LogRhythm NextGen SIEM Platform vs. Splunk Enterprise Security

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
LogRhythm NextGen SIEM Platform
Score 7.6 out of 10
N/A
The LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.N/A
Splunk Enterprise Security
Score 9.6 out of 10
N/A
Splunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.N/A
Pricing
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Considered Both Products
LogRhythm NextGen SIEM Platform
Chose LogRhythm NextGen SIEM Platform
LogRhythm has consistently been in the top quadrants and reviews. The support provided by the vendor is top class. Once it is up and running, there is no much to be done in terms of setup. However, free trainings on the internet like youtube are not available as they should be.
Chose LogRhythm NextGen SIEM Platform
SIEMs are complex behemoths, regardless of the one you decide to go with. Even those that are supposedly turn-key solutions aren't really and can pose some tricky issues for veteran IT and InfoSec staff. LogRhythm has the best educational services and technical support, hands …
Chose LogRhythm NextGen SIEM Platform
LogRhythm is heads and tails above AlienVault and more well known and industry-standard compared to InsightIDR.
Chose LogRhythm NextGen SIEM Platform
The only thing we chose LogRhythm NextGen SIEM Platform for is to allow the Security Analysts to work on the dashboards which don't know much about programming and query languages but has good intuition about cyber-security. It is easy to get hands-on compared to Splunk, which …
Chose LogRhythm NextGen SIEM Platform
We researched Splunk as well but it seemed to require more programming experience than LogRhythm which we currently do not have and could not support another FTE for. SolarWinds SIEM product was another product we researched, although it's basic functionality was good, it was …
Chose LogRhythm NextGen SIEM Platform
LogRhythm's NextGen SIEM Platform is lightning fast when compared to other SIEM platforms. With our previous SIEM platform, it would take several hours to query for certain events over a 90 day period. For more advanced queries we'd sometimes have to let it run overnight. …
Chose LogRhythm NextGen SIEM Platform
Unlike other vendors, all modules of LogRhythm are integrated with the main solution. One could go for the Enterprise Architecture which offers separate hardware for separate modules. But in our case that wasn't needed. We needed something that was user-friendly and didn't take …
Chose LogRhythm NextGen SIEM Platform
We used Kiwi years ago before it was owned by Solarwinds and it worked great for our then small server stack, but we grew much bigger fast and needed something more robust and LogRhythm fit the bill.
Chose LogRhythm NextGen SIEM Platform
LogRhythm is easily differentiated from the other log analysis products I've used in terms of sheer functionality. The competitors can't keep up in performance, speed, or correlation. The only thing that the other products can do to hold a candle to LogRhythm is to integrate it …
Chose LogRhythm NextGen SIEM Platform
LR is inferior when compared to a cloud-native SIEM - the functionality is simply not there.
Chose LogRhythm NextGen SIEM Platform
AlienVault USM Appliance and USM Anywhere might lack some functionality where LogRhythm does well. For instance, SmartResponse functionality is more mature than the Orchestration rules at AlienVault USM Anywhere. You can easily script SmartResponse to act accordingly to each …
Chose LogRhythm NextGen SIEM Platform
We selected LogRhythm due to low overall time investment to meet our basic needs, very competitive pricing, a strong user community and a reputation for excellent support. We have been pleasantly surprised by the very personal nature of the partnership we enjoy with LogRhythm - …
Chose LogRhythm NextGen SIEM Platform
We did an RFP and evaluated several SIEM vendors. LogRhythm ended up being a very clear choice when compared with the other vendors.
In this RFP we invited all vendors that were in the leaders category of the Gartner magic quadrant for SIEM.
Chose LogRhythm NextGen SIEM Platform
We had business requirements for the following features:
  • Sustained flow acquisition and data collection of dissimilar log types from multiple sources.
  • Customization for Reporting and Alerting in near real time.
Chose LogRhythm NextGen SIEM Platform
LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since …
Chose LogRhythm NextGen SIEM Platform
I work with every SIEM on the market and I believe LogRhythm simply provides the best overall value in terms of price, incident response capability, content capability, and ease of engineering.
