The LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.
N/A
SolarWinds Kiwi Syslog Server
Score 7.5 out of 10
N/A
Solarwinds® Kiwi Syslog® Server is a syslog management tool for network and systems engineers. It receives syslog messages and SNMP traps from network devices (routers, switches, firewalls, etc.), and Linux®/Unix® hosts. Users can filter and view these messages based on time, hostname, severity, etc., and set up custom alerts. Kiwi Syslog Server has built-in actions to react appropriately to syslog messages. There are also log archival and clean-up features to help comply with security policies.
LogRhythm has consistently been in the top quadrants and reviews. The support provided by the vendor is top class. Once it is up and running, there is no much to be done in terms of setup. However, free trainings on the internet like youtube are not available as they should be.
SIEMs are complex behemoths, regardless of the one you decide to go with. Even those that are supposedly turn-key solutions aren't really and can pose some tricky issues for veteran IT and InfoSec staff. LogRhythm has the best educational services and technical support, hands …
The only thing we chose LogRhythm NextGen SIEM Platform for is to allow the Security Analysts to work on the dashboards which don't know much about programming and query languages but has good intuition about cyber-security. It is easy to get hands-on compared to Splunk, which …
We researched Splunk as well but it seemed to require more programming experience than LogRhythm which we currently do not have and could not support another FTE for. SolarWinds SIEM product was another product we researched, although it's basic functionality was good, it was …
LogRhythm's NextGen SIEM Platform is lightning fast when compared to other SIEM platforms. With our previous SIEM platform, it would take several hours to query for certain events over a 90 day period. For more advanced queries we'd sometimes have to let it run overnight. …
Unlike other vendors, all modules of LogRhythm are integrated with the main solution. One could go for the Enterprise Architecture which offers separate hardware for separate modules. But in our case that wasn't needed. We needed something that was user-friendly and didn't take …
We used Kiwi years ago before it was owned by Solarwinds and it worked great for our then small server stack, but we grew much bigger fast and needed something more robust and LogRhythm fit the bill.
LogRhythm is easily differentiated from the other log analysis products I've used in terms of sheer functionality. The competitors can't keep up in performance, speed, or correlation. The only thing that the other products can do to hold a candle to LogRhythm is to integrate it …
AlienVault USM Appliance and USM Anywhere might lack some functionality where LogRhythm does well. For instance, SmartResponse functionality is more mature than the Orchestration rules at AlienVault USM Anywhere. You can easily script SmartResponse to act accordingly to each …
We selected LogRhythm due to low overall time investment to meet our basic needs, very competitive pricing, a strong user community and a reputation for excellent support. We have been pleasantly surprised by the very personal nature of the partnership we enjoy with LogRhythm - …
We did an RFP and evaluated several SIEM vendors. LogRhythm ended up being a very clear choice when compared with the other vendors. In this RFP we invited all vendors that were in the leaders category of the Gartner magic quadrant for SIEM.
LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since …
I work with every SIEM on the market and I believe LogRhythm simply provides the best overall value in terms of price, incident response capability, content capability, and ease of engineering.
Syslog-ng don't have customer support or technical support .But its a free software and no clarity on limitations ingestion bandwidth. No gui feature and everything should be done from backend. Gui can easily help to start and stop service ,easy to configure. Unlimited …
PRTG Network Monitor does not give enough reporting and visibility as SolarWinds Kiwi Syslog Server provides. PRTG Network Monitor Syslog is just a sensor but SolarWinds Kiwi Syslog Server has separate applications which are very useful.
SolarWinds Kiwi Syslog is a bare-bones Syslog Server. It doesn't have the advanced features of Splunk and SolarWinds Log Analyzer such as alerting, log analysis, event correlation, etc. However, if you're an SMB and just need a solution to fulfill a security requirement, then …
PRTG is a great package and very useful, but the jump from the free 100 sensor price model to the first tier of the paid model is WAY too expensive. SolarWinds Kiwi Syslog Server is very inexpensive and provides us with the results we needed for log monitoring.
Our group already had a license for the Orion Syslog server that comes bundled with Orion NPM, but it didn't quite meet our requirements for performance. Elasticsearch and Graylog easily met our performance requirements, but not enough team members were able to manage the …
I've not had any other interaction with other Syslog servers. The main reason for that is that Kiwi works outstandingly well at what it does. Simply put, I believe this product is a staple in the IT industry and will remain as such as long as they keep the tool current and …
The price for Kiwi was acceptable and it checked off all the boxes of a product that we needed. I also considered Graylog but Kiwi was much easier to configure.
LogRhythm is good for providing a comprehensive view of the environment. It gives a great outline of whatever is going on in our servers and systems regarding security malfunctions. The SIEM sends real-time notifications when there are some occurrences; like creating a new user and inappropriate login attempts. It also avails a good use case that meets our HIPAA compliance.
The SolarWinds Kiwi Syslog Server does what it's supposed to do. It's a bare-bones Syslog Server. If your company is just trying to fulfill security requirements or doesn't need all the advanced features of a product such as Splunk, then Kiwi will work well and not break the bank. Using the tool is very straightforward as there aren't a lot of options outside of just viewing logs.
LogRhythm is a great SIEM to learn content on because the building blocks are very intuitive and easy to implement. All of the concepts relevant to content development are literally represented as drag and drop building blocks that can be easily manipulated.
The statistical building blocks contain powerful anomaly detection capabilities that are extremely difficult to implement in other SIEMs or not possible at all.
LogRhythm does better event classification than any other SIEM by far. My team typically drops all classification schemes from default installations of SIEMs and rebuilds them from scratch. I can actually use LogRhythms event classifications in rules without worrying about excessive partial matches or correlating unwanted events.
Collection of SNMP traps a reliable and stable collection server for these is crucial to troubleshooting and time to ROS. Kiwi excels at this.
Easy to install set up and train users on.
The free version is a good free tool and handy to use for personal labs and other smalle use cases.
SNMP traps to user readable format is great, sometimes syslog and smnp messages can be hard to interpret and read with out a knowledge of how to do this.
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
Kiwi Syslog has the best usability of any syslog server. While not being able to offer the most features, the ones it does have are intuitive and easy to work with. Everything that it has is where you think it should be. If you can't find it in the menus, it doesn't exist.
Support has always been fantastic for this product compared to many other support providers I've worked with. They are always very friendly and seem to be well trained and knowledgeable and never have to wait long for a solution. We usually get the issue fixed in the first call, but also we really haven't had to use support a ton so that's also a plus
Because the solution is so simple to use and implement, support wasn't very necessary. The one time I did call them to better understand where logs were stored, they were very helpful and friendly. Kiwi has been around for some time and not a lot has changed over the years, so support for it is pretty straightforward and quick.
The only thing we chose LogRhythm NextGen SIEM Platform for is to allow the Security Analysts to work on the dashboards which don't know much about programming and query languages but has good intuition about cyber-security. It is easy to get hands-on compared to Splunk, which has an initial learning curve before being able to start harnessing its true power. Also, the ticketing system is quite fancy and somehow shows us the recent tickets that we need to jump on, which is not in Splunk.
Syslog-ng don't have customer support or technical support .But its a free software and no clarity on limitations ingestion bandwidth. No gui feature and everything should be done from backend. Gui can easily help to start and stop service ,easy to configure. Unlimited technical and customer support . Even when server got shutdown will get on-call or immediate support that will helps a lot to resolve errors