Talk to us
by ExabeamTechBag Intel Page

Exabeam Nova

Seven agents with named jobs, not one assistant that claims everything — Exabeam Nova puts AI agents for threat scoring, investigation, rule creation and search inside the workflow analysts already use, across both platforms.

Agents scoped to named SOC jobsCloud and self-hostedTest it on your own alerts

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Scoping discipline
each one is testable
Named jobs
Platform reach
parity is not guaranteed
Broad but uneven
Cost
quote-only, not standalone
Module on top
Proof for you
measure your own queue
Unproven

Data residency & processing — confirm before the PoC

Delivery

Cloud-native (New-Scale)

This is the cloud half of the portfolio. If your mandate rules out SaaS, LogRhythm SIEM is the self-hosted answer from the same vendor.

What to confirm

Region — and processing, separately

Storage residency and processing residency are two different commitments. Get both in writing for your region.

If your obligation requires data to stay in India, settle storage and processing separately with Exabeam before a proof of concept. If it rules out cloud entirely, see LogRhythm SIEM, which answers both by definition.

Quick answer

Exabeam Nova is a suite of roughly seven AI agents for security operations, sold as a licensed module on top of an Exabeam platform. What separates it from a general-purpose SOC chatbot is that each agent is scoped to a named job rather than to conversation. Threat Scoring prioritises alerts against machine-learned baselines and your business context. Investigation assembles case summaries, identifies attack vectors and proposes next steps. The Analyst Assistant answers case-specific questions in context. Search drives natural-language querying across users, hosts and logs. Visualisation turns a typed question into a chart. The Rule Creator generates, tunes and converts correlation rules. The Advisor produces executive reporting, mapping coverage to MITRE ATT&CK and compliance frameworks for the CISO rather than the analyst. That scoping matters commercially, because a named job can be evaluated against that job — you can ask whether the Investigation agent's conclusions survive analyst review in a way you cannot meaningfully ask of 'the assistant'. Nova spans both Exabeam platforms, New-Scale in the cloud and self-hosted LogRhythm SIEM, though the two are NOT at parity: the self-hosted AI lineage runs through LogRhythm Intelligence, and you should confirm agent-by-agent availability for your deployment in writing before signing. Licensed as a module and quoted, not listed. Be sceptical of the category. Every SIEM vendor is shipping agents in 2026 and all of them demo well on curated data. The only evidence that counts is what happens to your own noisy alert queue, measured during a trial. Worth knowing: Nova runs on Gemini models inside Google Cloud, so the underlying model is not the differentiator anyone claims. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Exabeam Nova — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
Exabeam Nova — agentic AI for the SOC
What it is
~7 job-scoped agents, not one chatbot
Vendor
Exabeam (merged with LogRhythm, July 2024)
Platforms
New-Scale and LogRhythm — NOT at parity
Underlying model
Gemini, inside Google Cloud
Licensing
Add-on module, quote-only
Prerequisite
An Exabeam platform — not standalone
Platform meter
Monitored users + sources + modules
Best evidence
Analyst acceptance rate on YOUR alerts
In India via
TechBag — trial design, GST invoicing
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Seven AI agents scoped to named SOC jobs — threat scoring, investigation, analyst assistance, rule creation, search, advisory and visualisation — across both Exabeam platforms.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolExabeam Nova
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownMonitored users — grows with headcount
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The structure

The agent layer

Seven named jobs

Nova is not a single model behind a text box. It is a set of agents, each bound to one SOC task with its own inputs, outputs and success criterion. This is the decision that makes evaluation possible at all, because you can hold one agent to one job.

02
The dependency

The platform beneath

New-Scale or LogRhythm

Nova has no data of its own. It reasons over whatever your Exabeam platform has already collected and normalised. It inherits every gap in that collection, so poor log coverage produces confident agents that are confidently wrong.

03
The evidence

The behavioural baseline

UEBA as substrate

Exabeam's long-standing strength is behavioural analytics, and Nova's threat scoring sits on top of it. The agents consume risk signals derived from learned normal behaviour rather than static rules alone. Where the baseline is thin, the scoring degrades accordingly.

