The SIEM priced on people, not gigabytes — Exabeam New-Scale SIEM meters on monitored users, sources and modules, which inverts the cost curve if your log volume is large and your team is not.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Delivery
Cloud-native (New-Scale)
This is the cloud half of the portfolio. If your mandate rules out SaaS, LogRhythm SIEM is the self-hosted answer from the same vendor.
What to confirm
Region — and processing, separately
Storage residency and processing residency are two different commitments. Get both in writing for your region.
If your obligation requires data to stay in India, settle storage and processing separately with Exabeam before a proof of concept. If it rules out cloud entirely, see LogRhythm SIEM, which answers both by definition.
Quick answer
This page covers Exabeam New-Scale SIEM — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Exabeam’s cloud-native SIEM — the platform the LogRhythm merger standardised on. Collection, correlation and cases, with behavioural analytics built in rather than bolted on.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Exabeam New-Scale SIEM |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Monitored users — grows with headcount |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Log collection from cloud, on-premises and SaaS sources into the cloud platform. Because the meter is users rather than volume, adding a noisy source does not carry the cost penalty it would on an ingest-priced SIEM.
Standard correlation and detection content, with the behavioural layer alongside rather than bolted on — so a detection can reference an entity's risk score, not only the event in front of it.
Behavioural baselines for every user and machine, with dynamic risk scoring. This is the capability Exabeam is known for and the reason the SIEM's detections behave differently from a purely rule-based one.
The chronological reconstruction of an entity's activity, assembled automatically rather than queried for. The measurable saving is analyst minutes per investigation, which is the thing that actually scales a SOC.
Seven AI agents scoped to named SOC jobs — threat scoring, investigation, analyst assistance, rule creation, search, advisory and visualisation — licensed as a module across both platforms.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Sources across cloud, on-premises and SaaS, into the cloud platform.
Adding a noisy source does not carry the usual per-GB cost penalty.
Parsing and normalisation for common security and infrastructure sources.
Retention configured per your mandate rather than fixed by the licence.
Standard correlation content, referencing entity risk as well as events.
What each user and machine normally does — and scored deviation from it.
Small signals accumulate on an entity until the sequence is alarming.
Entity activity reconstructed automatically, not queried for.
Query across collected data during an investigation.
Investigations, evidence and workflow in the platform.
Automated and analyst-triggered response across integrations.
Seven agents scoped to named SOC jobs, licensed as a module.
Endpoint protection, XDR and Security Copilot.
The SIEM, explained by Exabeam.
Where the SIEM sits in the platform.
The behavioural layer it ships with.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
Almost every SIEM in this category charges for gigabytes ingested, which means the bill grows every single year regardless of whether your organisation grows. Log volume expands on its own: you adopt another cloud service, an application gets more verbose, endpoint telemetry gets richer. Teams end up making retention and coverage decisions on budget rather than risk, which is exactly backwards. Exabeam meters on monitored users plus sources plus modules — your identity count, which tracks headcount and is therefore far more predictable to forecast. For a cloud-native organisation with enormous log volume and a small security team, that inversion is worth a great deal of money. Here is the honest other half: if you have a large workforce generating modest log volume, the arithmetic runs the other way and an ingest-priced SIEM will be cheaper. This is not a universally better meter, it is a differently-shaped one, and which shape fits is an arithmetic question you must actually do rather than assume.
Exabeam built on UEBA before the category had a name, and New-Scale Analytics ships as part of this platform rather than as a module you discover you need later. The practical consequence is what happens with a stolen credential. A rule-based SIEM has nothing to match: the login is valid, the source is plausible, the actions are permitted. Nothing is malformed, so nothing fires. A behavioural system has a baseline of what that identity normally does — hours, systems, volumes, sequences — and scores the deviation. Given that credential abuse is now the dominant initial-access route, that difference is not academic. It also changes what your analysts spend time on: instead of tuning rules to suppress noise, they are working a ranked risk list.
The unglamorous truth about security operations is that most analyst time goes on reconstruction — what did this account do, in what order, across which systems, over what period. Analysts do it by querying, repeatedly, and it is slow. Exabeam assembles that timeline automatically for the entity in question. The saving is minutes per investigation, and minutes per investigation is precisely the number that determines how many incidents a given team can actually work. Capability comparisons rarely capture this because it is not a feature you can tick; it shows up as throughput. When you evaluate, time a real investigation on your own data rather than reading the feature list.
The July 2024 LogRhythm merger left Exabeam with a genuinely unusual position: New-Scale for cloud, LogRhythm SIEM for self-hosted, with Axon retired to avoid overlap. Most vendors serve one deployment model well and treat the other as an afterthought, and several claim on-premises capability that turns out to mean a hosted appliance with cloud dependencies. LogRhythm SIEM is a mature product with over 1,100 prebuilt correlation rules and a long record in regulated and government estates. So if your mandate rules out cloud, you are not being handed a compromise — and for Indian buyers under DPDP or RBI, SEBI and IRDAI expectations, self-hosted answers both the storage and processing residency questions by definition. See the LogRhythm SIEM page for that side.
Being straight, and TechBag sells the alternatives: the pool of people who already know Exabeam is materially smaller than for Splunk or Microsoft Sentinel. SPL and KQL are on a great many CVs; Exabeam experience is on fewer, which affects hiring, contractor availability and how quickly a new analyst becomes productive. Second, any two-platform portfolio after a merger invites a question about where investment goes, and Axon's retirement demonstrates this company will consolidate where products overlap. New-Scale and LogRhythm SIEM do not overlap — they serve different deployment models — but ask for the roadmap commitment in writing anyway, for whichever one you are buying. A vendor confident in its plan will provide it, and the request costs you nothing.
