TrustRadius: an HG Insights company

Datadog vs. FortiSOAR vs. LogRhythm NextGen SIEM Platform

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Datadog

    Score8.8 out of 10
    N/ADatadog is a monitoring service for IT, Dev and Ops teams who write and run applications at scale, and want to turn the massive amounts of data produced by their apps, tools and services into actionable insight.

    $18

    per month per host

    FortiSOAR

    Score8 out of 10
    N/ACyberSponse was a security orchestration, automation and response (SOAR) solution, now known as FortiSOAR. Fortinet acquired and now supports the solution (December 2019).N/A

    LogRhythm NextGen SIEM Platform

    Score7.7 out of 10
    N/AThe LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.N/A
    Pricing
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Editions & Modules
    Log Management
    $1.27
    per month (billed annually) per host
    Infrastructure
    $15.00
    per month (billed annually) per host
    Standard
    $18
    per month per host
    Enterprise
    $27
    per month per host
    DevSecOps Pro
    $27
    per month per host
    APM
    $31.00
    per month (billed annually) per host
    DevSecOps Enterprise
    $41
    per month per host
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Free Trial
    YesNoNo
    Free/Freemium Version
    YesNoNo
    Premium Consulting/Integration Services
    NoNoNo
    Entry-level Setup FeeOptionalNo setup feeNo setup fee
    Additional DetailsDiscount available for annual pricing. Multi-Year/Volume discounts available (500+ hosts/mo).
    More Pricing Information
    Community Pulse
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Considered Multiple Products
    Datadog
    No answer on this topic
    Fortinet
    No answer on this topic
    LogRhythm
    Chose LogRhythm NextGen SIEM Platform
    I think Logrhythm still has a lot of work to do to catch up with competitors in many areas. They need to improve their design cycle, with a cycle that's completely focused on bug fixing and reliability, without introducing any new features to improve the system's overall …
    Incentivized
    Key User Insights
    Would buy again
    94%
    Would buy again
    50 Answers
    No answers on this topic
    75%
    Would buy again
    9 Answers
    Delivers good value for the price
    93%
    Delivers good value for the price
    41 Answers
    No answers on this topic
    75%
    Delivers good value for the price
    9 Answers
    Happy with the feature set
    98%
    Happy with the feature set
    52 Answers
    No answers on this topic
    92%
    Happy with the feature set
    11 Answers
    Lived up to sales and marketing promises
    97%
    Lived up to sales and marketing promises
    32 Answers
    No answers on this topic
    89%
    Lived up to sales and marketing promises
    8 Answers
    Implementation went as expected
    97%
    Implementation went as expected
    36 Answers
    No answers on this topic
    100%
    Implementation went as expected
    9 Answers
    Features
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Monitoring Tasks
    Comparison of Monitoring Tasks features of Datadog and FortiSOAR and LogRhythm NextGen SIEM Platform
    Feature
    Datadog
    7.9
    2 Ratings
    6% below category average
    FortiSOAR
    -
    Ratings
    LogRhythm NextGen SIEM Platform
    -
    Ratings
    Remote monitoring8.22 Ratings00 Ratings00 Ratings
    Network device monitoring7.72 Ratings00 Ratings00 Ratings
    Multiple Server Monitoring7.72 Ratings00 Ratings00 Ratings
    Multi-device monitoring7.72 Ratings00 Ratings00 Ratings
    Automated alerts and notifications8.22 Ratings00 Ratings00 Ratings
    Management Tasks
    Comparison of Management Tasks features of Datadog and FortiSOAR and LogRhythm NextGen SIEM Platform
    Feature
    Datadog
    6.1
    1 Ratings
    12% below category average
    FortiSOAR
    -
    Ratings
    LogRhythm NextGen SIEM Platform
    -
    Ratings
    Patch Management7.31 Ratings00 Ratings00 Ratings
    Service configuration management6.41 Ratings00 Ratings00 Ratings
    Software and hardware inventory5.51 Ratings00 Ratings00 Ratings
    Policy-based automation5.51 Ratings00 Ratings00 Ratings
    Reporting
    Comparison of Reporting features of Datadog and FortiSOAR and LogRhythm NextGen SIEM Platform
    Feature
    Datadog
    8.2
    2 Ratings
    3% above category average
    FortiSOAR
    -
    Ratings
    LogRhythm NextGen SIEM Platform
    -
    Ratings
    Performance data reports8.22 Ratings00 Ratings00 Ratings
    Customizable reporting7.72 Ratings00 Ratings00 Ratings
    Data visualization8.62 Ratings00 Ratings00 Ratings
    Risk analysis8.22 Ratings00 Ratings00 Ratings
    Security
    Comparison of Security features of Datadog and FortiSOAR and LogRhythm NextGen SIEM Platform
    Feature
    Datadog
    6.7
    1 Ratings
    9% below category average
    FortiSOAR
    -
    Ratings
    LogRhythm NextGen SIEM Platform
    -
    Ratings
    Data backup and recovery6.41 Ratings00 Ratings00 Ratings
    Antivirus and malware management7.31 Ratings00 Ratings00 Ratings
    Administrator access control6.41 Ratings00 Ratings00 Ratings
    Security Information and Event Management (SIEM)
    Comparison of Security Information and Event Management (SIEM) features of Datadog and FortiSOAR and LogRhythm NextGen SIEM Platform
    Feature
    Datadog
    -
    Ratings
    FortiSOAR
    -
    Ratings
    LogRhythm NextGen SIEM Platform
    6.7
    22 Ratings
    17% below category average
    Centralized event and log data collection00 Ratings00 Ratings8.522 Ratings
    Correlation00 Ratings00 Ratings7.522 Ratings
    Event and log normalization/management00 Ratings00 Ratings8.022 Ratings
    Deployment flexibility00 Ratings00 Ratings4.021 Ratings
