Ivanti Autonomous Endpoint Management (AEM) is an enterprise endpoint-operations solution built on the Ivanti Neurons platform. It combines unified endpoint management (UEM)—centralized management of desktops, mobile devices, and other endpoints—with digital employee experience monitoring, asset discovery, security controls, and automated remediation. Ivanti positions AEM as a broader solution layer that brings UEM, digital employee experience, and security capabilities together rather than as a…
N/A
LogRhythm NextGen SIEM Platform
Score7.7 out of 10
N/A
The LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.
I think that Ivanti Autonomous Endpoint Management can be well suited to most scenarios for patch management. The different options with Ring Deployments allow for rolling out patches in any number of circumstances. Typical monthly, weekly, daily, zero day response, etc. There is some lack of control over how to wrap up a deployment. What I mean is that in a scenario where we need extremely controlled rollouts, some of the features do not align well. For our organization, we would ideally evaluate patches that come out each Patch Tuesday. Select those patches for deployment, deploy those to our test servers over 3 days, wait 2 days, then deploy to production for 3 days. While we have plenty of control over the initial deployment, we have no clean way to say "after these 3 days, no longer deploy the patch". In our specific scenario, we sacrifice process to align with the tool's capabilities.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
Having mostly worked with their on-premises solution, I think it's well-suited for small , medium, and even big organisations. I feel it might be less suited if the customer wants a SIEM with 100% uptime, as it goes down a lot. Or if they want to depend on customer support. I suggest that if you want to go with LR, you have to have your own experienced engineers to work on.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Ivanti Autonomous Endpoint Management is light weight and easy to install
Ivanti Autonomous Endpoint Management allows the user to defer a required restart. Allowing them to restart their machine at a time that's more convenient for them.
Comparatively, Ivanti Autonomous Endpoint Management is a budget friendly solution.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
LogRhythm NextGen SIEM Platform has an alarm system that generates tickets based on the event and the way it has been configured in the LogRhythm console. Let's say we have a ticket for a malicious email attachment. The ticket will some information like the source of the log, the source IP, destination IP etc. It can be drilled down to obtain specific information like the recipient, source location, file attachment name, SHA hash of the file, source and destination port, time, mac address of the machine that downloaded it etc. This helps the analysts to go to the root of the cause and take actions easily without manually parsing them.
The second good thing about the LogRhythm NextGen SIEM Platform is that it is very easy to use with its well-structured interface. To use LogRhythm, an user barely require any technical skills. A little overview of IP, CIDR, hash, etc. is enough to get your hands on it. It requires no programming or coding skills, as everything is GUI based. It also provides a beautiful visualization dashboard. There is another beautiful feature that it provides for the classification of events, known as cases. Multiple users working on the same platform can create cases and add events to it. They also help to maintain future reference.
The third good feature is the search tool which is very powerful. For example, sometimes it is hard to find the users who downloaded a malware from the guest wireless of the institution and not the private network. The search tool helps us in searching the user by automatically correlating the MAC address from the current network logs and the previous logs as the MAC address is the same. It is highly scalable for parsing a large number of logs from various sources.
I particularly think this is one of the best software available for log parsing in an organization where non-technical users are working on incident response. This tool has a good amount of flexibility. However, it can only be configured with the LogRhythm NextGen SIEM Platform Console.
In terms of usability, as already mentioned, it is a very easy tool to use, with a GUI based interface.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
MDM has fallen a bit flat, however, with the recent acquisition of MobileIron I believe this will change but as of now there is some of this still built into the product
The antivirus portion of the product hasn't had much love and could use a bump. It is not bad at all but I would like to see it hit that next level.
Data Analytics is the most powerful tool inside this platform but it is so hard for people to figure it out that it often goes unused. It needs a good redesign.
LogRhythm absolutely needs to provide back end support for threat intelligence lists. Performing a linear search on massive lists of IPs on incoming web traffic can bring the SIEM to its knees.
LogRhythm should drop its entire code base for implementing lists and simply turn them into hash tables to avoid the excessive cost associated with referencing lists in rules. I haven't seen the code, but the performance suggests O(n).
The reporting feature is the worst of all SIEMs, luckily reports are not my primary service offering. LogRhythm should definitely revamp its reporting to be more intuitive.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
MobileIron is a constantly evolving platform that stays current with industry trends. iOS updates? No problem, they're supported almost immediately after a new iOS version comes out. If you are a Core (on-prem) customer there is ample support and assistance to migrate to the Cloud version of MobileIron (although I've yet to convince my department head to approve the request). The platform is very robust and extremely configurable. Management roles can be delegated effectively to other staff without compromising security. These in alone are important, but even more important is the company itself - they are great to work with, from support to sales. We have never had a situation where MobileIron left us on our own, and many times support has gone way beyond what is simply required in order to educate us or extend the usefulness of the product
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Importing devices and setting up patch deployment was very simple. The real star here is the automation built into Neurons though. Neurons is able to set up custom Bots commands which can automate troublesome servers which have custom start up and shut down commands that must be followed. User and SAML setup was also incredibly easy
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
TRM\TAM support has been generally very good. Getting reported bug fixes, design changes, UX problems resolved has been a pain. It is often difficult to get problems escalated beyond the TRM\TAM level. Support is fantastic when you can get it, getting it can often require more work than it should, and that is probably our biggest issue.
While LogRhythm support is generally quick to respond, the initial response is usually from a first line support engineer with general knowledge of the product. Any advanced or complex issues have always required the assistance of a higher tier of support, directly or indirectly. For a few occasions we actually used our PS hours to work on the issue.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
it was clear and understandable for me which is why i have a good hang of it the training material is also great which was provided by them. The help community and documentation is also great. all the questions were clearly answered and the person for clear and patient with it.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It is online based, after learning content you can take a test and if you don't pass you get two other chances to pass. Once you pass the test you can print out your certification or save it
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Better in most all categories. On-prem was not an issue for my organization. MS SCCM was lacking features. Airwatch required increasing tiers of service in order to match [Ivanti Unified Endpoint Manager (formerly LANDESK Management Suite)] features, and lacked the robust inventory data we needed. Meraki was very simple to use, but did not meet our needs. I would say that most Airwatch customers aren't using all the features they are paying for, and could save lots of money by using Meraki instead.
LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since support is based in the USA in Colorado.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The installation of MobileIron was for security compliance so we could containerize email on BYOD devices and also control who got email on company phones (to prevent hourly workers from working on emails after hours). MobileIron met this need nicely.
MobileIron allowed us to utilize device certificates to prevent unauthorized devices from joining wireless networks in our company.
MobileIron allows our sales staff to get emails on the road and many users rely on the functionality and ease of the phone for general mail communication.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info