The layer that catches a valid credential in the wrong hands — Exabeam New-Scale Analytics baselines every user and machine and scores the deviation, and it can run on a SIEM you already own.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Delivery
Cloud-native (New-Scale)
This is the cloud half of the portfolio. If your mandate rules out SaaS, LogRhythm SIEM is the self-hosted answer from the same vendor.
What to confirm
Region — and processing, separately
Storage residency and processing residency are two different commitments. Get both in writing for your region.
If your obligation requires data to stay in India, settle storage and processing separately with Exabeam before a proof of concept. If it rules out cloud entirely, see LogRhythm SIEM, which answers both by definition.
Quick answer
This page covers Exabeam New-Scale Analytics — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
The behavioural analytics engine — baselines for every user and machine, and dynamic risk scoring on deviation. The capability Exabeam is actually known for.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Exabeam New-Scale Analytics |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Monitored users — grows with headcount |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Logs arrive from Exabeam's collectors or from the SIEM you already run, parsed into a common schema. In augmentation mode you do not restructure your existing pipeline — data is fed across without reconfiguring what feeds your current SIEM.
Disparate identifiers — AD account, email, VPN username, cloud IAM principal, hostname — stitched into one entity. The least visible and most decisive component: behavioural analytics on unresolved identities produces confident nonsense.
Statistical and ML models profile normal for each user, peer group, host and service account across hundreds of dimensions — logon times, geographies, data volumes, privilege use. Models retrain as behaviour legitimately drifts.
Individual anomalies rarely justify an investigation; accumulated ones do. Weighted risk aggregates per entity, adjusted by business context — a domain admin's anomaly should outrank a contractor's identical one.
When an entity crosses a threshold, evidence is collected, correlated and enriched into a Smart Timeline the analyst reads top to bottom, rather than reconstructing across consoles.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Feeds from Splunk, Sentinel, QRadar and ArcSight without rebuilding your pipeline.
Heterogeneous sources parsed into one schema so behaviour is comparable across systems.
Accounts, hostnames, emails and cloud principals stitched into single resolved identities.
HR, asset criticality and org data layered on so scoring reflects real business risk.
Learns normal per user, peer group, host and service account across hundreds of dimensions.
Weighted risk accumulates per entity so weak signals surface only once they collectively matter.
Credential misuse, data staging and privilege abuse that rule-based detection routinely misses.
Anomalous authentication chains across hosts, exposing movement after initial compromise.
Behavioural baselining applied to AI agent activity — tool use and data egress.
A readable chronological session narrative, so analysts stop pivoting between consoles.
Agents handle case summaries, natural-language search and dashboards.
Detection coverage mapped to MITRE ATT&CK, with gaps stated in language a board follows.
Endpoint protection, XDR and Security Copilot.
Behavioural analytics in the analyst workflow.
Where analytics sits in the platform.
The SIEM it can run inside — or beside.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
The most useful thing about New-Scale Analytics is that you can license it against a SIEM you already own. Most organisations unhappy with their SIEM are not unhappy with its log storage — they are unhappy that it only catches what someone wrote a rule for. Replacing a SIEM is a multi-quarter project: re-onboarding every log source, rewriting detections, retraining analysts, renegotiating a large contract. Augmenting one is a fraction of that. You keep Splunk or Sentinel or QRadar doing the unglamorous work it does adequately, and add a behavioural layer that finds what rules structurally cannot. For an enterprise three years into a Splunk deployment, with a CISO who wants better insider-threat coverage and a CFO who will not fund a rip-and-replace, this is the version of the project that actually gets approved. It is also a materially smaller commercial commitment, which changes who has to sign.
Most alert-fatigue solutions are triage — sorting a flood after it arrives. Behavioural risk scoring works earlier. Individual anomalies are usually meaningless: people travel, projects change, someone genuinely does need the customer database on a Friday night. A rule-based system fires on each and drowns the analyst. Risk scoring accumulates weighted deviation against an entity and surfaces it only when the total crosses a threshold, so the analyst sees one enriched entity worth investigating rather than forty events to dismiss. Multi-layer scoring with business context means a domain administrator's anomaly outranks a contractor's identical one. Exabeam publishes alert-volume reductions up to 60 percent; treat that as a vendor figure, because the real reduction depends entirely on how noisy your baseline is and how much tuning you invest. The mechanism, though, is the correct one.