04
The tuning

The context layer

Your business

Threat scoring accepts business context, so a service account in a payments environment can be weighted differently from a laptop in marketing. This is the part most teams under-invest in and then blame the AI for. Untuned context is the commonest reason prioritisation fails to match analyst intuition.

05
The CISO view

The reporting surface

Advisor

The Advisor agent points at a different audience: it maps detection coverage against MITRE ATT&CK, OWASP and compliance frameworks and turns that into board-legible reporting. Genuinely useful, and the easiest agent to over-trust, because nobody in the boardroom can audit it.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Search

Natural-language search

Query users, hosts and logs from one interface without writing platform query syntax.

Collect
Coverage

Source visibility

Surfaces which log sources feed detections and where the collection gaps sit.

Collect
Context

Business context weighting

Lets you tell the scoring engine which users, assets and accounts actually matter.

Collect
Reach

Cross-platform data

Reasons over data in New-Scale or self-hosted LogRhythm, subject to per-agent availability.

Detect
Scoring

Machine-learned threat scoring

Prioritises alerts against behavioural baselines rather than static severity labels.

Detect
UEBA

Behavioural anomaly detection

Flags deviation from learned normal for users, hosts and service accounts.

Detect
Rules

AI-assisted rule creation

Generates, tunes and converts correlation rules to shorten detection-engineering cycles.

Detect
Mapping

ATT&CK coverage mapping

Maps existing detections to ATT&CK and compliance frameworks to expose blind spots.

Detect
Noise

Alert triage

Suppresses low-value alerts so the queue reflects what warrants human review.

Respond
Cases

Automated case summarisation

Assembles the narrative, entities and timeline so analysts start from evidence, not raw logs.

Respond
Guidance

Next-step guidance

Proposes the next investigative action and the likely attack vector for the analyst to confirm.

Respond
Reporting

Executive reporting

Turns coverage and SOC activity into reporting a CISO can defend outside the security team.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Exabeam (official)·Overview

The AI-Driven Exabeam Security Operations Platform

The AI platform, explained by Exabeam.

Exabeam (official)·SIEM

Exabeam SIEM Overview

The platform the agents work inside.

Exabeam (official)·Workflow

Introducing New-Scale Analytics — Analyst Workflow

The analyst workflow the agents join.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Nova

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

Named jobs beat a general assistant

The most useful thing about Nova is structural, not technical. A general SOC chatbot cannot really be evaluated — ask it anything, get a plausible answer, and there is no defined standard it either met or missed. An agent scoped to a named job can be held to that job. You can ask whether the Investigation agent's case summary matched what the analyst concluded independently. You can ask whether the Rule Creator's output needed rewriting before it went live. You can count how often the Threat Scoring agent's top ten matched the ten cases your analysts would have picked. None of those questions are answerable about 'the AI'. All are answerable about a specific agent doing a specific task, and that is the difference between a product you can procure responsibly and one you buy on a demo.

02

It rides on a behavioural engine, not a bolted-on model

Exabeam has been doing user and entity behaviour analytics far longer than the agentic AI category has existed, and Nova's scoring sits on that substrate. This matters because the failure mode of AI in the SOC is confident output over thin evidence. An agent reasoning over a learned behavioural baseline has something underneath it; an agent reasoning over raw alerts is mostly restating them in nicer prose. The practical implication is that Nova's value tracks the maturity of your Exabeam deployment. If your log coverage is patchy and your baselines are young, the agents operate on the same weak evidence your analysts do — and no amount of AI manufactures signal that was never collected.

03

Both deployment models are addressed — but confirm parity

The LogRhythm merger gave Exabeam something most cloud-native SIEM vendors cannot offer Indian buyers: a genuine self-hosted option still receiving development. For regulated environments where residency or sectoral guidance makes a cloud SIEM hard to approve, that matters. Nova is positioned to span both New-Scale and self-hosted LogRhythm SIEM. Be precise during procurement, though, because 'spans both platforms' is not the same as 'identical on both platforms' — the self-hosted AI lineage runs through LogRhythm Intelligence, and the cloud side has historically received net-new capability first. Get agent-by-agent availability for your specific deployment written into the quote rather than inferred from a marketing page, and re-confirm at renewal.