Splunk Enterprise Security
Chose Splunk Enterprise Security
LogRhythm is good for a team comprising mostly non-technical IT users. Unlike Splunk, it has a GUI log search and a good ticketing system. Splunk is better than Logrhythm for me as it provides me with the ultimate flexibility to write custom queries. Scalyr is a good tool and …
Chose Splunk Enterprise Security
Imperva Web Application Firewall (WAF), Juniper Mist Edge, Wazuh
Chose Splunk Enterprise Security
I did not choose this product. Overall although I like ES, I think Sentinel in certain ways is the superior product. The Kusto Query language is a lot easier to use. For instance anything that requires manual parsing in query can be more difficult with this product. Also some …
Chose Splunk Enterprise Security
Splunk Enterprise Security (ES) is much faster and easier to integrate logs and work on alerts to detect suspicious security events.
Chose Splunk Enterprise Security
AlienVault is much more user and beginner friendly, however Splunk ES very much so provides more capability for mass data manipulation, report and dashboard customization, and trend analytics.
Chose Splunk Enterprise Security
These two really helps in better way and low cost and high productivity. Automatic detection ML help you to detect many ways and create cases based on risk score
GRS UBA helps to protect organization from data ,via sharing through emails and USB s .
Gurucu product license once …
Chose Splunk Enterprise Security
Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review …
Chose Splunk Enterprise Security
I believe it is definitely a leader in the security space
Chose Splunk Enterprise Security
I consider Splunk Enterprise Security to have the strongest deployment methodology and troubleshoot features. Other products also provide good solutions such as Riverbed, Broadcom and Solarwinds but I think Splunk Enterprise Security is a great and trustable option to use for …
Chose Splunk Enterprise Security
Even though Splunk ES is not the cheapest solution on the markt, we found it was still cheaper compared to Secureworks we had before. Also the level of flexibility and "thinking with the customer" is much better now.
Chose Splunk Enterprise Security
Traditional hardware logging mechanisms do not provide in-depth research data on the threats and signatures, while Splunk Enterprise Security could easily achieve this feat.
Chose Splunk Enterprise Security
FortiAnalzer is a hardware solution, but with Splunk, we could identify as well get the correct solution for the active threats and too with accurate and precise detailing.
Chose Splunk Enterprise Security
- Schema on the fly indexing --> Gives you faster index searches. Even if you use Datamodes, it's 100x time faster as well.
- Correlation with other domains easily gives you total visibility and reduces the time to investigate and understand the problem.
- With lookups and trust, …
Chose Splunk Enterprise Security
Securonix does not nearly meet the scale, extensibility, and maturity that Splunk ES offers. However, when looking at the MSP architecture options, Securonix is a much more flexible platform for multi-tenanting. So, Splunk ES for captive SOC platforms and Securonix for …
Chose Splunk Enterprise Security
Splunk ES is by far the best solution in the market as per flexibility, features and support. Cost-wise, it is the most expensive option to go with, but that has its own advantages as the product that we get is premium and superior to other SIEM. The best thing about Spunk ES …
Chose Splunk Enterprise Security
Splunk Enterprise Security allows for data normalization that does not compare to other SIEMs such as QRadar or Trustwave. QRadar requires custom dsm parsers before the data can be onboarded. I appreciate that Splunk Enterprise Security can ingest any source of data and …
Chose Splunk Enterprise Security
All Splunk products are easy to integrate, and they collaborate in the security of our organization.
Chose Splunk Enterprise Security
N/A - Have only used Splunk Enterprise Security since coming to Deloitte
Chose Splunk Enterprise Security
LogRhythm is a superior SIEM from a purely security/SOC perspective in my opinion. However, Splunk shines if you have an expert behind the wheel or if the organization is quite large - as my experience with LogRhythm indicated it couldn't handle large-size organizations.
Chose Splunk Enterprise Security
Splunk does not hide its correlation and analytics logic from users as much as other solutions in the same space. While some features are harder to access the underlying information is all accessible and tunable. This gives Splunk an edge over other solutions that lock the …
Chose Splunk Enterprise Security
We have both of these instances in our organization.
Chose Splunk Enterprise Security
Splunk enterprise security works great in Splunk Cloud.
