Talk to us
by ExabeamTechBag Intel Page

Exabeam New-Scale Analytics

The layer that catches a valid credential in the wrong hands — Exabeam New-Scale Analytics baselines every user and machine and scores the deviation, and it can run on a SIEM you already own.

Augments your existing SIEMBaselines, not signaturesThe capability Exabeam is known for

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Detection depth
risk scoring and Smart Timelines
Strong
Deployment
augments your existing SIEM
Layer or platform
Pricing
bills do not spike with volume
Users, not GB
Time to value
baselining is not negotiable
Weeks, not days

Data residency & processing — confirm before the PoC

Delivery

Cloud-native (New-Scale)

This is the cloud half of the portfolio. If your mandate rules out SaaS, LogRhythm SIEM is the self-hosted answer from the same vendor.

What to confirm

Region — and processing, separately

Storage residency and processing residency are two different commitments. Get both in writing for your region.

If your obligation requires data to stay in India, settle storage and processing separately with Exabeam before a proof of concept. If it rules out cloud entirely, see LogRhythm SIEM, which answers both by definition.

Quick answer

Exabeam New-Scale Analytics is the behavioural analytics engine at the centre of Exabeam's platform — user and entity behaviour analytics plus dynamic risk scoring. Rather than matching logs against static rules, it builds a baseline of normal behaviour for every user, host and service account, then scores deviation from it. A finance user pulling ten times their usual volume at 2am from an unfamiliar network accumulates risk across several weak signals until the total is worth an analyst's attention. Those signals assemble into Smart Timelines — a chronological reconstruction an analyst reads instead of pivoting across six consoles. The commercially important point, and the reason this page exists separately from Exabeam's SIEM pages: New-Scale Analytics can be licensed to AUGMENT a SIEM you already own. If you run Splunk, Microsoft Sentinel, QRadar or ArcSight and your problem is detection quality rather than log storage, you can feed that SIEM's data across and keep everything else. That is a far smaller purchase, and a far smaller project, than replacing a SIEM. Pricing is quote-only on monitored users, sources and modules — deliberately not metered on gigabytes ingested. Honest caveats, and they matter: UEBA needs a behavioural baseline, so expect weeks before scoring is trustworthy, and expect ongoing tuning to suppress the benign anomalies every real environment produces. It is a detection layer, not a SIEM — in augmentation mode you are paying for both. Identity data quality is decisive and largely outside the product's control: if your AD and HR records are messy, the models inherit that. TechBag sells Securonix and Splunk too. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Exabeam New-Scale Analytics — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
Exabeam New-Scale Analytics (UEBA)
Vendor
Exabeam (merged with LogRhythm, July 2024)
Ownership
Thoma Bravo · CEO Pete Harteveld
The key option
Can augment a SIEM you already own
Augments
Splunk, Sentinel, QRadar, ArcSight
Priced on
Monitored users + sources + modules
Not priced on
Gigabytes ingested
Published pricing
None — quote-only
Prerequisite
Clean identity data — AD and HR feeds
In India via
TechBag — scoping, GST invoicing
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

The behavioural analytics engine — baselines for every user and machine, and dynamic risk scoring on deviation. The capability Exabeam is actually known for.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolExabeam New-Scale Analytics
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownMonitored users — grows with headcount
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The intake

Data ingestion

Collect

Logs arrive from Exabeam's collectors or from the SIEM you already run, parsed into a common schema. In augmentation mode you do not restructure your existing pipeline — data is fed across without reconfiguring what feeds your current SIEM.

02
The foundation

Entity resolution

Identity graph

Disparate identifiers — AD account, email, VPN username, cloud IAM principal, hostname — stitched into one entity. The least visible and most decisive component: behavioural analytics on unresolved identities produces confident nonsense.

03
The learning

Behavioural models

Baselining

Statistical and ML models profile normal for each user, peer group, host and service account across hundreds of dimensions — logon times, geographies, data volumes, privilege use. Models retrain as behaviour legitimately drifts.

