What users are saying about
4 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.6 out of 100
47 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 7.7 out of 100

Likelihood to Recommend

Azure Sentinel

If you are new to SIEM and have not invested in pre-exiting SIEM solutions, Azure Sentinel is a great way to start your SIEM journey. This is especially true if you are involved in other Microsoft products or are using Office 365 or Azure, it would be very easy to deploy and will have the logs in no time.
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

I will say that the LogRhythm NextGen SIEM Platform is well suited for an organization that is not very big but has multiple log sources. Or a lot of non-technical employees who do not know how to code or do write custom queries. Typically it is a good fit for universities and mid-range startups. This has an excellent interface, dashboard, useful for managing roles, but it doesn't provide the level of customization that a technical person with knowledge of coding probably would prefer. Software like Splunk and Elastic Search are much more flexible in terms of the granularity of the search.
Anonymous | TrustRadius Reviewer

Feature Rating Comparison

Security Information and Event Management (SIEM)

Azure Sentinel
7.8
LogRhythm NextGen SIEM Platform
8.6
Centralized event and log data collection
Azure Sentinel
9.0
LogRhythm NextGen SIEM Platform
9.5
Correlation
Azure Sentinel
9.0
LogRhythm NextGen SIEM Platform
9.1
Deployment flexibility
Azure Sentinel
6.0
LogRhythm NextGen SIEM Platform
8.4
Integration with Identity and Access Management Tools
Azure Sentinel
8.0
LogRhythm NextGen SIEM Platform
7.9
Custom dashboards and views
Azure Sentinel
7.0
LogRhythm NextGen SIEM Platform
9.3
Event and log normalization
Azure Sentinel
LogRhythm NextGen SIEM Platform
8.6
Host and network-based intrusion detection
Azure Sentinel
LogRhythm NextGen SIEM Platform
7.3

Pros

Azure Sentinel

  • Very easy to setup
  • Pay as you use--month-to-month subscription--no lengthily contracts
  • Works very well with other Microsoft tools as it has native integration
  • Cheaper then other SIEM products
  • No need to deploy any infrastructure on-premises to manage it
  • Very fast deployment
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

  • LogRhythm is a great SIEM to learn content on because the building blocks are very intuitive and easy to implement. All of the concepts relevant to content development are literally represented as drag and drop building blocks that can be easily manipulated.
  • The statistical building blocks contain powerful anomaly detection capabilities that are extremely difficult to implement in other SIEMs or not possible at all.
  • LogRhythm does better event classification than any other SIEM by far. My team typically drops all classification schemes from default installations of SIEMs and rebuilds them from scratch. I can actually use LogRhythms event classifications in rules without worrying about excessive partial matches or correlating unwanted events.
Joel Eng | TrustRadius Reviewer

Cons

Azure Sentinel

  • Better integration with third-party tools
  • More connectors for third-party tools
  • Better online training available
  • More built-in queries
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

  • While searching for log events is quick, the interface isn't as user-friendly as other SIEM products.
  • Many of the administrative/management functions are only available through the full LogRhythm desktop console, not through the web console.
  • The LogRhythm agent, when used for FIM and RIM, is very memory intensive.
Anonymous | TrustRadius Reviewer

Likelihood to Renew

Azure Sentinel

No score
No answers yet
No answers on this topic

LogRhythm NextGen SIEM Platform

LogRhythm NextGen SIEM Platform 9.0
Based on 1 answer
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
James Harrison | TrustRadius Reviewer

Usability

Azure Sentinel

Azure Sentinel 9.0
Based on 1 answer
I think the solution is robust, very usable, and user friendly. Overall it is very solid product that might not have all the functionality that Splunk has, but considering the time it has been on the market, I think it's really good. Having in mind how much Microsoft has invested in Cloud (i.e., Azure), this product will only grow stronger and better. I have been using it for a year, and since we started using it, there have been a lot of improvements and the number of connectors has increased.
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

LogRhythm NextGen SIEM Platform 8.0
Based on 2 answers
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
Anonymous | TrustRadius Reviewer

Support Rating

Azure Sentinel

Azure Sentinel 6.0
Based on 1 answer
The support is standard Microsoft support. It's not bad, but far from best in the industry. Compared to not having too many online courses/training available, this can be a roadblock, but in all honesty, deployment and day-to-day operations are easy and the product is intuitive. If you know how to read and understand Windows logs and have basic knowledge in any query language, you won't have much difficulty getting around. If you have some urgent investigation to do and you are stuck in understanding what happened and have difficulty correlating logs from different systems, other products probably will have better support where you can call someone and have screen sharing session/assistance in finding what's going on, but you pay premium for that, so at the end it all depends on your budget, technical skills, and comfort level.
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