The dominant cost in a SOC is not detection, it is investigation. An analyst receiving an alert pivots across the SIEM, the EDR console, the identity provider, the DLP tool and a spreadsheet of asset owners to assemble what happened. That reconstruction is repetitive, slow, and where most analyst hours vanish. Smart Timelines do it automatically — the session arrives as a chronological narrative with evidence already correlated and enriched. The analyst reads rather than assembles. For teams running follow-the-sun SOCs or MSSP arrangements where tier-one turnover is high, this materially lowers the skill floor for useful triage. It also fixes handover: a timeline is a document a new analyst can pick up, where a half-finished pivot across six tools is not.
Licensing on monitored users, sources and modules rather than gigabytes matters more than it sounds. Volume metering creates a perverse incentive at exactly the wrong moment: teams stop onboarding log sources, sample noisy ones, or cut retention to control spend — and the blind spots that result sit precisely where attackers operate. It also makes budgeting adversarial, because a cloud migration or a chatty new application moves your bill without anyone deciding anything. User- and source-based licensing tracks something you control and can forecast: headcount grows predictably, log volume does not. Securonix, the closest UEBA-led competitor, prices on GB/day. This is a structural difference, not a discount — though it is quote-only with no published list, and we would be misleading you to imply otherwise.
Five things worth knowing before you commit. Baselining takes time: UEBA cannot score deviation until it knows normal, so expect weeks before output is trustworthy, and treat any promise of immediate value as a warning about the salesperson. Tuning is ongoing work, not a phase — every real environment produces benign anomalies, and suppressing them without suppressing real threats needs a named owner; deployments that disappoint almost always disappoint here. Identity data quality is a prerequisite you must meet yourself: stale AD accounts and unreliable HR feeds degrade entity resolution, and the models inherit that. In augmentation mode you pay for both products — this adds to your SIEM spend rather than displacing it. And Exabeam is still integrating the LogRhythm merger, so ask for written roadmap commitments for whichever line you buy.
Choose New-Scale Analytics when your detection gap is behavioural — insider threat, credential misuse, lateral movement, accounts that look legitimate because the credentials are — and especially when you own a SIEM you are not ready to replace. The augmentation licence is the strongest reason to shortlist it. Do not choose it if what you need is a SIEM: this is a detection layer and something must still collect and retain. Do not choose it if you need value inside a quarter. Be cautious if your identity data is in poor shape, because that is a prerequisite rather than something the product fixes. If you want a single cloud-native platform with no self-hosted legacy line, Securonix is the more direct comparison and a legitimate winner — TechBag sells it and will say so. If your SOC is small and Microsoft-centric, Sentinel's own UEBA may be sufficient and cheaper.
Establish whether your gap is detection quality or log management — that determines which licence you buy. Audit what your SIEM catches and what it structurally cannot. Inventory identity data quality honestly.
Feed from your existing SIEM or Exabeam collectors, confirm parsing across sources, and validate entity resolution against known users. In augmentation mode you should not be rebuilding pipelines.
Behavioural models need observation before scoring means anything. Resist acting on early scores. Use the window to layer business context — asset criticality, HR attributes, privileged groups.
Suppress benign anomalies, calibrate thresholds, build workflows around Smart Timelines. Assign a named platform owner. This phase does not end — it becomes routine operational work.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We kept Splunk and bought Analytics on top. That was the only version of this project our board would have approved — a SIEM replacement was never getting funded.”
“Smart Timelines cut our tier-one investigation time by more than half. Analysts read a narrative instead of assembling one across five consoles.”
“The risk scoring genuinely surfaces things our rules never would. An account doing six mildly odd things is invisible to a rule engine and obvious here.”
“Pricing on users and sources rather than GB means I can onboard a new log source without a budget conversation. That changed our coverage more than any feature did.”