04
The ranking

Dynamic risk scoring

Prioritisation

Individual anomalies rarely justify an investigation; accumulated ones do. Weighted risk aggregates per entity, adjusted by business context — a domain admin's anomaly should outrank a contractor's identical one.

05
The output

Threat Center

Investigation

When an entity crosses a threshold, evidence is collected, correlated and enriched into a Smart Timeline the analyst reads top to bottom, rather than reconstructing across consoles.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Ingestion

Bring your own SIEM

Feeds from Splunk, Sentinel, QRadar and ArcSight without rebuilding your pipeline.

Collect
Normalisation

Common schema parsing

Heterogeneous sources parsed into one schema so behaviour is comparable across systems.

Collect
Identity

Entity resolution

Accounts, hostnames, emails and cloud principals stitched into single resolved identities.

Collect
Context

Business enrichment

HR, asset criticality and org data layered on so scoring reflects real business risk.

Detect
Baselining

Behavioural profiling

Learns normal per user, peer group, host and service account across hundreds of dimensions.

Detect
Scoring

Dynamic risk scoring

Weighted risk accumulates per entity so weak signals surface only once they collectively matter.

Detect
Insider

Insider threat detection

Credential misuse, data staging and privilege abuse that rule-based detection routinely misses.

Detect
Lateral

Lateral movement

Anomalous authentication chains across hosts, exposing movement after initial compromise.

Detect
Agents

Agent Behavior Analytics

Behavioural baselining applied to AI agent activity — tool use and data egress.

Respond
Timelines

Smart Timelines

A readable chronological session narrative, so analysts stop pivoting between consoles.

Respond
Nova

AI agent assistance

Agents handle case summaries, natural-language search and dashboards.

Respond
Reporting

Coverage reporting

Detection coverage mapped to MITRE ATT&CK, with gaps stated in language a board follows.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Exabeam (official)·UEBA

Introducing New-Scale Analytics — Analyst Workflow

Behavioural analytics in the analyst workflow.

Exabeam (official)·Platform

The AI-Driven Exabeam Security Operations Platform

Where analytics sits in the platform.

Exabeam (official)·SIEM

Exabeam SIEM Overview

The SIEM it can run inside — or beside.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why New-Scale Analytics

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

It buys detection quality without a SIEM migration

The most useful thing about New-Scale Analytics is that you can license it against a SIEM you already own. Most organisations unhappy with their SIEM are not unhappy with its log storage — they are unhappy that it only catches what someone wrote a rule for. Replacing a SIEM is a multi-quarter project: re-onboarding every log source, rewriting detections, retraining analysts, renegotiating a large contract. Augmenting one is a fraction of that. You keep Splunk or Sentinel or QRadar doing the unglamorous work it does adequately, and add a behavioural layer that finds what rules structurally cannot. For an enterprise three years into a Splunk deployment, with a CISO who wants better insider-threat coverage and a CFO who will not fund a rip-and-replace, this is the version of the project that actually gets approved. It is also a materially smaller commercial commitment, which changes who has to sign.

02

Risk scoring attacks alert volume at the right end

Most alert-fatigue solutions are triage — sorting a flood after it arrives. Behavioural risk scoring works earlier. Individual anomalies are usually meaningless: people travel, projects change, someone genuinely does need the customer database on a Friday night. A rule-based system fires on each and drowns the analyst. Risk scoring accumulates weighted deviation against an entity and surfaces it only when the total crosses a threshold, so the analyst sees one enriched entity worth investigating rather than forty events to dismiss. Multi-layer scoring with business context means a domain administrator's anomaly outranks a contractor's identical one. Exabeam publishes alert-volume reductions up to 60 percent; treat that as a vendor figure, because the real reduction depends entirely on how noisy your baseline is and how much tuning you invest. The mechanism, though, is the correct one.

