution."
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"LogRhythm's pricing and licensing is extremely competitive and it's one of the top three reasons we continue to invest in the platform."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"The product is inexpensive than other tools."
"The setup and licensing for small and medium size businesses is straightforward, though when it comes to the enterprise it pays to keep in mind the possibility for complications given all the extras and add-ons that may be required."
"I give the price a six out of ten."
"The solution is reasonably priced."
"It is expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
9%
Outsourcing Company
8%
Comms Service Provider
7%
Performing Arts
14%
Outsourcing Company
10%
Manufacturing Company
10%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
By reviewers
Company SizeCount
Small Business5
Large Enterprise4
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
What needs improvement with Palo Alto Networks AutoFocus?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed Service feature, which is still not available with Palo Alto. The MDR feature i...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself. I use the threat data correlation feature, which correlates with Cortex. We can use it for data corre...
What advice do you have for others considering Palo Alto Networks AutoFocus?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager. I confirm that we will publish these reviews on peerspot.com in written or audio format...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
Palo Alto Threat Intelligence Management
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Telkom Indonesia
Find out what your peers are saying about Splunk, IBM, Wazuh and others in Security Information and Event Management (SIEM). Updated: August 2026.
908,800 professionals have used our research since 2012.