Try our new research platform with insights from 80,000+ expert users
it_user341220 - PeerSpot reviewer
Systems Administrator at a financial services firm with 501-1,000 employees
Vendor
We selected it based on the ability to comply with regulations and its advanced features, but support needs to be improved.

What is most valuable?

The log aggregation is what we use it for.

We don’t have a lot of the reporting configured or the advanced analytics. When the time is right, we will we will make the most of these features.

How has it helped my organization?

We need to improve our internal training and use of it. We use it, but we don’t use it to its potential. It’s a very powerful and robust device and application. We don’t use it how we could.

What needs improvement?

I don’t have a lot of confidence in their support. The support is not first class. I am still working with them with follow ups with the numerous issues we have had. The appliance itself seems to be doing what it’s supposed to, but the support is lacking.

For how long have I used the solution?

I've used it for six years.

Buyer's Guide
LogRhythm SIEM
May 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.

What was my experience with deployment of the solution?

We went through research of multiple products that were similar in nature and selected LogRhythm based on the ability to comply with regulations and the advanced features that it offered. It’s a really deep product and you can do a lot with it, but it just hasn't been realized.

What do I think about the stability of the solution?

It handles what we throw at it.

How are customer service and support?

I have mixed feelings. We have had some issues with their internal support.

We lost our ability to access the support portal, and it took them around three weeks to resolve it. We had a new upgraded appliance implemented and professional services set it up. They failed to take all of the alerts and bring it to the new appliance.

What about the implementation team?

We implemented it in-house.

What's my experience with pricing, setup cost, and licensing?

The licensing has improved. It has gone down because it is no longer individual monitoring licensing, whereas before it was licensed per collection manager. They have given us decent pricing, they gave us credit for the old appliance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user341262 - PeerSpot reviewer
Security Analyst at a retailer with 1,001-5,000 employees
Vendor
We are able to manage the items we have coming in with one product; however, if the client doesn't have a customer in their system, they can’t use it.

What is most valuable?

I find that the ease of installation is a valuable part of the solution.

How has it helped my organization?

The consolidation of the logs and being able to manage the items we have coming in -- all in one product -- has really helped this company a lot.

What needs improvement?

The main area of improvement is that the client must be installed on the computer for all of the functions to work. So if the client doesn't have a customer in their system, they can’t use it.

For how long have I used the solution?

I have been directly responsible for this install around two years. I worked with LogRhythm at another company for around three years.

What was my experience with deployment of the solution?

We didn’t encounter any issues that were not fixable.

What do I think about the stability of the solution?

I can’t remember the last time it was down. It’s very stable.

What do I think about the scalability of the solution?

The way it’s set up with agents, we can scale very well and if we need to we can just add more hardware to the system. The only limit is the hardware. We have been happy with it.

How are customer service and technical support?

Very knowledgeable, though I wouldn’t say proactive. When you speak with technical support you don’t actual speak with someone: you leave a message, which I do not like, although they respond pretty quickly.

Which solution did I use previously and why did I switch?

The scalability was the main reason for switching. You never know how much you may need and the ability to quickly adapt is great.

The ability to add something quickly is very important. It's more complete than a lot of products, such as Splunk, but you have to put in a lot of work.

With LogRhythm, security feeds and security alerts are just built in.

What about the implementation team?

We did migrate recently and had help from LogRhythm.

What was our ROI?

I’d say we have an ROI. It helps us identity problems before they become issues.

What's my experience with pricing, setup cost, and licensing?

Always plan for more logs than you think you have. Once you start collecting you will realize that you need more than you thought.

What other advice do I have?

My relationship has been very good. When we updated our software we set up weekly meetings which really helped us with reporting. We don’t directly get in touch with support but when we do they solve our problems.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
LogRhythm SIEM
May 2025
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
CISO at a religious institution with 501-1,000 employees
Real User
Daily alerts allow me to quickly find security and operational issues
Pros and Cons
  • "The daily alerts allow me to quickly find security and operations issues which need to be addressed."
  • "More detail in the alerts given to avoid additional searches, as often the source or destination associated with the alert is not evidenced."

What is our primary use case?

The primary use case is an analysis of server logs with some deeper analysis done on searches. Reports help ensure various departments have daily notices of any activity that they should be reviewing.

How has it helped my organization?

  • Alerts to account usage errors.
  • Reports of malware from the antivirus.
  • Reports application errors presented in logs.

What is most valuable?

Daily alerts: These allow me to quickly find security and operational issues which need to be addressed.

What needs improvement?

More detail in the alerts given to avoid additional searches, as often the source or destination associated with the alert is not evidenced.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user313884 - PeerSpot reviewer
Contract Sr. Security Engineer, LogRhythm Analysis/Forensics at a financial services firm with 1,001-5,000 employees
Vendor
It provides reports on the Cardholder Data Environment at 95% effectiveness, but to operate at the 99.99% level, it needs to have uninterrupted reporting host connections to the Log Mediator.

LogRhythm is a perfect example of "Garbage In, Garbage Out" in Information Security—LogRhythm reports on the Cardholder Data Environment (CDE) activity are only as reliable as the data coming in.

If there are interruptions in the data downloads or hosts that don't report to LogRhythm from the CDE, the utility of the LogRhythm Reports declines dramatically. Even when reporting at 95% effectiveness, critical information regarding Threat Agent activity is probably still missing.

