The solution's most valuable features are the graphical user interface and the reporting.
Senior Solutions Specialist (Network & Security) at Ooredoo Qatar
A solution with a good interface and great reporting features but in need of better technical support
Pros and Cons
- "The solution's most valuable features are the graphical user interface and the reporting."
- "The search feature needs to be improved."
What is most valuable?
What needs improvement?
The search feature needs to be improved.
The solution needs better filtering in the next versions.
For how long have I used the solution?
I've been using the solution for more than three years.
What do I think about the stability of the solution?
The stability isn't very good, but it's okay.
Buyer's Guide
User Entity Behavior Analytics (UEBA)
June 2025

Find out what your peers are saying about LogRhythm, Splunk, Hewlett Packard Enterprise and others in User Entity Behavior Analytics (UEBA). Updated: June 2025.
860,592 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Technical support is okay. It's not great. The problem is being able to reach the right people at the right time. This is what needs to be improved.
How was the initial setup?
The initial setup is very complex.
What's my experience with pricing, setup cost, and licensing?
The solution is very expensive. There are also costs beyond the standard licensing fee.
What other advice do I have?
We use the private cloud deployment model.
I would rate the solution six out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.

Security Engineer at U.S. Acute Care Solutions
It watches everything to tell you what you don't know, and gives you a second opinion
What is most valuable?
Like they say, you don't know what you don't know. So, with CloudAI, it's just watching everything to see what you don't know, and it gives you a second opinion.
An ever-changing landscape, in medical, we deal with a lot of doctors in all sorts of places. So, they're always changing, moving, and using Macs. So, it makes it interesting. I definitely think that it's good at finding things automatically, versus trying to define it.
How has it helped my organization?
Not yet, but it's still working on it, it's still maturing. Right now, we were having some issues with some things, but as it continues, it will definitely.
What needs improvement?
Better dashboarding. At the moment, the dashboard only has an hour. It will give you one period of time, versus being an active dashboard like the rest of the dashboards. It doesn't give you an active tally of what's going on. It just gives you a snapshot.
Also, better automation and response.
What do I think about the scalability of the solution?
So far, so good. We haven't needed to scale yet.
How are customer service and technical support?
We've been working with their Beta team, not really technical support. I would say their Beta team is good, a seven on a scale of one to 10.
Which solution did I use previously and why did I switch?
No. We've been using the AI rules within LogRhythm for UABE. This is just on top of it.
Users are always the hard part. They're the biggest vulnerability in any environment. For us, we needed to go through and find something that would help us keep better track. And this does that.
How was the initial setup?
Straightforward. We had to do a couple of changes in a couple of places that were very specific, but the applications were already precompiled and we just had to run it in the various locations. So it was pretty straightforward.
Which other solutions did I evaluate?
We looked into LightCyber, which is a Palo Alto product. At the moment, LightCyber requires an on-premises box, and we didn't want to go with that.
What other advice do I have?
We're at about 2000 logs per second. We have about 42 locations and around 4000 users.
In terms of important criteria when selecting a vendor, whichever one works the best, whether it be the newest or whatever. Whichever one has the best feature set would probably be the winner.
If I were advising someone looking at this solution or something similar, I would say there are a lot of log collectors out there, but LogRhythm's the only one that incorporates intelligence into the solution, versus just being something that collects.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
User Entity Behavior Analytics (UEBA)
June 2025

Find out what your peers are saying about LogRhythm, Splunk, Hewlett Packard Enterprise and others in User Entity Behavior Analytics (UEBA). Updated: June 2025.
860,592 professionals have used our research since 2012.
Business Intelligence Developer at a computer software company with 11-50 employees
Has valuable dashboard features, whereas it could be easier to understand for new users
Pros and Cons
- "LogRhythm UEBA’s best feature is the dashboard. It provides several graphs, charts, and event logs."
- "The product could be user-friendly for someone who doesn’t have any prior experience working with it."
What is our primary use case?
I used the product for monitoring logs.
What is most valuable?
LogRhythm UEBA’s best feature is the dashboard. It provides several graphs, charts, and event logs for 30 to 60 days.
What needs improvement?
The product could be user-friendly for someone who doesn’t have any prior experience working with it.
For how long have I used the solution?
I used LogRhythm UEBA for a year.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
We have five to six LogRhythm UEBA users in our organization. It is very scalable. I can add as many servers as required.
Which solution did I use previously and why did I switch?
I have used Microsoft Sentinel. It is a clutter-free solution. In comparison, LogRhythm UEBA is difficult to use for a beginner. It is easier for someone who has experience working with it.
What's my experience with pricing, setup cost, and licensing?
According to a review by one of my colleagues, it is quite a budget-friendly product.
What other advice do I have?
I rate LogRhythm UEBA a seven out of ten. If you are looking for on-premise and budget-friendly tools, you should go for it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free User Entity Behavior Analytics (UEBA) Report and find out what your peers are saying about LogRhythm, Splunk, Hewlett Packard Enterprise, and more!
Updated: June 2025
Popular Comparisons
CrowdStrike Falcon
Darktrace
Microsoft Defender XDR
IBM Security QRadar
Cortex XDR by Palo Alto Networks
Trellix Endpoint Security Platform
Trend Vision One
Vectra AI
Rapid7 InsightIDR
Splunk User Behavior Analytics
Secureworks Taegis XDR
Aruba IntroSpect
Veriato User Activity Monitoring (UAM)
Buyer's Guide
Download our free User Entity Behavior Analytics (UEBA) Report and find out what your peers are saying about LogRhythm, Splunk, Hewlett Packard Enterprise, and more!
Quick Links
Learn More: Questions:
- Which is the best UEBA solution?
- Viable, Cost-Effective Competitors to Rapid7 InsightIDK
- What is your recommended cost-effective solution to detect and prevent APT attacks?
- Looking for recommendations and a pros/cons template for software to detect insider threats
- What are the main differences between UEBA and SIEM solutions?
- Monitoring Web Hosted Servers for unwanted guests
- Why is User Entity Behavior Analytics - UEBA important for companies?
- When evaluating User Behavior Analytics, what aspect do you think is the most important to look for?
- Which is the best User Entity Behavior Analytics (UEBA) solution?
- What are the different types of insider threats that UEBA solutions help to detect?