LogRhythm NextGen SIEM is great. We use it for log management for security purposes.
CEO/Consultant at a tech services company with 51-200 employees
User-friendly with an excellent security operation center
Pros and Cons
- "The security operation center is excellent."
- "The customer support system is time-consuming."
What is our primary use case?
How has it helped my organization?
The security operation center is excellent, and we can pick logs from any system, not only the IPS or firewall. In addition, it has the capacity to accept logs and provide smart dashboards and analysis.
What is most valuable?
The most valuable feature is the SOC Security Operations Center feature. This solution has two types of systems, virtualization and the appliance. The appliance is ready and configured, so we use the IP addresses and trigger the endpoint. It's very user-friendly, and whenever anyone deploys a virtualization system, they can experience it.
What needs improvement?
The customer support system is time-consuming and needs to be improved because it is not very good. For other solutions, you can deliver whenever you have a customer problem. All you need to do is open a ticket, log into the system, and the issue is resolved. However, for LogRhytm, we have to flag the problem and then send the log, and we never know if we will receive a response in one hour or one week.
In addition, LogRhythm NextGen SIEM has one of the best analysis features, but it can still be improved. However, I believe they plan to make improvements since they're only selling the product for two systems currently.
Buyer's Guide
LogRhythm SIEM
January 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
For how long have I used the solution?
We have been using this solution for three years.
What do I think about the stability of the solution?
It is a very stable solution.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
I rate the customer support a four out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup was very easy. I rate the setup a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is very good, and it is very cheap compared to other solutions. If we compare it to SolarWind, SolarWind is not as advanced as LogRhythm NextGen SIEM.
I rate the price a nine out of ten. We always consider the features and quality before the price, but the cost is still very good. We get about 98% of the features we want.
What other advice do I have?
I rate LogRhythm NextGen SIEM a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
security solutions integrator at a consultancy with 1-10 employees
The GUI is easy to explore, and it integrates well with other security solutions
Pros and Cons
- "LogRhythm's GUI is easy to explore. We also like other features, such as its integration with other security solutions, log correlation, and the deployment of use cases."
- "LogRhythm's SOAR and NDR features don't stack up well against competitors. maybe integrating theme functionality as the other do. But in general, it's okay."
What is most valuable?
LogRhythm's GUI is easy to explore. We also like other features, such as its integration with other security solutions, log correlation, and the deployment of use cases.
What needs improvement?
LogRhythm's SOAR and NDR features don't stack up well against competitors.
maybe integrating theme functionality as the other do. But in general, it's okay.
For how long have I used the solution?
We started with LogRhythm about three years ago.
What do I think about the stability of the solution?
LogRhythm is stable.
What do I think about the scalability of the solution?
Scalability is a matter of cost. LogRhythm has the technical capacity to scale if you pay for the components and licenses.
How are customer service and support?
LogRhythm's support is good.
How was the initial setup?
Setting up LogRhythm is straightforward. It is not complicated.
What's my experience with pricing, setup cost, and licensing?
We work with French-speaking African countries, and it costs more than the average SIEM solution. Also, the pricing isn't too flexible. AlienVault, Splunk, and IBM QRadar are more suitable for customers on a tight budget.
What other advice do I have?
I rate LogRhythm eight out of 10. With any solution, you need to deploy the use cases correctly, so the customer should understand the use cases for a SIEM. An SIEM solution only collects and centralizes logs instead of detecting unknown malware. There are no use cases that are customized to fit the customers' context.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
LogRhythm SIEM
January 2026
Learn what your peers think about LogRhythm SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
Head Of Technical Services at a tech services company with 51-200 employees
Stable for long periods, and comes with built-in UEBA
Pros and Cons
- "I would say the most valuable feature of LogRhythm is that it has built-in UEBA functionality, among other basic Windows packages."
- "I think there is room for improvement because the system is still running on the Windows Server platform. The problem with running on Windows is that it is not that good for scaling and providing for big deployment environments."
What is our primary use case?
I am a distributor and not an end-user of the product, so I cannot comment on use cases.
What is most valuable?
I would say the most valuable feature of LogRhythm is that it has built-in UEBA functionality, among other basic Windows packages.