03

Smart Timelines change what tier-one analysts actually do

The dominant cost in a SOC is not detection, it is investigation. An analyst receiving an alert pivots across the SIEM, the EDR console, the identity provider, the DLP tool and a spreadsheet of asset owners to assemble what happened. That reconstruction is repetitive, slow, and where most analyst hours vanish. Smart Timelines do it automatically — the session arrives as a chronological narrative with evidence already correlated and enriched. The analyst reads rather than assembles. For teams running follow-the-sun SOCs or MSSP arrangements where tier-one turnover is high, this materially lowers the skill floor for useful triage. It also fixes handover: a timeline is a document a new analyst can pick up, where a half-finished pivot across six tools is not.

04

Pricing that does not punish you for collecting logs

Licensing on monitored users, sources and modules rather than gigabytes matters more than it sounds. Volume metering creates a perverse incentive at exactly the wrong moment: teams stop onboarding log sources, sample noisy ones, or cut retention to control spend — and the blind spots that result sit precisely where attackers operate. It also makes budgeting adversarial, because a cloud migration or a chatty new application moves your bill without anyone deciding anything. User- and source-based licensing tracks something you control and can forecast: headcount grows predictably, log volume does not. Securonix, the closest UEBA-led competitor, prices on GB/day. This is a structural difference, not a discount — though it is quote-only with no published list, and we would be misleading you to imply otherwise.

05

The honest caveats — where this will frustrate you

Five things worth knowing before you commit. Baselining takes time: UEBA cannot score deviation until it knows normal, so expect weeks before output is trustworthy, and treat any promise of immediate value as a warning about the salesperson. Tuning is ongoing work, not a phase — every real environment produces benign anomalies, and suppressing them without suppressing real threats needs a named owner; deployments that disappoint almost always disappoint here. Identity data quality is a prerequisite you must meet yourself: stale AD accounts and unreliable HR feeds degrade entity resolution, and the models inherit that. In augmentation mode you pay for both products — this adds to your SIEM spend rather than displacing it. And Exabeam is still integrating the LogRhythm merger, so ask for written roadmap commitments for whichever line you buy.

06

The honest positioning

Choose New-Scale Analytics when your detection gap is behavioural — insider threat, credential misuse, lateral movement, accounts that look legitimate because the credentials are — and especially when you own a SIEM you are not ready to replace. The augmentation licence is the strongest reason to shortlist it. Do not choose it if what you need is a SIEM: this is a detection layer and something must still collect and retain. Do not choose it if you need value inside a quarter. Be cautious if your identity data is in poor shape, because that is a prerequisite rather than something the product fixes. If you want a single cloud-native platform with no self-hosted legacy line, Securonix is the more direct comparison and a legitimate winner — TechBag sells it and will say so. If your SOC is small and Microsoft-centric, Sentinel's own UEBA may be sufficient and cheaper.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

up to 60%
Alert-volume reduction — Exabeam's own figure, test it
Vendor claim*
7 Nova agents
Scoped to named SOC jobs
Exabeam
4 SIEMs augmented
Splunk, Sentinel, QRadar, ArcSight
Exabeam
3 licence tiers
SIEM, Analytics, or Fusion
Portfolio
2024
Exabeam and LogRhythm merged, July
Company
0 GB metering
Priced on identities, not ingest volume
The meter

What your Exabeam New-Scale Analytics rollout looks like

Phase 1Scope

Decide augment or replace

Establish whether your gap is detection quality or log management — that determines which licence you buy. Audit what your SIEM catches and what it structurally cannot. Inventory identity data quality honestly.

Phase 2Integrate

Connect the data

Feed from your existing SIEM or Exabeam collectors, confirm parsing across sources, and validate entity resolution against known users. In augmentation mode you should not be rebuilding pipelines.

Phase 3Baseline

Let the models learn

Behavioural models need observation before scoring means anything. Resist acting on early scores. Use the window to layer business context — asset criticality, HR attributes, privileged groups.

