Talk to us
by ExabeamTechBag Intel Page

Exabeam New-Scale SIEM

The SIEM priced on people, not gigabytes — Exabeam New-Scale SIEM meters on monitored users, sources and modules, which inverts the cost curve if your log volume is large and your team is not.

Priced on users, not GB ingestedThe platform the merger standardised onBehavioural analytics built in

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
What it is
the post-merger standard
Cloud SIEM
The meter
not gigabytes
Monitored users
The heritage
baselines, not just rules
UEBA built in
Honest note
no published list
Quote-only

Data residency & processing — confirm before the PoC

Delivery

Cloud-native (New-Scale)

This is the cloud half of the portfolio. If your mandate rules out SaaS, LogRhythm SIEM is the self-hosted answer from the same vendor.

What to confirm

Region — and processing, separately

Storage residency and processing residency are two different commitments. Get both in writing for your region.

If your obligation requires data to stay in India, settle storage and processing separately with Exabeam before a proof of concept. If it rules out cloud entirely, see LogRhythm SIEM, which answers both by definition.

Quick answer

Exabeam New-Scale SIEM is the cloud-native SIEM the combined Exabeam-LogRhythm company standardised on after their July 2024 merger — LogRhythm's competing cloud product, Axon, was retired in its favour, which tells you where the investment goes. It does what a SIEM does: collects logs from across the estate, correlates them, raises incidents and gives analysts a place to investigate. What makes it commercially distinctive is the meter. Most of this category charges per gigabyte ingested, so the bill grows every year whether or not your organisation does, because log volume grows on its own — more cloud services, more verbose applications, more telemetry per endpoint. Exabeam meters on MONITORED USERS plus sources plus modules, which tracks your headcount instead. For a cloud-native organisation with enormous log volume and a small security team, that inversion can be worth a great deal; for a large workforce generating modest logs, it runs the other way. There is no shortcut — you have to model both. The other thing you get is Exabeam's behavioural analytics heritage: New-Scale Analytics ships alongside, so detections are baselined rather than purely rule-matched. Pricing is quote-only with no published list. The honest caveats: the talent pool is smaller than for Splunk or Microsoft, and a two-platform portfolio after a merger deserves a direct roadmap question. TechBag sells Splunk, Sentinel and Securonix too, and will model the user-count bill against the ingest-priced alternatives, in INR with GST. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Exabeam New-Scale SIEM — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
Exabeam New-Scale SIEM
Vendor
Exabeam (Thoma Bravo-backed)
Category
Cloud-native SIEM + log management
Priced on
Monitored users + sources + modules
Not priced on
Gigabytes ingested — the usual axis
The merger
The cloud platform Axon was retired for
Analytics
New-Scale Analytics ships alongside
Deployment
Cloud-native (LogRhythm SIEM is the on-prem half)
Published pricing
None — quote-only
In India via
TechBag — user-count modelling, GST invoicing
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Exabeam’s cloud-native SIEM — the platform the LogRhythm merger standardised on. Collection, correlation and cases, with behavioural analytics built in rather than bolted on.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolExabeam New-Scale SIEM
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownMonitored users — grows with headcount
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The ingest

Cloud collection

The intake

Log collection from cloud, on-premises and SaaS sources into the cloud platform. Because the meter is users rather than volume, adding a noisy source does not carry the cost penalty it would on an ingest-priced SIEM.

02
The baseline

Correlation & detection

The rules

Standard correlation and detection content, with the behavioural layer alongside rather than bolted on — so a detection can reference an entity's risk score, not only the event in front of it.

03
The differentiator

New-Scale Analytics

UEBA

Behavioural baselines for every user and machine, with dynamic risk scoring. This is the capability Exabeam is known for and the reason the SIEM's detections behave differently from a purely rule-based one.

04
The time saver

Smart Timelines

The investigation

The chronological reconstruction of an entity's activity, assembled automatically rather than queried for. The measurable saving is analyst minutes per investigation, which is the thing that actually scales a SOC.

05
The AI

Exabeam Nova

The agents

Seven AI agents scoped to named SOC jobs — threat scoring, investigation, analyst assistance, rule creation, search, advisory and visualisation — licensed as a module across both platforms.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Ingest

Cloud log collection

Sources across cloud, on-premises and SaaS, into the cloud platform.

Collect
User meter

Priced on monitored users

Adding a noisy source does not carry the usual per-GB cost penalty.

Collect
Parsers

Prebuilt source content

Parsing and normalisation for common security and infrastructure sources.

Collect
Retention

Cloud retention tiers

Retention configured per your mandate rather than fixed by the licence.

Detect
Correlation

Detection rules

Standard correlation content, referencing entity risk as well as events.