    Integration with Identity and Access Management Tools00 Ratings00 Ratings6.018 Ratings
    Custom dashboards and workspaces00 Ratings00 Ratings7.022 Ratings
    Host and network-based intrusion detection00 Ratings00 Ratings7.016 Ratings
    Data integration/API management00 Ratings00 Ratings5.54 Ratings
    Behavioral analytics and baselining00 Ratings00 Ratings7.04 Ratings
    Rules-based and algorithmic detection thresholds00 Ratings00 Ratings7.04 Ratings
    Response orchestration and automation00 Ratings00 Ratings6.04 Ratings
    Reporting and compliance management00 Ratings00 Ratings6.05 Ratings
    Incident indexing/searching00 Ratings00 Ratings8.04 Ratings
    Best Alternatives
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Small Businesses
    Amazon CloudWatch
    Score7.6 out of 10
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    LogicMonitor
    Score8.9 out of 10
    Splunk SOAR
    Score8.9 out of 10
    IBM Security QRadar SIEM
    Score8.9 out of 10
    Enterprises
    ManageEngine Site24x7
    Score10 out of 10
    Palo Alto Networks Cortex XSOAR
    Score1.1 out of 10
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    All AlternativesView all alternativesView all alternativesView all alternatives
    User Ratings
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Likelihood to Recommend
    8.9
    (65 ratings)
    9.0
    (3 ratings)
    7.0
    (22 ratings)
    Likelihood to Renew
    4.3
    (2 ratings)
    -
    (0 ratings)
    8.0
    (2 ratings)
    Usability
    8.7
    (44 ratings)
    -
    (0 ratings)
    6.5
    (4 ratings)
    Support Rating
    5.0
    (7 ratings)
    -
    (0 ratings)
    8.2
    (9 ratings)
    Implementation Rating
    1.0
    (1 ratings)
    -
    (0 ratings)
    8.0
    (1 ratings)
    User Testimonials
    DatadogFortiSOARLogRhythm NextGen SIEM Platform
    Likelihood to Recommend
    Datadog
    Datadog may be better suited for teams that have a more out-of-the-box infrastructure, on the primary platforms Datadog supports. You may also have better results if you have a bigger team dedicated to devops and/or a bigger budget. We found that trying to adapt it to our use case (small team, .NET on AWS Fargate) wasn't feasible. We continually ran into roadblocks that required us to dig through documentation (and at times, having to figure out some documentation was wrong), go back and forth with support, and in my opinion, waste money on excessive and unintended usages due to opaque pricing models and inaccurate usage reports, as well as broken/non-functional rate sampling controls.
    Incentivized
    Read full review
    Fortinet
    Most organization with medium & maturity SOC struggle with alert fatigue & false positives with addressing alert volume is result in increasing risk of critical alerts being masked by trivial one , in this situation FortiSOAR help in case management : rapidly response in case of crises also. FortiSOAR is designed very well where Fortinet have other stack of security component also like Fortinet NGFW & Forti SIEM etc.. Fortinet NGFW can and generate the FortiSOAR instance through FortiCloud for Customer . However In absence of FortiFabric it require lot of connectors to work well the solution.
    Incentivized
    Read full review
    LogRhythm
    Having mostly worked with their on-premises solution, I think it's well-suited for small , medium, and even big organisations. I feel it might be less suited if the customer wants a SIEM with 100% uptime, as it goes down a lot. Or if they want to depend on customer support. I suggest that if you want to go with LR, you have to have your own experienced engineers to work on.
    Incentivized
    Read full review
    Pros
    Datadog
    • The thing which Datadog does really well, one of them are its broad range of services integrations and features which makes it one step observability solution for all. We can monitor all types of our application, infrastructure, hosts, databases etc with Datadog.
    • Its custom dashboard feature which helps us to visualize the data in a better way . It supports different types of charts through those charts we can create our dashboard more attractive.
    • Its AI powered alerting capability though that we can easily identify the root cause and also it has a low noise alerting capability which means it correlated the similar type of issues.
    Incentivized
    Read full review
    Fortinet
    • User-friendly interface and easy to read data on the panels.
    • Perfect for vulnerability management.
    • Great integration with different security operations center platforms.
    • Customized panels.
    • Setting User Permissions.
    • Scheduled asset scans with reports.
    Incentivized
    Read full review
    LogRhythm
    • LogRhythm NextGen SIEM Platform has an alarm system that generates tickets based on the event and the way it has been configured in the LogRhythm console. Let's say we have a ticket for a malicious email attachment. The ticket will some information like the source of the log, the source IP, destination IP etc. It can be drilled down to obtain specific information like the recipient, source location, file attachment name, SHA hash of the file, source and destination port, time, mac address of the machine that downloaded it etc. This helps the analysts to go to the root of the cause and take actions easily without manually parsing them.
    • The second good thing about the LogRhythm NextGen SIEM Platform is that it is very easy to use with its well-structured interface. To use LogRhythm, an user barely require any technical skills. A little overview of IP, CIDR, hash, etc. is enough to get your hands on it. It requires no programming or coding skills, as everything is GUI based. It also provides a beautiful visualization dashboard. There is another beautiful feature that it provides for the classification of events, known as cases. Multiple users working on the same platform can create cases and add events to it. They also help to maintain future reference.