What LogRhythm really excels at is its stability, since, in all the deployments that I have been involved in, there's no break-and-fix at all. When the customer finds that there is something lacking from the solution, it is often a matter of deploying extra appliances and things like that. So the most valuable feature in an abstract sense is that it is so reliable.
What needs improvement?
I do think there is room for improvement because the system is still running on the Windows Server platform. The problem with running on Windows is that it is not that good for scaling and providing for big deployment environments.
With that said, I think it's good enough. For the most part, I just want to have a consolidated platform for the NDR, i.e. the new MistNet NDR that they have acquired, with the current XDR. At this time, it is still two separate controls.
For how long have I used the solution?
I have been working with LogRhythm NextGen SIEM from a company perspective for three years.
What do I think about the stability of the solution?
All of the deployments that I have been involved in have been very stable, over long periods of time. There's very little in the way of breaking and fixing at all. Most complaints are typically just that the customer comes across extra requirements that need to added on to the base product.
What do I think about the scalability of the solution?
There are some issues with scaling that I'm aware of. Most of the time, the scalability becomes increasingly more complex when increasing the indexing or when processing the loss security complex. It's not easy when we go to a high-volume customer environment where many laptops are involved, for example. In that case, it's perhaps not that easy to scale.
How are customer service and support?
The technical support is good, and they are available at any time. They allocate customer assistants and account managers for taking care of all the application support. Any time that I need a technical fix and the customer is not certified, they will escalate the issue to the customer success manager who will then help solve it.
Which solution did I use previously and why did I switch?
Compared to other solutions, an advantage of LogRhythm is that it still works on a lot of the old platforms. As mentioned, it is based on the Windows platform, and I think that it wins out due to the straightforward pricing and how easy it is to calculate for the sizing and critical add-ons such as UEBA and SOAR.
Because the platform is always the same, it's just easier to extend it as needed. For example, it's not technically dependent on another solution that's been acquired by themselves or another company like IBM.
The main difference boils down to the question: for add-ons and such, do you need to seek out a different service from a different vendor rather than adding to the same solution by the same company? I believe they do it all from the same R&D teams and it shows.
How was the initial setup?
The deployment for only one small or medium size environment is pretty straightforward, but for enterprise deployments where there are many different components (e.g. various appliances or other software add-ons) it can become very complex, especially for HA setups.
What's my experience with pricing, setup cost, and licensing?
The setup and licensing for small and medium size businesses is straightforward, though when it comes to the enterprise it pays to keep in mind the possibility for complications given all the extras and add-ons that may be required.
What other advice do I have?
My advice is to take a look at the account directly with the account manager of LogRhythm and find a value-added distributor to support you with the sizing, consulting, use case discovery, and building up the operation maturity roadmap, in order to be truly aligned with the LogRhythm deployment in the long term.
I would rate LogRhythm NextGen SIEM a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems Administrators at a tech services company with 201-500 employees
Very helpful for monitoring and alarming, very stable and scalable, and excellent technical support
Pros and Cons
- "File Integrity Monitoring is really valuable because we have it set up on our core assets. This is one of the key features that I utilize. We also use it quite a lot for event management to do reporting."
- "It should have some more message monitoring features. It can also have some free message monitoring tools."
What is our primary use case?
I use LogRhythm for PCI DSS compliance. All of our devices are sending logs to LogRhythm. I have set up Silent Integrity Monitoring, Data Loss Prevention, Registry Integrity Monitoring, and other alarms for detection, and we do investigations.
How has it helped my organization?
I don't have metrics, but it has really improved the monitoring and alarming for us.
What is most valuable?
File Integrity Monitoring is really valuable because we have it set up on our core assets. This is one of the key features that I utilize. We also use it quite a lot for event management to do reporting.
What needs improvement?
It should have some more message monitoring features. It can also have some free message monitoring tools.
For how long have I used the solution?
I have been using this solution for about two years.
What do I think about the stability of the solution?
It has been very stable. There are no major issues. It has been exactly doing what I expected it to do.
What do I think about the scalability of the solution?
It has been very scalable in terms of adding new systems and stuff like that. It has been quite good.