“Good product, but nobody told us how much tuning it needs. The first two months were noisy and we nearly gave up before it settled. Budget a dedicated owner or do not start.”
“Nova's investigation summaries are useful for shift handovers. Not magic, but it saves each analyst real time every day.”
“Insider threat was our driver. We found two cases of data staging in the first quarter that our previous stack had no mechanism to catch.”
“Our AD hygiene was worse than we admitted and entity resolution exposed it immediately. Painful, but the cleanup was overdue and the models improved sharply afterwards.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
UEBA heritage, with a real self-hosted answer.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Behavioural depth, and a meter that suits big volume.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Exabeam | Securonix | Splunk Enterprise Security | Microsoft Sentinel | Elastic Security |
|---|---|---|---|---|---|
| Position | UEBA-led SecOps, cloud AND self-hosted | The other UEBA-led vendor | The reference SIEM | SIEM for Microsoft estates | Search-engine-native SIEM |
| Pricing axis | Monitored users + sources + modules | GB/day, hybrid commitment + PAYG | Ingest or workload — historically costly | Per GB ingested per day | Subscription tier + resources |
| Behavioural analytics | The founding capability | The founding capability | Available, an add-on heritage | UEBA included | Entity risk scoring |
| Self-hosted option | LogRhythm SIEM — genuinely on-prem | Cloud-native only | Cloud, on-prem or hybrid | SaaS only, on Azure | Self-managed, even air-gapped |
| Analyst standing (SIEM MQ 2025) | Long-running MQ presence | Leader, six times running | Leader | Leader | Visionary, not Leader |
| Augments a SIEM you own | New-Scale Analytics, licensed separately | UEBA available | Buy the platform | Buy the platform | Buy the platform |
| AI in the SOC | Nova — seven agents, named jobs | Sam, the AI SOC analyst | Cisco AI Assistant | Security Copilot + MCP | Elastic AI Assistant |
| Talent pool | Smaller than the incumbents | Smaller than the incumbents | SPL — the largest by far | KQL — widely known | Large for the engine, smaller for security |
| The thing to plan around | Two platforms post-merger — ask the roadmap | Cloud-only; model the GB/day | Cisco integration reshaping roadmap | Azure portal retires 31 Mar 2027 | You operate it unless you buy Cloud |
| Best fit | Large log volume, small team — or on-prem | UEBA-led with Leader standing | Engineers who will build with it | Microsoft-standardised estates | Air-gapped, or existing ELK |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Exabeam New-Scale Analytics is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Exabeam meters on monitored users; most of the category meters on gigabytes ingested. Which is cheaper depends entirely on the ratio between your log volume and your headcount — and it genuinely goes both ways, so this calculator will tell you when a rival is the better buy. Illustrative only: Exabeam is quote-only with no published list, and the comparator is an ingest-metered SIEM at roughly ₹249/GB. Move both sliders to find your crossover.
If the saving reads zero, the ingest-priced SIEM is cheaper for your shape and you should buy that one — a large workforce with modest logs is exactly the case where Exabeam’s meter works against you. Neither figure is a quote. TechBag models both properly before recommending either.
Quote-only, on the same monitored-users axis as the rest of the portfolio. The commercially important option here is that Analytics can be licensed to augment a SIEM you already run rather than only as part of New-Scale — if your log platform works and the problem is that nobody trusts its alerts, that is a much smaller and cheaper purchase than replacing it. TechBag scopes which of the two you actually need, in INR with GST.
Best if your log platform is fine
Best if you are replacing anyway
Best for triage load
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Can I license Analytics against my existing SIEM, and what does that quote include versus Fusion?
How are monitored users counted — named, active, or every directory object? The difference is large.
Has my specific SIEM and log-source mix been deployed in augmentation mode before? Can I speak to that customer?
How long until risk scores are trustworthy at my size, and what will the vendor commit to in writing?
How much FTE time do comparable customers spend tuning in months one to six, and then steady-state?
What entity-resolution accuracy should I expect given the state of my AD and HR feeds?
Given the LogRhythm merger, what is the committed roadmap for the line I am buying?
If I augment now and replace my SIEM in two years, what carries over and what restarts?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.