Detect
UEBA

Behavioural baselines

What each user and machine normally does — and scored deviation from it.

Detect
Risk scoring

Dynamic risk accumulation

Small signals accumulate on an entity until the sequence is alarming.

Detect
Timelines

Smart Timelines

Entity activity reconstructed automatically, not queried for.

Respond
Search

Investigation search

Query across collected data during an investigation.

Respond
Cases

Case management

Investigations, evidence and workflow in the platform.

Respond
Automation

Response actions

Automated and analyst-triggered response across integrations.

Respond
Nova agents

AI agents in the workflow

Seven agents scoped to named SOC jobs, licensed as a module.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Exabeam (official)·Overview

Exabeam SIEM Overview

The SIEM, explained by Exabeam.

Exabeam (official)·Platform

The AI-Driven Exabeam Security Operations Platform

Where the SIEM sits in the platform.

Exabeam (official)·Analytics

Introducing New-Scale Analytics — Analyst Workflow

The behavioural layer it ships with.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why New-Scale

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

The meter is the argument, and it cuts both ways

Almost every SIEM in this category charges for gigabytes ingested, which means the bill grows every single year regardless of whether your organisation grows. Log volume expands on its own: you adopt another cloud service, an application gets more verbose, endpoint telemetry gets richer. Teams end up making retention and coverage decisions on budget rather than risk, which is exactly backwards. Exabeam meters on monitored users plus sources plus modules — your identity count, which tracks headcount and is therefore far more predictable to forecast. For a cloud-native organisation with enormous log volume and a small security team, that inversion is worth a great deal of money. Here is the honest other half: if you have a large workforce generating modest log volume, the arithmetic runs the other way and an ingest-priced SIEM will be cheaper. This is not a universally better meter, it is a differently-shaped one, and which shape fits is an arithmetic question you must actually do rather than assume.

02

Behavioural analytics as the product, not an add-on

Exabeam built on UEBA before the category had a name, and New-Scale Analytics ships as part of this platform rather than as a module you discover you need later. The practical consequence is what happens with a stolen credential. A rule-based SIEM has nothing to match: the login is valid, the source is plausible, the actions are permitted. Nothing is malformed, so nothing fires. A behavioural system has a baseline of what that identity normally does — hours, systems, volumes, sequences — and scores the deviation. Given that credential abuse is now the dominant initial-access route, that difference is not academic. It also changes what your analysts spend time on: instead of tuning rules to suppress noise, they are working a ranked risk list.

03

Smart Timelines, and the minutes that actually scale a SOC

The unglamorous truth about security operations is that most analyst time goes on reconstruction — what did this account do, in what order, across which systems, over what period. Analysts do it by querying, repeatedly, and it is slow. Exabeam assembles that timeline automatically for the entity in question. The saving is minutes per investigation, and minutes per investigation is precisely the number that determines how many incidents a given team can actually work. Capability comparisons rarely capture this because it is not a feature you can tick; it shows up as throughput. When you evaluate, time a real investigation on your own data rather than reading the feature list.

04

Two platforms — and the on-premises one is real

The July 2024 LogRhythm merger left Exabeam with a genuinely unusual position: New-Scale for cloud, LogRhythm SIEM for self-hosted, with Axon retired to avoid overlap. Most vendors serve one deployment model well and treat the other as an afterthought, and several claim on-premises capability that turns out to mean a hosted appliance with cloud dependencies. LogRhythm SIEM is a mature product with over 1,100 prebuilt correlation rules and a long record in regulated and government estates. So if your mandate rules out cloud, you are not being handed a compromise — and for Indian buyers under DPDP or RBI, SEBI and IRDAI expectations, self-hosted answers both the storage and processing residency questions by definition. See the LogRhythm SIEM page for that side.

05

The honest caveat — smaller talent pool, and a fair roadmap question

Being straight, and TechBag sells the alternatives: the pool of people who already know Exabeam is materially smaller than for Splunk or Microsoft Sentinel. SPL and KQL are on a great many CVs; Exabeam experience is on fewer, which affects hiring, contractor availability and how quickly a new analyst becomes productive. Second, any two-platform portfolio after a merger invites a question about where investment goes, and Axon's retirement demonstrates this company will consolidate where products overlap. New-Scale and LogRhythm SIEM do not overlap — they serve different deployment models — but ask for the roadmap commitment in writing anyway, for whichever one you are buying. A vendor confident in its plan will provide it, and the request costs you nothing.