04

The commercial meter is more predictable than ingest pricing

Exabeam's platform meter is monitored users, sources and modules rather than gigabytes ingested, and this is the quiet advantage that compounds. Ingest-priced SIEMs create a perverse incentive: every new log source becomes a budget conversation, so teams under-collect to control cost and discover the gap during an incident. A user-and-source meter decouples cost from volume, so turning on verbose logging for a critical system does not trigger a finance escalation. Nova itself is a module on top of that, quoted separately. Model the combined figure over three years — platform, Nova, and the growth in monitored users you actually expect — before comparing it to anything else.

05

The honest caveat about AI claims

Every SIEM vendor is shipping AI agents in 2026, and every one of them demos beautifully. That is not evidence, because demos run on curated data where the answer is known. Vendor figures — investigations completed dramatically faster, alerts meaningfully reduced — describe someone else's environment and someone else's queue. The only test that counts is your own noisy alerts during the trial. Run the agents against real production volume, including the boring ambiguous ones, and measure the thing that matters: do your analysts accept the agents' conclusions, or do they quietly redo the work? Watch for the second behaviour specifically, because it is easy to miss. An analyst who reads the AI summary, nods, then opens the raw logs and rebuilds the timeline has told you the productivity claim is not landing — but usage metrics will still record that summary as consumed. If the redo rate is high after a fair trial with tuned context, you are paying for a module your team does not trust. Walk away, or renegotiate.

06

The honest positioning

Nova is a sensible implementation of an idea the entire market is chasing simultaneously, and it is strongest for organisations already committed to Exabeam. It is not standalone and cannot rescue a poorly instrumented SOC — it needs the platform beneath it, decent log coverage and tuned business context before it does anything useful. If you are not already an Exabeam customer, the real decision is the SIEM, not the agents: choose the platform on detection quality, deployment model and total cost, then treat Nova as an add-on to evaluate on its own merits. TechBag sells Exabeam's competitors too and will say plainly when one fits better. If Microsoft is already deep in your estate, Security Copilot may be the cheaper path. If you need self-hosted above all, the LogRhythm lineage is a real advantage. If your alert volume is modest and your team small, agentic AI may be solving a problem you do not yet have.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

7 agents
Named SOC jobs in the suite
Exabeam
2 platforms
Cloud and self-hosted — but not at parity
Exabeam
3 frameworks
ATT&CK, OWASP and compliance, via Advisor
Exabeam
30 days
Minimum honest trial on your own alert queue
TechBag guidance
2024
Exabeam and LogRhythm merged, July
Company
0 GB tiers
Platform meters users and sources, not ingest
The meter

What your Exabeam Nova rollout looks like

Phase 1Foundation

Establish the platform baseline

Before Nova can be judged, confirm what your Exabeam deployment actually sees. Audit log source coverage and check how mature your behavioural baselines are. Agents reasoning over incomplete collection produce fluent, confident, wrong answers — and you will blame the AI for a data problem.

Phase 2Tuning

Load real business context

Threat scoring is only as good as the context you give it. Mark your crown-jewel systems, privileged accounts and regulated data stores so the agents weight them properly. Teams that skip this and then complain prioritisation does not match analyst intuition have diagnosed the symptom and missed the cause.

Phase 3Evidence

Trial against your own noisy queue

Run the agents on real production alerts for at least a month, including the ambiguous low-grade ones that make up most of the work. Log every case where an analyst accepted the conclusion and every case where they redid it. That ratio is your actual evidence.