Phase 4Operate

Make it trustworthy

Suppress benign anomalies, calibrate thresholds, build workflows around Smart Timelines. Assign a named platform owner. This phase does not end — it becomes routine operational work.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Financial Services
We kept Splunk and bought Analytics on top. That was the only version of this project our board would have approved — a SIEM replacement was never getting funded.
Head of Security Operations
Financial Services
IT Services
Smart Timelines cut our tier-one investigation time by more than half. Analysts read a narrative instead of assembling one across five consoles.
SOC Manager
IT Services
Manufacturing
The risk scoring genuinely surfaces things our rules never would. An account doing six mildly odd things is invisible to a rule engine and obvious here.
Security Architect
Manufacturing
Retail
Pricing on users and sources rather than GB means I can onboard a new log source without a budget conversation. That changed our coverage more than any feature did.
CISO
Retail
Healthcare
Good product, but nobody told us how much tuning it needs. The first two months were noisy and we nearly gave up before it settled. Budget a dedicated owner or do not start.
Security Engineer
Healthcare
Banking
Nova's investigation summaries are useful for shift handovers. Not magic, but it saves each analyst real time every day.
Deputy CISO
Banking
Pharmaceuticals
Insider threat was our driver. We found two cases of data staging in the first quarter that our previous stack had no mechanism to catch.
Head of Information Security
Pharmaceuticals
Telecom
Our AD hygiene was worse than we admitted and entity resolution exposed it immediately. Painful, but the cleanup was overdue and the models improved sharply afterwards.
Infrastructure Security Lead
Telecom
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ExabeamThis page

UEBA heritage, with a real self-hosted answer.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
ExabeamThis page

Behavioural depth, and a meter that suits big volume.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Exabeam New-Scale Analytics vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionExabeamSecuronixSplunk Enterprise SecurityMicrosoft SentinelElastic Security
PositionUEBA-led SecOps, cloud AND self-hostedThe other UEBA-led vendorThe reference SIEMSIEM for Microsoft estatesSearch-engine-native SIEM
Pricing axisMonitored users + sources + modulesGB/day, hybrid commitment + PAYGIngest or workload — historically costlyPer GB ingested per daySubscription tier + resources
Behavioural analyticsThe founding capabilityThe founding capabilityAvailable, an add-on heritageUEBA includedEntity risk scoring
Self-hosted optionLogRhythm SIEM — genuinely on-premCloud-native onlyCloud, on-prem or hybridSaaS only, on AzureSelf-managed, even air-gapped
Analyst standing (SIEM MQ 2025)Long-running MQ presenceLeader, six times runningLeaderLeaderVisionary, not Leader
Augments a SIEM you ownNew-Scale Analytics, licensed separatelyUEBA availableBuy the platformBuy the platformBuy the platform
AI in the SOCNova — seven agents, named jobsSam, the AI SOC analystCisco AI AssistantSecurity Copilot + MCPElastic AI Assistant
Talent poolSmaller than the incumbentsSmaller than the incumbentsSPL — the largest by farKQL — widely knownLarge for the engine, smaller for security
The thing to plan aroundTwo platforms post-merger — ask the roadmapCloud-only; model the GB/dayCisco integration reshaping roadmapAzure portal retires 31 Mar 2027You operate it unless you buy Cloud
Best fitLarge log volume, small team — or on-premUEBA-led with Leader standingEngineers who will build with itMicrosoft-standardised estatesAir-gapped, or existing ELK
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Exabeam New-Scale Analytics fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Exabeam if…

  • Your log volume is large relative to your security headcount — the user-based meter favours exactly that shape
  • You need behavioural analytics rather than more rules, and you want the vendor that built on it
  • Your mandate rules out cloud — LogRhythm SIEM is a genuine self-hosted platform, not a retrofit
  • You want to add analytics to a SIEM you already own rather than replace it

Choose Securonix if…

  • You want the other UEBA-led vendor, with six consecutive Gartner MQ Leader placements — and cloud-native suits you

Choose Splunk if…

  • You have engineers who will build with it, and you want the deepest content and the largest talent pool (TechBag sells it)

Choose Microsoft Sentinel if…

  • Your estate is Microsoft — first-party logs ingest free and SIEM shares the Defender incident queue

Choose Elastic Security if…

  • You need air-gapped deployment, or your engineers already run Elasticsearch

Exabeam New-Scale Analytics is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Exabeam meters on monitored users; most of the category meters on gigabytes ingested. Which is cheaper depends entirely on the ratio between your log volume and your headcount — and it genuinely goes both ways, so this calculator will tell you when a rival is the better buy. Illustrative only: Exabeam is quote-only with no published list, and the comparator is an ingest-metered SIEM at roughly ₹249/GB. Move both sliders to find your crossover.