06

The honest positioning

Exabeam New-Scale SIEM is the right choice when your log volume is large relative to your security headcount, because the user-based meter is built for exactly that shape; when you want behavioural detection as the product rather than rules you maintain; and when you value having a genuine on-premises option in the same portfolio. It is the wrong choice when your workforce is large and your logs are modest — the meter works against you — or when you need the largest talent pool and deepest content library, which is Splunk. TechBag sells Splunk, Microsoft Sentinel, Securonix and Elastic as well, and will do the arithmetic both ways before recommending, quoted in INR with GST.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

1100+ rules
Prebuilt correlation content in the self-hosted sibling
Exabeam
7 Nova agents
Scoped to named SOC jobs
Exabeam
2024
LogRhythm merger completed, July
Company
2 platforms
Cloud and self-hosted, deliberately
Post-merger
0 GB metering
Priced on identities, not ingest volume
The meter
2013
Founded, Foster City California
Company

What your Exabeam New-Scale SIEM rollout looks like

Day 0Free

Count identities, not gigabytes

The quote turns on monitored users. Get an accurate identity count — arriving with only a GB/day figure means you cannot compare this bid to anyone else's. TechBag does this free.

Week 1–3Deploy

Connect sources and baseline

Onboard log sources, then let the behavioural baselines establish. Analytics needs a period of normal activity before deviation means anything.

Week 4–8Tune

Tune risk, not rules

The work here is calibrating what risk score warrants attention, rather than writing and suppressing rules. Different discipline from a rule-based SIEM.

Month 3+Operate

Measure investigation minutes

Time real investigations before and after. Smart Timelines' value shows up as throughput, and throughput is what decides how many incidents your team can work.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Technology
Our log volume was enormous and our team is six people. Priced per gigabyte we could not afford proper coverage; priced per monitored user we could.
Head of SecOps
Technology
Banking
The behavioural scoring caught an account doing entirely permitted things at an entirely wrong hour. No rule we would have written would have fired on that.
SOC Lead
Banking
Insurance
Smart Timelines is the feature that does not demo well and matters most. Reconstruction used to be most of an investigation; now it is the starting point.
Security Analyst
Insurance
Financial Services
Honest warning: hiring is harder. Everyone has SPL on their CV. We trained internally and budgeted for the ramp.
CISO
Financial Services
Manufacturing
We asked the roadmap question about two platforms after the merger and got a straight answer in writing. That mattered more to our board than any feature.
IT Director
Manufacturing
Retail
Being able to add the analytics layer to what we already ran, rather than replacing the SIEM, made the business case survivable.
Security Architect
Retail
IT Services
Model the meter honestly. We have a large workforce and modest logs — for us an ingest-priced SIEM was genuinely cheaper, and TechBag said so.
Head of Infrastructure
IT Services
BFSI
As an Indian enterprise, having both a cloud option and a real on-prem one from the same vendor kept our options open while the mandate was being settled.
CISO
BFSI
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ExabeamThis page

UEBA heritage, with a real self-hosted answer.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
ExabeamThis page

Behavioural depth, and a meter that suits big volume.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Exabeam New-Scale SIEM vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionExabeamSecuronixSplunk Enterprise SecurityMicrosoft SentinelElastic Security
PositionUEBA-led SecOps, cloud AND self-hostedThe other UEBA-led vendorThe reference SIEMSIEM for Microsoft estatesSearch-engine-native SIEM
Pricing axisMonitored users + sources + modulesGB/day, hybrid commitment + PAYGIngest or workload — historically costlyPer GB ingested per daySubscription tier + resources
Behavioural analyticsThe founding capabilityThe founding capabilityAvailable, an add-on heritageUEBA includedEntity risk scoring
Self-hosted optionLogRhythm SIEM — genuinely on-premCloud-native onlyCloud, on-prem or hybridSaaS only, on AzureSelf-managed, even air-gapped
Analyst standing (SIEM MQ 2025)Long-running MQ presenceLeader, six times runningLeaderLeaderVisionary, not Leader
Augments a SIEM you ownNew-Scale Analytics, licensed separatelyUEBA availableBuy the platformBuy the platformBuy the platform
AI in the SOCNova — seven agents, named jobsSam, the AI SOC analystCisco AI AssistantSecurity Copilot + MCPElastic AI Assistant
Talent poolSmaller than the incumbentsSmaller than the incumbentsSPL — the largest by farKQL — widely knownLarge for the engine, smaller for security
The thing to plan aroundTwo platforms post-merger — ask the roadmapCloud-only; model the GB/dayCisco integration reshaping roadmapAzure portal retires 31 Mar 2027You operate it unless you buy Cloud
Best fitLarge log volume, small team — or on-premUEBA-led with Leader standingEngineers who will build with itMicrosoft-standardised estatesAir-gapped, or existing ELK
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Exabeam New-Scale SIEM fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Exabeam if…

