No more typing reviews! Try our Samantha, our new voice AI agent.

LogRhythm SIEM vs RSA enVision comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm SIEM
Ranking in Security Information and Event Management (SIEM)
13th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
176
Ranking in other categories
Log Management (11th)
RSA enVision
Ranking in Security Information and Event Management (SIEM)
50th
Average Rating
7.2
Reviews Sentiment
6.7
Number of Reviews
6
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of LogRhythm SIEM is 2.7%, down from 3.3% compared to the previous year. The mindshare of RSA enVision is 0.8%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
LogRhythm SIEM2.7%
RSA enVision0.8%
Other96.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

RS
Engineer Information Security at N-Able (Pvt) Ltd
Advanced threat detection has improved investigations but complexity and resource use need refinement
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat better and more matured in Wazuh compared to LogRhythm SIEM. Additionally, the parsers that I write for LogRhythm SIEM tend to get quite complex for log parsing, while with Wazuh, I can achieve a similar parser with much less complexity. Those are some of the pain points that some of our customers have been expressing. If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity. Therefore, they have been moved to Wazuh, which I am deploying for them. Even though LogRhythm SIEM has extremely good capabilities, their resource utilization is too heavy for certain customers, so if they could make a separate, lightweight version, that would be quite beneficial.
SF
Président at ARS Solutions
Support both French and English, which is important for us and adapted to the evolving security landscape over time in my experience
You need a skilled engineer to deploy it because you can do anything with this tool. You can see everything on the network. A good engineer will be surprised and have fun using this tool because it's very powerful. Deployment process: You need to build a recipe/layout when you want to deploy something. Once the recipe is done, you just have to copy it. So you really need a good engineer at first, but then any other technician can copy the recipe. You don't need to be an expert once the recipe is finalized. So, once you have it set up, it's easy to deploy. But you need a good engineer to deploy it correctly. You will get alerts from the system, but if you want to fully explore and maximize the tool, the engineering needs are different.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For what it does, LogRhythm works pretty well."
"We looked at LogRhythm, and LogRhythm seemed to have a lot of the stuff built in, canned already."
"The user interface is pretty good compared to other SIEM tools."
"It makes it possible to stay aware of much more of what's going on; we get an overview, a macro view that we can zoom in on as opposed to prior to that when we had individual panes of glass and might be stuck in the firewall interface for half a day while something going on is not getting addressed that we really should probably investigate."
"I am pretty impressed with it."
"It's positively affected our overall rate of efficiency."
"Now it pulls it all into one spot and we're actually able to correlate data and say, "Hey look, this person's really actually being shady," and go from there."
"The most valuable part of the solution is being to view all of the logs whenever you want."
"The most valuable feature is the management features. It's capable of managing large enterprises."
"RSA enVision provides the full system visibility of your events within your IT ecosystem."
"We developed around this solution and received excellent support from the company."
"The ease of log collection and stability of the platform are the most valuable features."
"The most valuable feature of this solution is the reporting."
"The custom dashboard and correlation alerts in this solution improved our incident response process."
"The configuration part is very easy...The technical support was sincere in their responses...I rate the technical support a nine out of ten."
 

Cons

"I do think there is room for improvement because the system is still running on the Windows Server platform. The problem with running on Windows is that it is not that good for scaling and providing for big deployment environments."
"I have had a lot of trouble with stability, perfect timing."
"Scalability-wise, it's not that great, but integration with other solutions is pretty easy."
"Right now there is the concern about being able to gather all of the data into the system."
"For me it would be the efficiency and signing up and standing up systems, as well as a little bit cleaner on case management."
"A month or two will go by and everything will be fine, and all of a sudden, something breaks."
"The system monitor (collector) agent has issues with resource consumption. Even when not actively collecting data, the agent continues to consume significant CPU and memory resources, which can be particularly problematic for small business environments with limited resources."
"Easier creation of rules and parsing, and more user-friendly."
"Licensing could be improved to be more oriented towards Managed Service Providers (MSPs)."
"Whenever you perform the query, it takes too long."
"The integration could be easier, it should support more products."
"RSA enVision log manager is out of date and is not in use anymore."
"Sometimes the investigation panel and reporting engine work very slowly."
"In general, the solution currently isn't user-friendly."
"There is no future for this solution. It does not exist anymore."
 

Pricing and Cost Advice

"NextGen SIEM's pricing is moderate."
"Look closely at the cost of licensing of other products. This should include setups and the need for support services. I did a RFQ to 2 other vendors before choosing this product."
"I give the price a six out of ten."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"We have seen a measurable decrease in the mean time to detect and respond to threats. As it comes out new features and new releases, the window is becoming a lot narrower because you can pivot a lot more with the data. Therefore, the new features and enhancements are reducing that."
"When it comes time to renew, they say, "This is what you are using. This is what we can do for you." So, they work with you on pricing."
"We work with French-speaking African countries, and it costs more than the average SIEM solution. Also, the pricing isn't too flexible. AlienVault, Splunk, and IBM QRadar are more suitable for customers on a tight budget."
"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"On a scale of one to ten, where one is low, and ten is high price, I rate the pricing a six."
"We no longer pay a licensing fee because it is out of date and don't pay for support."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Outsourcing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Comms Service Provider
15%
Outsourcing Company
14%
Construction Company
13%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise39
Large Enterprise83
No data available
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
LogRhythm SIEM could learn from Wazuh, as Wazuh has a built-in mechanism that allows you to write custom scripting and scripts through languages that Wazuh can then trigger, which is somewhat bette...
What is your experience regarding pricing and costs for LogRhythm SIEM?
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar, although I have not been involved in negotiation charges; however, from the manager's approval, I see it as affordable.
Ask a question
Earn 20 points
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
No data available
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
BPS (SUISSE), Hypovereinsbank Germany, MAX Hamburgers, Infoplex, Neotel, Telus
Find out what your peers are saying about LogRhythm SIEM vs. RSA enVision and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.