Phase 4Decision

Decide on measured evidence

If acceptance is high after fair tuning, embed the agents into standard procedure and define which conclusions may be acted on without human confirmation. If the redo rate stayed high, say so plainly and either renegotiate or decline. A trial that cannot produce a 'no' was never an evaluation.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Financial Services
The case summaries genuinely changed how our tier-one starts a shift. They open with a narrative instead of a wall of raw events, and that alone took real minutes off every ticket.
SOC Manager
Financial Services
Manufacturing
Threat scoring was mediocre until we spent a fortnight loading proper business context. That is on us, not the product, but nobody warned us it was a prerequisite rather than an optimisation.
Security Architect
Manufacturing
IT Services
Honest assessment after two quarters: the AI is fine, but my senior analysts still rebuild the timeline themselves before they close anything material. We are paying for a module that mostly helps the juniors, and the productivity numbers we were shown have not materialised for us.
Head of Security Operations
IT Services
Healthcare
Natural-language search removed a real barrier. Our newer analysts were blocked on query syntax and are now productive in weeks rather than months.
SOC Team Lead
Healthcare
Insurance
The Advisor reporting is what got the renewal approved, frankly. Showing the board a coverage map against ATT&CK made a conversation possible that we had been failing at for two years.
CISO
Insurance
Retail
Rule Creator output always needs review before it goes live. It is a competent first draft and a poor final answer. Treated correctly, it still saves detection-engineering time.
Detection Engineer
Retail
Government
We are self-hosted for regulatory reasons and not every capability we saw demonstrated was available to us on day one. Clarify this before you sign — we assumed parity and were wrong.
Infrastructure Security Manager
Government
Logistics
Not having to argue with finance every time we onboard a new log source has quietly improved our detection coverage more than any AI feature has.
Security Operations Director
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ExabeamThis page

UEBA heritage, with a real self-hosted answer.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
ExabeamThis page

Behavioural depth, and a meter that suits big volume.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Exabeam Nova vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionExabeamSecuronixSplunk Enterprise SecurityMicrosoft SentinelElastic Security
PositionUEBA-led SecOps, cloud AND self-hostedThe other UEBA-led vendorThe reference SIEMSIEM for Microsoft estatesSearch-engine-native SIEM
Pricing axisMonitored users + sources + modulesGB/day, hybrid commitment + PAYGIngest or workload — historically costlyPer GB ingested per daySubscription tier + resources
Behavioural analyticsThe founding capabilityThe founding capabilityAvailable, an add-on heritageUEBA includedEntity risk scoring
Self-hosted optionLogRhythm SIEM — genuinely on-premCloud-native onlyCloud, on-prem or hybridSaaS only, on AzureSelf-managed, even air-gapped
Analyst standing (SIEM MQ 2025)Long-running MQ presenceLeader, six times runningLeaderLeaderVisionary, not Leader
Augments a SIEM you ownNew-Scale Analytics, licensed separatelyUEBA availableBuy the platformBuy the platformBuy the platform
AI in the SOCNova — seven agents, named jobsSam, the AI SOC analystCisco AI AssistantSecurity Copilot + MCPElastic AI Assistant
Talent poolSmaller than the incumbentsSmaller than the incumbentsSPL — the largest by farKQL — widely knownLarge for the engine, smaller for security
The thing to plan aroundTwo platforms post-merger — ask the roadmapCloud-only; model the GB/dayCisco integration reshaping roadmapAzure portal retires 31 Mar 2027You operate it unless you buy Cloud
Best fitLarge log volume, small team — or on-premUEBA-led with Leader standingEngineers who will build with itMicrosoft-standardised estatesAir-gapped, or existing ELK
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Exabeam Nova fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Exabeam if…

  • Your log volume is large relative to your security headcount — the user-based meter favours exactly that shape
  • You need behavioural analytics rather than more rules, and you want the vendor that built on it
  • Your mandate rules out cloud — LogRhythm SIEM is a genuine self-hosted platform, not a retrofit
  • You want to add analytics to a SIEM you already own rather than replace it

Choose Securonix if…

  • You want the other UEBA-led vendor, with six consecutive Gartner MQ Leader placements — and cloud-native suits you

Choose Splunk if…

  • You have engineers who will build with it, and you want the deepest content and the largest talent pool (TechBag sells it)

Choose Microsoft Sentinel if…

  • Your estate is Microsoft — first-party logs ingest free and SIEM shares the Defender incident queue

Choose Elastic Security if…

  • You need air-gapped deployment, or your engineers already run Elasticsearch

Exabeam Nova is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Exabeam meters on monitored users; most of the category meters on gigabytes ingested. Which is cheaper depends entirely on the ratio between your log volume and your headcount — and it genuinely goes both ways, so this calculator will tell you when a rival is the better buy. Illustrative only: Exabeam is quote-only with no published list, and the comparator is an ingest-metered SIEM at roughly ₹249/GB. Move both sliders to find your crossover.