We have plans to increase the usage of LogRhythm. We have some new solutions and new networks coming up. We might be looking to expand within the next two years to onboard new systems.
How are customer service and technical support?
Technical support has been excellent so far. I never had any issues with technical support. Their support has been excellent.
Which solution did I use previously and why did I switch?
I didn't use any other solution previously.
How was the initial setup?
It was pretty straightforward. The actual deployment of it took about two days, but the implementation strategy took longer. It took a couple of months for meetings and planning with different experts, project managers, and engineers. They looked at our business requirements and other things.
We have two administrators and two analysts. Four of us are managing the system.
What's my experience with pricing, setup cost, and licensing?
It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that.
Which other solutions did I evaluate?
When I was looking for a solution, I looked at Splunk and LogRhythm. There was one from SolarWinds as well. Cost-wise, LogRhythm was the one that impressed me the most. Splunk was really good as well, but it was a little too costly.
What other advice do I have?
I would definitely recommend this solution for compliance requirements, such as PCI DSS compliance. It does cost a great amount, but its pricing is competitive with some of the other vendors. If it is a necessity to have a SIEM solution, I would definitely recommend LogRhythm.
I would rate LogRhythm NextGen SIEM a nine out of ten. It has been really good. So far, my experience has been seamless. They should keep doing what they're doing.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Researcher at a tech services company with 1-10 employees
Efficiently catches threats and reduces the risk of exposure
Pros and Cons
- "In terms of security, LogRhythm NextGen SIEM is great."
- "Scalability-wise, it's not that great."
What is our primary use case?
Private monitoring is our primary use case.
What is most valuable?
In terms of security, LogRhythm NextGen SIEM is great.
For how long have I used the solution?
I have been using LogRhythm NextGen SIEM for one year.
What do I think about the stability of the solution?
LogRhythm NextGen SIEM is stable.
What do I think about the scalability of the solution?
Scalability-wise, it's not that great, but integration with other solutions is pretty easy.
How are customer service and technical support?
The technical support is great.
Which solution did I use previously and why did I switch?
We also use Splunk, but in terms of security, we always recommend LogRhythm NextGen SIEM.
How was the initial setup?
The initial setup was very straightforward. We deployed LogRhythm very easily. In total, including configuration, we deployed this solution in less than one day.
What's my experience with pricing, setup cost, and licensing?
In the context of our country, the price of this solution is too high.
What other advice do I have?
Overall, on a scale from one to ten, I would give LogRhythm NextGen SIEM a rating of eight.
I would definitely recommend this solution; my only concern is with the price — it should be lower.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Associate Senior Engineer - Network & Security at a tech services company with 51-200 employees
Enables us to alternate incident automations but reporting needs improvement
Pros and Cons
- "The most valuable feature is that we can alternate incident automations."
- "We need to get better training for things like creating code and playlists. The way it's done now takes a long time."
What is our primary use case?
Our primary use case is for financial companies and telcos.
What is most valuable?
The most valuable feature is that we can alternate incident automations.
What needs improvement?
We need to get better training for things like creating code and playlists. The way it's done now takes a long time.
For how long have I used the solution?
I have been using LogRhythm NextGen SIEM for two years.
What do I think about the stability of the solution?
The stability depends on the client we installing or integrating for based on the server's requirements. We can create them according to that defined time period. It's not that difficult but depending on the customer or the other server requirements.
We can have a dashboard in a single platform, we can get notifications via email or SMS, and we have Smart Response actions. So that kind of possibility is there.
What do I think about the scalability of the solution?
Our clients are mostly on a larger scale.
How are customer service and technical support?
You can request support and they respond immediately. They're really good.
How was the initial setup?
The initial setup is easy. It can take two hours. The first day of deployment is easy. Then depending on the devices and log servers, it can take time. We can give them predefined or pre-created devices and logs. The deployment depends on the devices and systems we are integrating. But the initial stage is easy.
What's my experience with pricing, setup cost, and licensing?
Because we are a developing country, the costs depend on country development. We implement it for large-scale companies because normal companies, startup companies, can't afford products at that price. We mainly focus on large-scale companies.