Exabeam New-Scale SIEM is the right choice when your log volume is large relative to your security headcount, because the user-based meter is built for exactly that shape; when you want behavioural detection as the product rather than rules you maintain; and when you value having a genuine on-premises option in the same portfolio. It is the wrong choice when your workforce is large and your logs are modest — the meter works against you — or when you need the largest talent pool and deepest content library, which is Splunk. TechBag sells Splunk, Microsoft Sentinel, Securonix and Elastic as well, and will do the arithmetic both ways before recommending, quoted in INR with GST.
The quote turns on monitored users. Get an accurate identity count — arriving with only a GB/day figure means you cannot compare this bid to anyone else's. TechBag does this free.
Onboard log sources, then let the behavioural baselines establish. Analytics needs a period of normal activity before deviation means anything.
The work here is calibrating what risk score warrants attention, rather than writing and suppressing rules. Different discipline from a rule-based SIEM.
Time real investigations before and after. Smart Timelines' value shows up as throughput, and throughput is what decides how many incidents your team can work.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our log volume was enormous and our team is six people. Priced per gigabyte we could not afford proper coverage; priced per monitored user we could.”
“The behavioural scoring caught an account doing entirely permitted things at an entirely wrong hour. No rule we would have written would have fired on that.”
“Smart Timelines is the feature that does not demo well and matters most. Reconstruction used to be most of an investigation; now it is the starting point.”
“Honest warning: hiring is harder. Everyone has SPL on their CV. We trained internally and budgeted for the ramp.”
“We asked the roadmap question about two platforms after the merger and got a straight answer in writing. That mattered more to our board than any feature.”
“Being able to add the analytics layer to what we already ran, rather than replacing the SIEM, made the business case survivable.”
“Model the meter honestly. We have a large workforce and modest logs — for us an ingest-priced SIEM was genuinely cheaper, and TechBag said so.”
“As an Indian enterprise, having both a cloud option and a real on-prem one from the same vendor kept our options open while the mandate was being settled.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
UEBA heritage, with a real self-hosted answer.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Behavioural depth, and a meter that suits big volume.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Exabeam | Securonix | Splunk Enterprise Security | Microsoft Sentinel | Elastic Security |
|---|---|---|---|---|---|
| Position | UEBA-led SecOps, cloud AND self-hosted | The other UEBA-led vendor | The reference SIEM | SIEM for Microsoft estates | Search-engine-native SIEM |
| Pricing axis | Monitored users + sources + modules | GB/day, hybrid commitment + PAYG | Ingest or workload — historically costly | Per GB ingested per day | Subscription tier + resources |
| Behavioural analytics | The founding capability | The founding capability | Available, an add-on heritage | UEBA included | Entity risk scoring |
| Self-hosted option | LogRhythm SIEM — genuinely on-prem | Cloud-native only | Cloud, on-prem or hybrid | SaaS only, on Azure | Self-managed, even air-gapped |
| Analyst standing (SIEM MQ 2025) | Long-running MQ presence | Leader, six times running | Leader | Leader | Visionary, not Leader |
| Augments a SIEM you own | New-Scale Analytics, licensed separately | UEBA available | Buy the platform | Buy the platform | Buy the platform |
| AI in the SOC | Nova — seven agents, named jobs | Sam, the AI SOC analyst | Cisco AI Assistant | Security Copilot + MCP | Elastic AI Assistant |
| Talent pool | Smaller than the incumbents | Smaller than the incumbents | SPL — the largest by far | KQL — widely known | Large for the engine, smaller for security |
| The thing to plan around | Two platforms post-merger — ask the roadmap | Cloud-only; model the GB/day | Cisco integration reshaping roadmap | Azure portal retires 31 Mar 2027 | You operate it unless you buy Cloud |
| Best fit | Large log volume, small team — or on-prem | UEBA-led with Leader standing | Engineers who will build with it | Microsoft-standardised estates | Air-gapped, or existing ELK |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Exabeam New-Scale SIEM is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Exabeam meters on monitored users; most of the category meters on gigabytes ingested. Which is cheaper depends entirely on the ratio between your log volume and your headcount — and it genuinely goes both ways, so this calculator will tell you when a rival is the better buy. Illustrative only: Exabeam is quote-only with no published list, and the comparator is an ingest-metered SIEM at roughly ₹249/GB. Move both sliders to find your crossover.
If the saving reads zero, the ingest-priced SIEM is cheaper for your shape and you should buy that one — a large workforce with modest logs is exactly the case where Exabeam’s meter works against you. Neither figure is a quote. TechBag models both properly before recommending either.
Exabeam does not publish list pricing, and it does not meter on gigabytes. The axis is monitored users plus sources plus modules — so the number that decides your quote is your identity count, not your ingest volume. That inverts the usual SIEM cost curve: large log volume against a small team favours this meter, and the reverse does not. Arrive with an accurate user count. TechBag models it against the ingest-priced alternatives and quotes in INR with GST.
Best for cloud-capable estates
Best when alerts are not trusted
Best for stretched analysts
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many monitored users? This is the number the quote turns on — not your GB/day.
Model the user-based bill AND an ingest-priced competitor. Large volume against a small team favours Exabeam; the reverse does not.
Cloud or on-premises? That decides New-Scale versus LogRhythm SIEM before any feature comparison.
If your log platform is fine and its alerts are not trusted, New-Scale Analytics on your existing SIEM is a much smaller purchase.
Two platforms after a merger — ask where investment goes for the one you are buying, in writing.
Who will run it? The Exabeam talent pool is smaller than Splunk's or Microsoft's — budget the ramp honestly.
Behavioural analytics needs normal activity before deviation is meaningful. Plan the evaluation long enough to see that.
Quote-only with no published list — have you modelled it in INR with GST?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.