What is our primary use case?
We use LogRhythm NetworkXDR to correlate the data with the SIEM dashboards. The product correlates all the data from the systems and machines, for example, the firewalls, the switches, and other Windows machines, then it generates logs from the application security system. All the logs from machines can be correlated and will show the type of clouds populated, so from there comes an auto-response to block the IPs over the firewall if IPs have issues.
Another good use case that we create after office hours is that if anyone logs in, alarms are generated, so it's a custom use case where clients are alerted of incidents via email. Daily, we can send incident responses for the clients to check and we can make their environment more secure through LogRhythm NetworkXDR.
What is most valuable?
What we like most in LogRhythm NetworkXDR is its GUI. The GUI is the best when compared to competitors. For example, there is another SIEM in QRadar and Splunk, and for open source SIEM there is Wazuh and there are other SIEM solutions, but LogRhythm NetworkXDR is more reliable and easier to access. It's easy to use and its display is easy to understand. Learning LogRhythm NetworkXDR is smooth sailing compared to other SIEM solutions.
What needs improvement?
What would make LogRhythm NetworkXDR better is if they could run it open source, similar to what is being done in Wazuh, and Wazuh is also a good tool to compare against. More integration could also make LogRhythm NetworkXDR better.
For how long have I used the solution?
We've been providing LogRhythm NetworkXDR for four years now.
What do I think about the stability of the solution?
LogRhythm NetworkXDR is a stable product.
What do I think about the scalability of the solution?
LogRhythm NetworkXDR is a scalable product, and I'm marking its scalability a ten out of ten.
How are customer service and support?
The technical support for LogRhythm NetworkXDR is fine, and there's nothing that needs to be changed in it.
How was the initial setup?
LogRhythm NetworkXDR has a straightforward installation, though it's a combination of our team and the client installing and deploying it because we're both required to validate the IDs for smooth communication with the IPs. It would take just a few minutes to deploy if the software has been installed in the client side.
What's my experience with pricing, setup cost, and licensing?
My team has no information on the licensing cost for LogRhythm NetworkXDR because it's the account manager from the sales team who deals with licensing.
Which other solutions did I evaluate?
We evaluated Qradar, Splunk, and Wazuh.
What other advice do I have?
My company has been providing LogRhythm NetworkXDR to clients.
There are ten clients using LogRhythm NetworkXDR currently. For deployment and maintenance, there are fifteen people managing the product twenty four by seven.
My rating for LogRhythm NetworkXDR is ten out of ten.
I'm recommending LogRhythm NetworkXDR to anyone I come across, especially because my rating for it is a ten out of ten.