If we were a smaller environment, LogRhythm's NextGen SIEM Platform would be perfect
- Once LogRhythm is running, it's a fairly simple and quick process to get logs ingested. You can have your first log sources being parsed with 30 minutes.
- LogRhythm is very good at parsing out Windows event logs and presenting them in an easily readable way.
- Searching/Investing thru logs is extremely quick with LogRhythm.
Cons
- While searching for log events is quick, the interface isn't as user-friendly as other SIEM products.
- Many of the administrative/management functions are only available through the full LogRhythm desktop console, not through the web console.
- The LogRhythm agent, when used for FIM and RIM, is very memory intensive.