Chose Splunk Enterprise Security
Splunk Enterprise Security is superior in the logging aspect and searching. That’s why it was easier to pick switch to Splunk Enterprise Security. Arcsight is however superior in the correlation and stability aspect. It’s very reliable and stable that we sometimes forget that …
Features
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
LogRhythm NextGen SIEM Platform
7.4
Ratings
5% below category average
Splunk Enterprise Security
8.4
Ratings
8% above category average
Centralized event and log data collection9.00 Ratings9.30 Ratings
Correlation8.10 Ratings8.60 Ratings
Event and log normalization/management8.00 Ratings8.50 Ratings
Deployment flexibility4.60 Ratings8.30 Ratings
Integration with Identity and Access Management Tools7.10 Ratings7.80 Ratings
Custom dashboards and workspaces7.50 Ratings9.20 Ratings
Host and network-based intrusion detection7.10 Ratings7.90 Ratings
Data integration/API management8.00 Ratings8.40 Ratings
Behavioral analytics and baselining8.00 Ratings7.70 Ratings
Rules-based and algorithmic detection thresholds7.10 Ratings8.50 Ratings
Response orchestration and automation7.10 Ratings7.00 Ratings
Reporting and compliance management7.00 Ratings8.60 Ratings
Incident indexing/searching7.10 Ratings9.20 Ratings
Best Alternatives
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.8 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.8 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 9.4 out of 10
Sumo Logic
Sumo Logic
Score 9.4 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 9.4 out of 10
Sumo Logic
Sumo Logic
Score 9.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Likelihood to Recommend
7.5
(0 ratings)
8.8
(0 ratings)
Likelihood to Renew
9.0
(0 ratings)
9.0
(0 ratings)
Usability
8.0
(0 ratings)
7.5
(0 ratings)
Availability
-
(0 ratings)
9.1
(0 ratings)
Performance
-
(0 ratings)
8.2
(0 ratings)
Support Rating
8.2
(0 ratings)
6.6
(0 ratings)
In-Person Training
-
(0 ratings)
9.1
(0 ratings)
Online Training
-
(0 ratings)
8.2
(0 ratings)
Implementation Rating
8.0
(0 ratings)
9.1
(0 ratings)
Configurability
-
(0 ratings)
7.3
(0 ratings)
Ease of integration
-
(0 ratings)
6.4
(0 ratings)
Product Scalability
-
(0 ratings)
9.3
(0 ratings)
Vendor post-sale
-
(0 ratings)
8.2
(0 ratings)
Vendor pre-sale
-
(0 ratings)
8.2
(0 ratings)
User Testimonials
LogRhythm NextGen SIEM PlatformSplunk Enterprise Security
Likelihood to Recommend
LogRhythm is good for providing a comprehensive view of the environment. It gives a great outline of whatever is going on in our servers and systems regarding security malfunctions. The SIEM sends real-time notifications when there are some occurrences; like creating a new user and inappropriate login attempts. It also avails a good use case that meets our HIPAA compliance.
Read full review
Well-Suited Scenarios:
Real-Time Threat Response: ES excels in swiftly detecting and responding to security threats through data correlation.
Compliance Management: ES streamlines compliance with detailed logs and reports, ideal for regulated industries.
User Behavior Analytics: Effective in monitoring user and entity behavior, particularly for insider threat detection.
Large-Scale Environments: Valuable for organizations with diverse data sources and high volumes of data.
Incident Investigation: ES aids in post-incident analysis, reconstructing events to understand root causes.
Less Appropriate Scenarios:
Smaller Organizations: For simpler setups, ES may be complex and costly.
Static Environments: In low-risk settings, ES's advanced features may be unnecessary.
Limited Resources: Tight budgets or sparse IT resources may hinder effective ES use.
Lack of In-House Expertise: Without security experts, optimizing ES can be challenging.
Budget Constraints: ES may be cost-prohibitive for budget-conscious organizations, prompting consideration of more affordable alternatives.
Read full review
Pros
  • LogRhythm is a great SIEM to learn content on because the building blocks are very intuitive and easy to implement. All of the concepts relevant to content development are literally represented as drag and drop building blocks that can be easily manipulated.