2,000
25050,000
300
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is cheaper for your shape and you should buy that one — a large workforce with modest logs is exactly the case where Exabeam’s meter works against you. Neither figure is a quote. TechBag models both properly before recommending either.

An ingest-metered SIEM, at your GB/day
₹2,72,26,080
Difference vs Exabeam’s user meter
₹2,43,26,080
₹12,16,30,400 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Licensed as a module, quote-only, on either platform. Be sceptical in the useful way here: every SIEM vendor in the market is shipping agents right now and all of them demonstrate well on curated data. The structure is a good sign — agents scoped to named jobs can be evaluated against those jobs, where a general assistant can only be judged on impressions. But the only evidence that counts is what happens to your alert queue. TechBag structures the trial so that is what gets measured, and quotes in INR with GST.

Nova, on New-Scale

Quotemodule on the cloud platform

Best for cloud estates

  • Seven agents across triage, investigation and search
  • Inside the workflow analysts already use
  • Quote-only, licensed as a module

Nova, on LogRhythm

Quotemodule on self-hosted

Best for on-prem estates

  • The same agents on the self-hosted platform
  • AI without moving to cloud
  • Ask what differs between the two

Evaluation

Freerun it on your alerts

Best before you commit

  • Every SIEM vendor demos AI well on curated data
  • Measure whether analysts accept the conclusions
  • TechBag structures the trial to test this

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
AI evidence

During the trial, what percentage of agent conclusions did analysts accept WITHOUT redoing the work themselves?

2
AI evidence

Did we test on our own noisy production alerts, or only on the vendor's curated demo data?

3
AI evidence

Can we name one measurable outcome that changed — queue depth, time to close, escalation rate — rather than an impression?

4
Platform parity

Which specific agents are available on OUR deployment model, and is that written into the quote?

5
Data foundation

Which log sources are missing, and will the agents be reasoning over those gaps?

6
Tuning

Have we loaded real business context before judging the scoring, or are we evaluating an untuned system?

7
Commercials

What is the three-year cost of platform plus Nova at our projected monitored-user growth?

8
Governance

Which agent conclusions may be acted on without human confirmation, and who signed off on that boundary?

FAQ

Questions buyers ask

Nova is a suite of roughly seven AI agents for security operations, sold as a licensed module on top of an Exabeam platform. The important detail is that it is not one general-purpose chatbot with a security theme. Each agent is scoped to a named job: threat scoring prioritises alerts against behavioural baselines and business context; investigation assembles case summaries, identifies attack vectors and recommends next steps; the analyst assistant answers case-specific questions in context; search enables natural-language querying across users, hosts and logs; visualisation turns typed questions into charts and dashboards; rule creator assists detection engineering with rule generation, tuning and conversion; and the advisor agent produces executive coverage reporting mapped to MITRE ATT&CK, OWASP and compliance frameworks. That scoping is not a marketing distinction, it is a procurement one. A general assistant cannot be evaluated in any rigorous sense, because there is no defined task it either completed or failed. An agent with a named job can be tested against that job, repeatedly, on your data. You can count how often the investigation agent's conclusion matched what your analyst independently determined. You cannot ask that question of 'the AI'. Nova depends entirely on the platform beneath it. It holds no data of its own and reasons over what your Exabeam deployment has already collected and normalised. If your log coverage has holes, Nova inherits them. It is not a standalone purchase and it cannot fix a poorly instrumented SOC — it amplifies whatever evidence is already there, including the absence of it.

Ready to evaluate Exabeam Nova?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.