The LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.
N/A
ManageEngine ADAudit Plus
Score 9.0 out of 10
Mid-Size Companies (51-1,000 employees)
ADAudit Plus offers real-time monitoring,
user and entity behaviour analytics, and change audit reports that helps users keep AD and IT infrastructure secure and compliant. Track all changes to Windows AD objects including users, groups,
computers, GPOs, and OUs. Achieve hybrid AD monitoring with a single, correlated view of all
the activities happening across both on-premises AD and Azure AD. Monitor every user's logon and logoff activity, including…
$595
per year based on 2 Domain Controllers
Pricing
LogRhythm NextGen SIEM Platform
ManageEngine ADAudit Plus
Editions & Modules
No answers on this topic
Standard
$595
per year Both licensed based on number of Domain Controllers, Azure AD tenants, file servers, Windows member servers, and Workstations.
Professional
$945
per year Both licensed based on number of Domain Controllers, Azure AD tenants, file servers, Windows member servers, and Workstations.
Offerings
Pricing Offerings
LogRhythm NextGen SIEM Platform
ManageEngine ADAudit Plus
Free Trial
No
Yes
Free/Freemium Version
No
Yes
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
Optional
Additional Details
—
ADAudit Plus is licensed based on number of Domain Controllers (not per-user). Add-ons are available for Windows File Servers, NAS File Servers, Azure AD tenants, Windows Servers, Workstations, AD Backup and Recovery, and File Analysis. For more than 20 domain controllers, ManageEngine directs customers to contact sales for a personalized quote.
Pricing is dependent on the number of domain controllers and starts at $595/year for the Standard edition, and $945/year for the Professional edition.
More Pricing Information
Community Pulse
LogRhythm NextGen SIEM Platform
ManageEngine ADAudit Plus
Considered Both Products
LogRhythm NextGen SIEM Platform
No answer on this topic
ManageEngine ADAudit Plus
Verified User
Manager
Chose ManageEngine ADAudit Plus
We were using the Snare client that was only capable of forwarding logs to some type of syslog server. To be able to get meaning full reports or alerts from that system it would all need to be customized. This would require that you had the expertise on staff to set up these …
Having mostly worked with their on-premises solution, I think it's well-suited for small , medium, and even big organisations. I feel it might be less suited if the customer wants a SIEM with 100% uptime, as it goes down a lot. Or if they want to depend on customer support. I suggest that if you want to go with LR, you have to have your own experienced engineers to work on.
I would recommend ADAuditPlus (and/or Log360) to any org that is trying to achieve PCI DSS Compliance and is struggling with some of the monitoring and reporting aspects, provided that the org is prepared to spend a little time and effort in truly understanding the requirements and is prepared to document requirements and match them to the ADAuditPlus product features.
LogRhythm NextGen SIEM Platform has an alarm system that generates tickets based on the event and the way it has been configured in the LogRhythm console. Let's say we have a ticket for a malicious email attachment. The ticket will some information like the source of the log, the source IP, destination IP etc. It can be drilled down to obtain specific information like the recipient, source location, file attachment name, SHA hash of the file, source and destination port, time, mac address of the machine that downloaded it etc. This helps the analysts to go to the root of the cause and take actions easily without manually parsing them.
The second good thing about the LogRhythm NextGen SIEM Platform is that it is very easy to use with its well-structured interface. To use LogRhythm, an user barely require any technical skills. A little overview of IP, CIDR, hash, etc. is enough to get your hands on it. It requires no programming or coding skills, as everything is GUI based. It also provides a beautiful visualization dashboard. There is another beautiful feature that it provides for the classification of events, known as cases. Multiple users working on the same platform can create cases and add events to it. They also help to maintain future reference.
The third good feature is the search tool which is very powerful. For example, sometimes it is hard to find the users who downloaded a malware from the guest wireless of the institution and not the private network. The search tool helps us in searching the user by automatically correlating the MAC address from the current network logs and the previous logs as the MAC address is the same. It is highly scalable for parsing a large number of logs from various sources.
I particularly think this is one of the best software available for log parsing in an organization where non-technical users are working on incident response. This tool has a good amount of flexibility. However, it can only be configured with the LogRhythm NextGen SIEM Platform Console.
In terms of usability, as already mentioned, it is a very easy tool to use, with a GUI based interface.
ManageEngine ADAudit Plus changes for user and group management can be looked up in builtin reports
You can build your own reports based on almost every logic you can think of
You have the ability to create alerts based on logic and filters and sendout custom alerts to email, SMS or other means.
First you need to understand the basics of the software, after that the software itself is very helpfull in configuring specific items.
I really love the support that ManageEngine is giving the customer, for all questions I use the chat on their website. This is for me the best remote support I ever saw, and I saw a lot in my 20 years of experience in IT.
LogRhythm absolutely needs to provide back end support for threat intelligence lists. Performing a linear search on massive lists of IPs on incoming web traffic can bring the SIEM to its knees.
LogRhythm should drop its entire code base for implementing lists and simply turn them into hash tables to avoid the excessive cost associated with referencing lists in rules. I haven't seen the code, but the performance suggests O(n).
The reporting feature is the worst of all SIEMs, luckily reports are not my primary service offering. LogRhythm should definitely revamp its reporting to be more intuitive.
It's based on Java engine that is slow -- reports are often difficult to build (we are going to upgrade the machine it's running on to see if this is the issue)
Keeping this software up to date is a pain; there should be a better "update" function
The naming and navigation are terrible -- it's never clear which feature you're looking for and where it's hidden in the menus
Adding machines is not as easy as it should be; occasionally there are IP conflicts that are nearly impossible to resolve
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
It works great for everything we need and use. Any issues in the software are pretty easy to resolve with tech support. And they are very responsive to resolving issues. Even ones where a fix/patch are required. At present, the software does everything we need it to for compliance, audit, and account review.
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
ADAudit with its cloud and on prem install option allows any organization to get in on AD report management. Whether you need to report internally only for for external audit controls its a great tool with flexibility to handle most any user or group report capability. Since this also includes m365 integration it enables IT pros to administer usage, license, cost control and permission access to most anything in Microsoft's portfolio. Its a great tool all around for AD integrated access needs.
While LogRhythm support is generally quick to respond, the initial response is usually from a first line support engineer with general knowledge of the product. Any advanced or complex issues have always required the assistance of a higher tier of support, directly or indirectly. For a few occasions we actually used our PS hours to work on the issue.
I'd give their support a 10 if it weren't for the fact that sometimes, the support team (I believe they are overseas) can take a little bit to respond, but not too long. I may submit a ticket in the morning and won't hear about it until later in the afternoon. However, my tickets were not "urgent," so that may have been the reason for the delay. Other than that, support is great, and the ManageEngine account team has visited us in the past. It's always nice to see your product representatives take a white-glove approach like that.
The remote setup team helped when i needed it and setup weas very straight forward and easy. The advanced setup for an external db and customizations for our latest version AD environment went pretty easy once they found documentation on customization.
LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since support is based in the USA in Colorado.
In terms of features, ADAudit Plus offers a comprehensive set of features for monitoring and auditing Active Directory, including real-time alerts, detailed reports, and user behavior analytics. The platform also offers support for multiple platforms, including Windows, UNIX, and Linux, as well as integration with other ManageEngine tools.
I like the ability to customize reports and provided great visibility to AD and some servers.
It helped greatly with customer support issues when we used ADAudit with the hundreds of customer accounts used for SSON to the LOB application server to users over Citrix.
It saved time on some issues with accounts and Group Policy changes that affected customer experience.