LogRhythm NextGen SIEM Platform 8.0
Based on 18 answers
Support has always been fantastic for this product compared to many other support providers I've worked with. They are always very friendly and seem to be well trained and knowledgeable and never have to wait long for a solution. We usually get the issue fixed in the first call, but also we really haven't had to use support a ton so that's also a plus
Anonymous | TrustRadius Reviewer

Implementation Rating

Azure Sentinel

No score
No answers yet
No answers on this topic

LogRhythm NextGen SIEM Platform

LogRhythm NextGen SIEM Platform 8.0
Based on 3 answers
  • Buy professional services.
  • Buy and implement the system if possible.
  • Remember that the end point log configuration may require other teams in your company to assist you in getting the desired logs from all resources.
  • Attend the end user and daily operations training after a period of usage so you are not overwhelmed with information on concepts not yet seen.
  • Don't be afraid to call for help during your first months of use.
  • Don't close any ticket until you are sure the expected results are verified.
  • Use the community forums to discuss issues with your peers.
  • Watch the training videos offered by L R University.
James Harrison | TrustRadius Reviewer

Alternatives Considered

Azure Sentinel

Azure Sentinel is much more cost effective and affordable than FortiSIEM and especially compared to Splunk Enterprise. Azure Sentinel is easier and faster to implement and does not require having any on-premises setup. It's purely software. There is no need to install any hardware on your network and you do not need to tap into the network and sniff all the traffic. All the software components of the solutions reside in Azure. You need to send the logs to Azure. The only thing that needs to be done on the servers where you want to monitor logs is install a small, small agent that will have the info of your Log Anaytics and a key to be able to connect and upload the logs. If you are versed in Microsoft technology, there is not much training required to get it going. There is the KQL language for writing queries that might be kind of new but then, on the other hand, any SIEM product has its own subscription language and syntax that needs to be learned, so Azure Sentinel is no different.
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since support is based in the USA in Colorado.
Anonymous | TrustRadius Reviewer

Return on Investment

Azure Sentinel

  • It provide us with visibility in what's going on in our Azure deployments, Office 365 and on-premises servers
  • Allows us to investigate incidents
  • Allows to detect suspicious behavior
  • Fulfills the requirement to have SIEM/centralized log system that is required by security standards and certifications
Anonymous | TrustRadius Reviewer

LogRhythm NextGen SIEM Platform

  • The ability to search through logs in a centralized location really helps us to provide RCA (Root Cause Analysis) to management for outages. This helps us to quickly identify the cause of outages and thus saves money due to reduced downtime.
  • Being able to configure the alarms to provide real-time notification (and responses) to security events helps to prevent potential loss due to compromises (such as a fraudulent wire transfer).
  • The initial investment in LogRhythm SIEM is somewhat expensive, however, the appliance is built to your specific needs so you won't have to constantly be upgrading the device as your company grows.
Anonymous | TrustRadius Reviewer

Pricing Details

Azure Sentinel

General

Free Trial
Yes
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Azure Sentinel Editions & Modules

Edition
Azure Sentinel$2.461
100 GB per day$123.002
200 GB per day$221.402
300 GB per day$319.802
400 GB per day$410.002
500 GB per day$492.002
More than 500 GB per day$492.00 + $98.403
  1. per GB ingested
  2. per day
  3. per day/plus each additional 100 GB increment
Additional Pricing Details

LogRhythm NextGen SIEM Platform

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

LogRhythm NextGen SIEM Platform Editions & Modules

Additional Pricing Details

Rating Summary

Likelihood to Recommend

Azure Sentinel
10.0
LogRhythm NextGen SIEM Platform
7.7

Likelihood to Renew

Azure Sentinel
LogRhythm NextGen SIEM Platform
9.0

Usability

Azure Sentinel
9.0
LogRhythm NextGen SIEM Platform
8.0

Support Rating

Azure Sentinel
6.0
LogRhythm NextGen SIEM Platform
8.0

Implementation Rating

Azure Sentinel
LogRhythm NextGen SIEM Platform
8.0

Add comparison