What other advice do I have?
I would definitely recommend this solution if you can afford it.
We get customized reports and we get reports including all the details, but when we start using them we couldn't start with the Outlook editor. We can customize a document and we can write a report. The dashboards are very user-friendly and very attractive. But when it comes to the reporting part, I think that could use improvement in the next release.
I would rate it a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Distributor
Cyber Security Researcher at a tech services company with 1-10 employees
Stable with an easy initial setup and good security
Pros and Cons
- "The initial setup is pretty easy."
- "For our market, the solution is quite expensive. It would be ideal if they could work on and improve their existing pricing plans to help make it more affordable in our country."
What is our primary use case?
We typically consult with our clients and help them with necessary services.
What is most valuable?
The UEBA flow is the most useful aspect of the solution.
The initial setup is pretty easy.
While the cost is high, the security provided is quite good, and for those who can afford it, they will pay for the peace of mind.
What needs improvement?
I'm not a fan of the system's user interface.
For our market, the solution is quite expensive. It would be ideal if they could work on and improve their existing pricing plans to help make it more affordable in our country.
We'd like it if the solution could be more customizable in future releases.
For how long have I used the solution?
We've been dealing with the solution for about a year.
What do I think about the stability of the solution?
The solution is quite stable. There aren't issues related to bugs or glitches. It doesn't crash. It's reliable.
What do I think about the scalability of the solution?
The solution can scale if a client needs it to.
We have clients that have 10-15 users on the solution. They are mostly security analysts. In terms of those that can actually view and escalate cases, there may only be five with such access.
At this point, there aren't any plans to increase usage.
How are customer service and technical support?
We typically are the ones that handle technical support for our clients if they run into issues.
How was the initial setup?
The initial setup is not complicated. It's quite easy and very straightforward if you follow the guides provided. I followed the guides and found it to be rather simple. It's not difficult to get everything up and running.
The deployment doesn't take too long. You can have it ready to go in one working day. That includes installation and configuration.
We have a minimum of five people who handle maintenance and deployments.
What about the implementation team?
Our company handles the installation for our clients. We can handle the implementation ourselves. We don't need a separate consultant or integrator.
What's my experience with pricing, setup cost, and licensing?
In our market, for the price it costs, our clients aren't using this solution so much. It seems to be quite expensive in Nepal. That said, even with the fees and a rather high cost, it is the best product among other competitors.
What other advice do I have?
We're partners with LogRhythm.
We don't technically use the solution typically. We consult with clients and advise on products. We also provide services on the solutions we offer. In this case, we do use the product as we log issues.
We use the latest version of the solution.
For our customers, the pricing will scare off many. However, if users are concerned more with the security of their account, they'll find this is a good option.
I would recommend the product. On a scale from one to ten, I'd rate it at an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Sr IT Security Engineer at a energy/utilities company with 1,001-5,000 employees
Facilitates compliance and auditing of adherence to regulations
Pros and Cons
- "We use this solution to examine disparate log sources and provide a cohesive method to search for anomalous behavior."
- "I would like to see support added for Exchange 2016, and CheckPoint OPSec Lea."
What is our primary use case?
We use this solution to examine disparate log sources and provide a cohesive method to search for anomalous behavior.
How has it helped my organization?
In our compliance environments (NERC and SOX), we are able to provide evidence of compliance.
What is most valuable?
The most valuable feature is scheduling the KB update, which reduces administrative effort.
What needs improvement?
I would like to see support added for Exchange 2016, and Check Point OPSec Lea.
Adding the capability to identify and perform an auto import of new log sources (especially Windows-based systems), based on specified criteria, would be a useful feature.
Enhancing the creation of report packages would also improve this solution.
For how long have I used the solution?
Between four and five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Popular Comparisons
CrowdStrike Falcon
Datadog
Dynatrace
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Grafana Loki
Security Onion
Graylog Enterprise
Rapid7 InsightIDR
Elastic Stack
Amazon OpenSearch Service
Buyer's Guide
Download our free LogRhythm SIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- Does LogRhythm NextGen SIEM offer good security?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?















