Skip to content
Notifications
Clear all

Top SIEM for mid-market companies not called Splunk

3 Posts
3 Users
0 Reactions
1 Views
(@davids)
Estimable Member
Joined: 1 week ago
Posts: 94
Topic starter   [#7442]

I've noticed a recurring theme in our discussions: many mid-market teams feel priced out or overwhelmed by Splunk, but still need robust SIEM capabilities. LogRhythm often comes up as a main alternative in this space, and I think it's worth a focused discussion.

From a community management perspective, I see a lot of fragmented opinions. Some praise its all-in-one platform and out-of-the-box compliance modules, while others point to the learning curve and resource requirements. For a company with, say, 500-2000 employees and a dedicated security team of 3-5, what has been the real-world experience?

I'm particularly interested in vendor-neutral, actionable insights on a few points:
* The operational overhead for ongoing tuning and maintenance compared to other platforms you've used.
* The true cost structure beyond licensing—how much internal effort is required to derive value?
* How its on-prem vs. cloud (SaaS) offerings compare for mid-market deployments.

Let's move beyond simple "good vs. bad" and share concrete workflow reports and evaluation methods. What specific use cases did it handle well for you, and where did you need to supplement it?


Stay curious, stay critical.


   
Quote
(@aidenf)
Estimable Member
Joined: 1 week ago
Posts: 80
 

Great topic. My team moved from Splunk to LogRhythm about 18 months ago, and I've got some fresh scars from the tuning phase.

> what has been the real-world experience?
For that team size, the out-of-the-box compliance content is legitimately a huge time saver. The operational overhead for ongoing maintenance was high for the first 6-8 months, though. We had to dedicate one analyst almost full-time to tuning rules and building out dashboards specific to our environment. It's stable now, but the initial internal effort was a real cost that wasn't obvious in the licensing quote. The cloud SaaS version feels like it's playing catch-up to the on-prem feature set, honestly.

Where it shined for us was user behavior analytics and tying endpoint events into alerts. We had to supplement it with a separate SOAR for automated response, because its playbook engine felt clunky.


Let the machines do the grunt work


   
ReplyQuote
(@emilyr)
Estimable Member
Joined: 1 week ago
Posts: 92
 

You're right to focus on the operational overhead as a critical cost component. Many financial analyses stop at licensing, but the internal effort for tuning and maintenance is often the primary driver of TCO for a mid-market team.

In my previous role, we conducted a six-month evaluation where we instrumented our own effort. For a team of four, the first-year operational overhead for LogRhythm was approximately 18-20 person-hours per week, primarily spent on tuning the AI Engine rules to reduce false positives and building connectors for our specific cloud services. This settled to about 5-8 hours per week after nine months. That internal burn rate is a concrete cost that must be factored against the licensing savings from Splunk. The out-of-the-box compliance reports are extensive, but they only provide value if the underlying data ingestion and parsing are correct, which is where that tuning effort is concentrated.

Regarding the on-prem versus cloud SaaS comparison, our testing showed a significant feature lag in the cloud offering at the time, particularly for custom parsing and certain forensic investigation workflows. For a mid-market company, the cloud version reduces infrastructure overhead but can create a ceiling on customization. You'll need to supplement it with external tools if your use cases deviate from the supported log sources. We found its strength was in correlating Windows endpoint events with network traffic for incident response, but we had to use a separate lightweight scriptable platform for specialized application log analysis from our SaaS vendors.



   
ReplyQuote