    • The third good feature is the search tool which is very powerful. For example, sometimes it is hard to find the users who downloaded a malware from the guest wireless of the institution and not the private network. The search tool helps us in searching the user by automatically correlating the MAC address from the current network logs and the previous logs as the MAC address is the same. It is highly scalable for parsing a large number of logs from various sources.
    • I particularly think this is one of the best software available for log parsing in an organization where non-technical users are working on incident response. This tool has a good amount of flexibility. However, it can only be configured with the LogRhythm NextGen SIEM Platform Console.
    • In terms of usability, as already mentioned, it is a very easy tool to use, with a GUI based interface.
    Incentivized
    Read full review
    Cons
    Datadog
    • Alert windows cause lag in notifications (e.g. if the alert window is X errors in 1 hour, we won't get alerted until the end of the 1 hour range)
    • I would appreciate more supportive examples for how to filter and view metrics in the explorer
    • I would like a more clear interface for metrics that are missing in a time frame, rather than only showing tags/etc. for metrics that were collected within the currently viewed time frame
    Incentivized
    Read full review
    Fortinet
    • Training Services- Fortinet offers courses geared towards administration and designed and development of FortiSOAR , Which required multiples access , we need all training services with self pace basis , I think here Fortinet need to improve.
    • Licensing Model- Being as a new technology Licensing model should be crystal & Clear, be it Concurrent Users or The number of FortiSOAR nodes there should be no ambiguity .
    Incentivized
    Read full review
    LogRhythm
    • LogRhythm absolutely needs to provide back end support for threat intelligence lists. Performing a linear search on massive lists of IPs on incoming web traffic can bring the SIEM to its knees.
    • LogRhythm should drop its entire code base for implementing lists and simply turn them into hash tables to avoid the excessive cost associated with referencing lists in rules. I haven't seen the code, but the performance suggests O(n).
    • The reporting feature is the worst of all SIEMs, luckily reports are not my primary service offering. LogRhythm should definitely revamp its reporting to be more intuitive.
    Incentivized
    Read full review
    Likelihood to Renew
    Datadog
    Definitely will not revisit after our issues and, in my opinion, poor support.
    Incentivized
    Read full review
    Fortinet
    No answers on this topic
    LogRhythm
    LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
    Incentivized
    Read full review
    Usability
    Datadog
    There are so many features that it can be hard to figure out where you need to go for your own use case. For example, RUM monitoring us buried in a "Digital Experience" sidebar setting when this is one of our key use cases that I sometimes struggle to find in the application. It appears that ECS + Fargate monitoring was recently released which is great because we had to build a lambda reporting solution for ephemeral task monitoring. But this new feature was never on my radar until I starting clicking around the application.
    Incentivized
    Read full review
    Fortinet
    No answers on this topic
    LogRhythm
    LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
    Incentivized
    Read full review
    Support Rating
    Datadog
    The support team usually gets it right. We did have a rather complicate issue setting up monitoring on a domain controller. However, they are usually responsive and helpful over chat. The downside would be I don’t think they have any phone support. If that is important to you this might not be a good fit.
    Incentivized
    Read full review
    Fortinet
    No answers on this topic
    LogRhythm
    While LogRhythm support is generally quick to respond, the initial response is usually from a first line support engineer with general knowledge of the product. Any advanced or complex issues have always required the assistance of a higher tier of support, directly or indirectly. For a few occasions we actually used our PS hours to work on the issue.
    Incentivized
    Read full review
    Implementation Rating
    Datadog
    Documentation was difficult to work through, rollout was catastrophic (completely outage)
    Incentivized
    Read full review
    Fortinet
    No answers on this topic
    LogRhythm
    • Buy professional services.
    • Buy and implement the system if possible.
    • Remember that the end point log configuration may require other teams in your company to assist you in getting the desired logs from all resources.
    • Attend the end user and daily operations training after a period of usage so you are not overwhelmed with information on concepts not yet seen.
    • Don't be afraid to call for help during your first months of use.
    • Don't close any ticket until you are sure the expected results are verified.
    • Use the community forums to discuss issues with your peers.
    • Watch the training videos offered by L R University.
    Incentivized
    Read full review
    Alternatives Considered
    Datadog
    Our logs are very important, and Datadog manages them exceptionally well. We frequently use Datadog services for our investigations. Use case: Monitor your apps, infrastructure, APIs, and user experience.