  • The statistical building blocks contain powerful anomaly detection capabilities that are extremely difficult to implement in other SIEMs or not possible at all.
  • LogRhythm does better event classification than any other SIEM by far. My team typically drops all classification schemes from default installations of SIEMs and rebuilds them from scratch. I can actually use LogRhythms event classifications in rules without worrying about excessive partial matches or correlating unwanted events.
Read full review
  • Its best feature is its user interface, which is easy to navigate and understand. All you need is a little tutorial on how to use the Splunk query language and you're done.
  • Logs can be easily uploaded or shared across multiple platforms and display a highly insightful graphical representations of data using graphs, tables, and many other formats.
Read full review
Cons
  • While searching for log events is quick, the interface isn't as user-friendly as other SIEM products.
  • Many of the administrative/management functions are only available through the full LogRhythm desktop console, not through the web console.
  • The LogRhythm agent, when used for FIM and RIM, is very memory intensive.
Read full review
  • To identify User Behaviour analysis is lacking component which we get in Splunk UBA.
  • The documentation part is hard to work on because if the new user tries to learn ES then the documentation is not user-friendly.
  • ES must ass more Knowledge objects by default to make security-related aspects more reliable and enhance the details.
Read full review
Likelihood to Renew
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
Read full review
We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
Read full review
Usability
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
Read full review
You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.
Read full review
Reliability and Availability
No answers on this topic
I'm not an ES user, but, in my implementation I usually try to prevent all service stops to guarantee High availability to the final customers.
Read full review
Performance
No answers on this topic
ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.
Read full review
Support Rating
Support has always been fantastic for this product compared to many other support providers I've worked with. They are always very friendly and seem to be well trained and knowledgeable and never have to wait long for a solution. We usually get the issue fixed in the first call, but also we really haven't had to use support a ton so that's also a plus
Read full review
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
Read full review
In-Person Training
No answers on this topic
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
Read full review
Online Training
No answers on this topic
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
Read full review
Implementation Rating
  • Buy professional services.
  • Buy and implement the system if possible.
  • Remember that the end point log configuration may require other teams in your company to assist you in getting the desired logs from all resources.
  • Attend the end user and daily operations training after a period of usage so you are not overwhelmed with information on concepts not yet seen.
  • Don't be afraid to call for help during your first months of use.
  • Don't close any ticket until you are sure the expected results are verified.
  • Use the community forums to discuss issues with your peers.
  • Watch the training videos offered by L R University.
Read full review
It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
Read full review
Alternatives Considered
The only thing we chose LogRhythm NextGen SIEM Platform for is to allow the Security Analysts to work on the dashboards which don't know much about programming and query languages but has good intuition about cyber-security. It is easy to get hands-on compared to Splunk, which has an initial learning curve before being able to start harnessing its true power. Also, the ticketing system is quite fancy and somehow shows us the recent tickets that we need to jump on, which is not in Splunk.
Read full review
LogRhythm is good for a team comprising mostly non-technical IT users. Unlike Splunk, it has a GUI log search and a good ticketing system. Splunk is better than Logrhythm for me as it provides me with the ultimate flexibility to write custom queries. Scalyr is a good tool and quite frankly lot faster than Splunk. However, I prefer Splunk because of its better Dashboards and panel customization abilities. Elastic is another amazing tool. It is hard to choose between the two especially because both have different sets of logs on them. I use both. Elastic for internal server logs, Splunk for everything else.
Read full review
Scalability
No answers on this topic
We have on prem splunk and it’s mostly east to setup, but we have issues keeping data separated between customer splunk deployments while at the same time only having to look at one SIEM to address events in every environment
Read full review
Return on Investment
  • We were able to retire a few older log collection platforms that we had in house. There were 2-3 systems doing the job of LogRhythm.
  • We were able to bring some part of the analysis of events back in house and not rely on third party MSS.
Read full review
  • We have a 100% success rate on all our ES implementations due to the amazing documentation and Splunk enablement on the subject.
  • Our Splunk ES business has grown 100% YoY for the last 3 years.
  • In terms of long term management and maintenance, ES has been highly stable and predictable, reducing our overhead on costly services team for ad hoc maintenance work.
Read full review
ScreenShots