  • Your log volume is large relative to your security headcount — the user-based meter favours exactly that shape
  • You need behavioural analytics rather than more rules, and you want the vendor that built on it
  • Your mandate rules out cloud — LogRhythm SIEM is a genuine self-hosted platform, not a retrofit
  • You want to add analytics to a SIEM you already own rather than replace it

Choose Securonix if…

  • You want the other UEBA-led vendor, with six consecutive Gartner MQ Leader placements — and cloud-native suits you

Choose Splunk if…

  • You have engineers who will build with it, and you want the deepest content and the largest talent pool (TechBag sells it)

Choose Microsoft Sentinel if…

  • Your estate is Microsoft — first-party logs ingest free and SIEM shares the Defender incident queue

Choose Elastic Security if…

  • You need air-gapped deployment, or your engineers already run Elasticsearch

Exabeam New-Scale SIEM is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Exabeam meters on monitored users; most of the category meters on gigabytes ingested. Which is cheaper depends entirely on the ratio between your log volume and your headcount — and it genuinely goes both ways, so this calculator will tell you when a rival is the better buy. Illustrative only: Exabeam is quote-only with no published list, and the comparator is an ingest-metered SIEM at roughly ₹249/GB. Move both sliders to find your crossover.

2,000
25050,000
300
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is cheaper for your shape and you should buy that one — a large workforce with modest logs is exactly the case where Exabeam’s meter works against you. Neither figure is a quote. TechBag models both properly before recommending either.

An ingest-metered SIEM, at your GB/day
₹2,72,26,080
Difference vs Exabeam’s user meter
₹2,43,26,080
₹12,16,30,400 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Exabeam does not publish list pricing, and it does not meter on gigabytes. The axis is monitored users plus sources plus modules — so the number that decides your quote is your identity count, not your ingest volume. That inverts the usual SIEM cost curve: large log volume against a small team favours this meter, and the reverse does not. Arrive with an accurate user count. TechBag models it against the ingest-priced alternatives and quotes in INR with GST.

New-Scale SIEM

Quotemonitored users + sources

Best for cloud-capable estates

  • Metered on monitored users, not gigabytes ingested
  • Log management, correlation, search and cases
  • The cloud platform the LogRhythm merger standardised on

+ New-Scale Analytics

Quotethe UEBA layer

Best when alerts are not trusted

  • Behavioural baselines and dynamic risk scoring
  • Can also augment a SIEM you already own
  • The capability Exabeam is actually known for

+ Exabeam Nova

Quoteagentic AI module

Best for stretched analysts

  • Seven agents scoped to named SOC jobs
  • Spans cloud and self-hosted platforms
  • Test it on your own alert queue, not a demo

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Identity count

How many monitored users? This is the number the quote turns on — not your GB/day.

2
Do the arithmetic both ways

Model the user-based bill AND an ingest-priced competitor. Large volume against a small team favours Exabeam; the reverse does not.

3
Deployment

Cloud or on-premises? That decides New-Scale versus LogRhythm SIEM before any feature comparison.

4
Replace or augment

If your log platform is fine and its alerts are not trusted, New-Scale Analytics on your existing SIEM is a much smaller purchase.

5
Roadmap

Two platforms after a merger — ask where investment goes for the one you are buying, in writing.

6
Talent

Who will run it? The Exabeam talent pool is smaller than Splunk's or Microsoft's — budget the ramp honestly.

7
Baseline period

Behavioural analytics needs normal activity before deviation is meaningful. Plan the evaluation long enough to see that.

8
Commercials

Quote-only with no published list — have you modelled it in INR with GST?

FAQ

Questions buyers ask

New-Scale SIEM is Exabeam's cloud-native security information and event management platform: it collects logs from across your estate, correlates them into incidents, and gives analysts a place to hunt and investigate. It is also the product the combined company standardised on for cloud after Exabeam and LogRhythm merged in July 2024 — LogRhythm's competing cloud SIEM, Axon, was retired in its favour, which is a clear signal about where cloud investment goes. Two things distinguish it from the rest of the category. The first is behavioural analytics: New-Scale Analytics ships alongside, so detections are baselined against what each user and machine normally does rather than only matched against rules somebody wrote in advance. Exabeam built on UEBA before the category had a name and it remains what they are known for. The second is the pricing axis, which is genuinely unusual: monitored users plus sources plus modules, rather than gigabytes ingested. That inverts the cost curve most SIEM buyers are used to. Alongside sits Exabeam Nova, a suite of seven AI agents scoped to specific SOC jobs, licensed as a module. Pricing is quote-only with no published list. TechBag sells Splunk, Microsoft Sentinel, Securonix and Elastic as well, so the advice here is about which shape fits your estate.

Ready to evaluate Exabeam New-Scale SIEM?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.