    Key features:


    Logs, metrics, and APM (Application Performance Monitoring)


    Real-time alerting and dashboards


    Supports Kubernetes, AWS, GCP, and other integrations


    RUM (Real User Monitoring) and Synthetics





    ✅ Best for backend, server, and distributed systems monitoring.
    Incentivized
    Read full review
    Fortinet
    Done prove of concept (POC) thoroughly , where we judged the solution on every aspect & We came to know FortiSOAR will work well in our environment as it is blended with features like Case managements , Product Flexibility * Scalable Architecture . These features were much required to optimum use of our SOC solution. Since we have all the Fortinet security stack in our environment it helped us a lot in selection (POC) and also commercially.
    Incentivized
    Read full review
    LogRhythm
    LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since support is based in the USA in Colorado.
    Incentivized
    Read full review
    Return on Investment
    Datadog
    • Saved us (time & money) from developing our own monitoring utilities that would pale in comparison
    • Alerts allow us to remedy issues before our customers even know about them
    • Tracking resource usage over time allows us to better plan for future needs, before it becomes a pain-point.
    Incentivized
    Read full review
    Fortinet
    • Improved compliance control and risk management.
    • Improved the business process.
    • Improved incident visibility.
    Incentivized
    Read full review
    LogRhythm
    • It gives the overall view of the environment so we are always aware of our security position.
    • It has created operational effectiveness; we are able to rapidly detect threats and resolve it fast.
    • We have been able to track inappropriate login attempts through tickets.
    Incentivized
    Read full review
    ScreenShots

    Datadog Screenshots

    Screenshot of the out-of-the-box and customizable monitoring dashboards.Screenshot of Datadog's collaboration features, where users can discuss issues in-context with production data, annotate changes and notify their teams, see who responded to that alert before, and discover what was done to fix it.Screenshot of where Datadog unifies traces, metrics, and logs—the three pillars of observability.Screenshot of some of Datadog's 400+ built-in integrations.Screenshot of Datadog's Service Map, which decomposes an application into all its component services and draws the observed dependencies between these services in real timeScreenshot of centralized log data, pulled from any source.