2,000
25050,000
300
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is cheaper for your shape and you should buy that one — a large workforce with modest logs is exactly the case where Exabeam’s meter works against you. Neither figure is a quote. TechBag models both properly before recommending either.

An ingest-metered SIEM, at your GB/day
₹2,72,26,080
Difference vs Exabeam’s user meter
₹2,43,26,080
₹12,16,30,400 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote-only, on the same monitored-users axis as the rest of the portfolio. The commercially important option here is that Analytics can be licensed to augment a SIEM you already run rather than only as part of New-Scale — if your log platform works and the problem is that nobody trusts its alerts, that is a much smaller and cheaper purchase than replacing it. TechBag scopes which of the two you actually need, in INR with GST.

Augment your SIEM

Quoteanalytics only

Best if your log platform is fine

  • Adds behavioural analytics without replacing your SIEM
  • A far smaller decision than a migration
  • The option vendors rarely volunteer

Inside New-Scale

Quotepart of the platform

Best if you are replacing anyway

  • Analytics and SIEM on one platform, one contract
  • Dynamic risk scoring across the estate
  • Smart Timelines assembled automatically

+ Nova agents

QuoteAI module

Best for triage load

  • AI agents over the scored risk
  • Threat scoring and investigation agents
  • Prove it on your own alerts first

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Licensing

Can I license Analytics against my existing SIEM, and what does that quote include versus Fusion?

2
Pricing units

How are monitored users counted — named, active, or every directory object? The difference is large.

3
Integration

Has my specific SIEM and log-source mix been deployed in augmentation mode before? Can I speak to that customer?

4
Baselining

How long until risk scores are trustworthy at my size, and what will the vendor commit to in writing?

5
Tuning burden

How much FTE time do comparable customers spend tuning in months one to six, and then steady-state?

6
Identity data

What entity-resolution accuracy should I expect given the state of my AD and HR feeds?

7
Roadmap

Given the LogRhythm merger, what is the committed roadmap for the line I am buying?

8
Exit

If I augment now and replace my SIEM in two years, what carries over and what restarts?

FAQ

Questions buyers ask

New-Scale Analytics is Exabeam's user and entity behaviour analytics and risk-scoring engine. Where a traditional SIEM detects threats by matching events against rules someone wrote in advance, this builds a statistical baseline of normal behaviour for every user, host, peer group and service account, then scores deviation from it. The practical difference matters. A rule engine can tell you a login came from an unusual country. It cannot easily tell you that a particular finance user logged in at an unusual hour, from an unfamiliar network, touched repositories they never use, and moved ten times their normal data volume — and that those four individually unremarkable facts together describe a compromised account. Behavioural analytics accumulates weighted risk across weak signals until the total is worth an analyst's time. Around that core sit several components. Entity resolution stitches the many identifiers a person has — AD account, email, VPN username, cloud principal — into one identity. Dynamic risk scoring applies weighting adjusted by business context, so a domain administrator's anomaly outranks a contractor's identical one. Threat Center and Smart Timelines assemble evidence into a chronological narrative an analyst reads rather than reconstructs. Exabeam Nova, a set of AI agents scoped to named SOC jobs, handles summarisation, natural-language search and reporting. More recently Exabeam extended the same approach to AI agents themselves — behavioural baselining for autonomous agent activity, which is genuinely early and worth evaluating on its merits rather than assuming maturity.

Ready to evaluate Exabeam New-Scale Analytics?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.