To operate at the 99.99% level, LogRhythm needs to have uninterrupted reporting host connections to LogRhythm’s Log Mediator(s) for optimal LogRhythm device functioning, complete and valid CDE host presence in LogRhythm’s log records, the minimization of false positives (Trash Traffic), the use of dedicated LogRhythm Appliances (not VMs), and flexibility in LogRhythm Change Management procedures that accommodate swiftly to LogRhythm-specific needs.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

like :dude - Speciallyyyy LogRhythm Change Management

it_user317892 - PeerSpot reviewer
Senior Information Security Manager with 1,001-5,000 employees
Vendor
It's simplified and clarified complex volumes of information, but customizing features could be improved.

Valuable Features

  • Clarity of information
  • Ease of deployment

Improvements to My Organization

The ability to provide insights and simplification for complex volumes of information.

Room for Improvement

The ability to customize certain features of the product.

Use of Solution

I've used it for one year.

Stability Issues

I find that the system is stable and handling our traffic very well.

Customer Service and Technical Support

Customer Service:

The customer service teams is excellent and have they resolved anything we have thrown at them in a timely fashion.

Technical Support:

The technical support team is excellent and have they resolved anything we have thrown at them in a timely fashion.

ROI

We do not have one yet, but we definitely foresee a ROI.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Real User
Great dashboards at a competitive price
Pros and Cons
  • "NextGen SIEM's best feature is how it presents logs."
  • "NextGen SIEM has separate rules for AI, advanced intelligence, and MP rules - it would be better to have a centralized way to write the rules and create alarms."

What is most valuable?

NextGen SIEM's best feature is how it presents logs. For example, the dashboard view is detachable from other things.

What needs improvement?

NextGen SIEM has separate rules for AI, advanced intelligence, and MP rules - it would be better to have a centralized way to write the rules and create alarms. In the next release, I would like to see the network hierarchy diagram that QRadar offers.

For how long have I used the solution?

I've been using LogRhythm NextGen SIEM for one year.

What do I think about the stability of the solution?

NextGen SIEM's performance is quite good.

What do I think about the scalability of the solution?

NextGen SIEM is easy to scale.

Which solution did I use previously and why did I switch?

I previously used QRadar SIEM.

How was the initial setup?

The initial setup was simple, and it took two days to deploy.

What's my experience with pricing, setup cost, and licensing?

NextGen SIEM's pricing is moderate. There are additional costs for different applications.

What other advice do I have?

I would recommend NextGen SIEM to other users as it is a leading solution with new features at a better price than competitors like Splunk and QRadar.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partners
PeerSpot user
Security Analyst at a financial services firm with 201-500 employees
Real User
Dashboards and AI Engine are key features giving us more insight into the traffic patterns we see

How has it helped my organization?

It's given us more insight into the traffic patterns that we see.

What is most valuable?

The dashboards and the AI Engine.

What needs improvement?

Mostly they should just expand on the features that are already there. More pre-built parsers, more pre-built AI rules, more dashboard widgets that we can put to use.

What do I think about the scalability of the solution?

I would say scalability is very good.

How is customer service and technical support?

Mostly very good. We have had some issues that have taken a long time to resolve, various technical issues that have taken longer to resolve than we desire.

What other advice do I have?

The criteria that we look when selecting a vendor are usually support, and being and end-to-end solution, that is very important too.

I gave it a nine out of 10 overall because we have had some support issues that haven't been resolved quickly enough but, other than that, I've been very happy with the product.

If a colleague was researching this and other popular SIEM tools, I would say for the most part I'm very happy with it. I would advise them to schedule a demo and see if it meets their needs.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user756399 - PeerSpot reviewer
EMS-Scada Infrastructure Engineer at a energy/utilities company
Vendor
It is very stable once it is configured. We have not had any downtime.

What is most valuable?

Compliance. It's the main focus of the solution, and that is what we've been doing: logging, monitoring, and alerting.

How has it helped my organization?

We keep an eye on all the events which actually are configured as an alert. This keeps us on compliant for compliance purposes.

Our key challenge and goal is maintaining a secure infrastructure. We are a power electric company, so we are trying to be as secure as we can.

It is a very good solution. It is very robust. It is very extensive. We're trying to go into the minimum requirements for compliance purposes, but I would like to start implementing more for administration purposes and security.

What needs improvement?

  • More seminars.
  • Reporting: A reporting tool would be good for us, especially if we have better knowledge of them.

What do I think about the stability of the solution?

It is very stable once it is configured. We have not had any downtime.

What do I think about the scalability of the solution?

The scalability is very powerful. Our network is not very big, but we can configure it so we can always be up and running with redundancy. It's a great solution.

How is customer service and technical support?

It is a great experience all the time working with them. They are very useful, if they don't have the answer, they find the people that have the answer.

How was the initial setup?

On the last upgrade, I was part of the group to implement it. We did have some challenges, because the previous deployment was not configured right, then we did the implementation and it was very straightforward.

Which other solutions did I evaluate?

Alert Logic, but the laws were going outside of the company, so we want to keep it inside for security purposes.

LogRhythm was the best solution that we could find.

What other advice do I have?

We have LogRhythm in place and it's been working well for us.

It's a great solution but training will be a big key on the implementation. We can troubleshoot it and get the technical support, but it always being very good to have technical training on LogRhythm.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros sharing their opinions.