Talk to us
by ExabeamTechBag Intel Page

LogRhythm SIEM

The on-premises half of the portfolio — LogRhythm SIEM is now exclusively self-hosted, with over 1,100 prebuilt correlation rules and a long record in regulated and government estates.

Self-hosted only, post-merger1,100+ prebuilt correlation rulesResidency answered by definition

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Regulated fit
residency by construction
Answered by design
OOTB content
ATT&CK and compliance mapped
1,100+ rules
Cost clarity
the iron underneath is yours
Licence is quotable
Roadmap
but get it in writing
Shipping in 2026

Data residency & processing — answered by definition

Self-hosted

Stored AND processed by you

Runs entirely on infrastructure you own and operate. Both questions answered by definition — the data never leaves your perimeter.

What that rules in

Mandates the cloud SIEMs cannot meet

Sentinel, Google SecOps and Cortex XSIAM are SaaS-only. Where SaaS is prohibited, they are not candidates at any price.

For Indian buyers under the DPDP Act, or subject to RBI, SEBI or IRDAI expectations, self-hosted sidesteps the storage-versus-processing distinction entirely — there is no processing location to confirm because there is no third party. See the SIEM guide for the other products that can do this.

Quick answer

LogRhythm SIEM is a self-hosted security information and event management platform that you install and run on infrastructure you own — your data centre, your racks, or a private cloud you control. Since the July 2024 merger with Exabeam under Thoma Bravo, it is the on-premises half of a two-platform portfolio: LogRhythm SIEM for self-hosted estates, Exabeam New-Scale for cloud. LogRhythm's own cloud SIEM, Axon, was retired in favour of New-Scale. That merger clarified rather than diminished the product. It is now positioned unambiguously as a self-hosted product with over twenty years behind it, and it continues to ship — the April and July 2026 releases added investigation workflow, archiving automation and broader telemetry coverage. It carries more than 1,100 prebuilt correlation rules mapped to MITRE ATT&CK and to compliance mandates including ISO 27001, PCI DSS, HIPAA, SOX, NIST CSF and CIS Controls. The reason this product reaches shortlists that better-marketed rivals cannot is architectural, not featural. Microsoft Sentinel is SaaS on Azure. Google SecOps is SaaS on Google Cloud. Palo Alto Cortex XSIAM is SaaS. For a buyer whose regulator, contract or board forbids SaaS, those three are not expensive candidates — they are not candidates. For Indian buyers this matters twice over. Self-hosting answers data residency AND processing residency in one stroke, because the logs never leave your estate. Under the DPDP Act, and against RBI, SEBI and IRDAI expectations, 'it stays in our data centre' is a much shorter conversation than any cloud attestation. The trade is real: you supply and run the infrastructure, capacity planning and upgrades. Pricing is quote-only. And a two-platform portfolio after a merger deserves a written roadmap question. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers LogRhythm SIEM — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
LogRhythm SIEM — self-hosted
Vendor
Exabeam (merged with LogRhythm, July 2024)
Owner
Thoma Bravo · CEO Pete Harteveld (Oct 2025)
Deployment
On-premises or self-managed private cloud
Cloud option
None — New-Scale is the cloud platform
Correlation rules
1,100+ prebuilt, MITRE ATT&CK mapped
Compliance
ISO 27001, PCI DSS, HIPAA, SOX, NIST, CIS
Analytics add-on
LogRhythm Intelligence (Exabeam UEBA)
Residency
Storage AND processing — answered by design
Pricing
Quote-only; you supply the infrastructure
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

The self-hosted SIEM — exclusively on-premises since the merger, with 1,100+ prebuilt correlation rules and a long record in regulated and government estates.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolLogRhythm SIEM
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownMonitored users — grows with headcount
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where logs live

Data Indexer

Store

The indexer holds collected and structured log data on storage you own and size. Retention is a function of your disk, not a vendor tier — the point for buyers who must keep years of audit trail without a per-GB meter running. It is also the component most often under-provisioned in year one.

02
The brain

Platform Manager

Control

Runs correlation, holds the rule set, manages alarms and drives workflow. This is where the 1,100+ prebuilt rules execute and where your tuning lives. Everything an auditor wants to see about how a detection was defined and who changed it is anchored here.

03
Parse and enrich

Data Processor

Process

Takes raw events, parses them into a common schema, enriches them and applies risk-based prioritisation. This turns a firewall's terse syslog and an identity provider's JSON into something one correlation rule can reason about across both — and it happens inside your estate.

04
The telemetry

System Monitor Agents

Collect

Agents on hosts and collectors for network, cloud, identity, email and collaboration sources feed the pipeline. Agent-based collection picks up host artefacts that log forwarding alone misses, such as process and file-integrity data.

05
The analytics

LogRhythm Intelligence

Extend

Brings Exabeam's UEBA to the self-hosted platform, scoring user and entity behaviour rather than matching signatures alone. A sync service aligns case status, risk scores and ATT&CK data with New-Scale for organisations running both. NetMon adds network traffic analysis.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Ingest

Broad source coverage

Collectors and agents pull from firewalls, endpoints, servers, identity, cloud, email and collaboration platforms.

Collect
Agents

Host-level monitors

Capture what forwarded syslog cannot: process activity, file integrity and local authentication detail.

Collect
Parsing

Common schema

Every source parsed into one structure so a single rule reasons across a Cisco device and an Okta tenant.

Collect
Retention

Storage you own

Archive and retention live on your disk, so multi-year retention is a storage purchase, not a licence tier.

Detect
Rules

1,100+ correlations

Ships mapped to ATT&CK and compliance mandates, so a new deployment alarms meaningfully in weeks.

Detect
ATT&CK

Framework coverage

Rules carry ATT&CK mapping, turning 'what are we covered for' from an opinion into a grid.

Detect
UEBA

LogRhythm Intelligence

Behavioural analytics score users against their own baselines, catching what signature rules cannot.

Detect
Risk

Risk-based prioritisation

Events carry scores driven by asset criticality and behaviour, so a small team triages in a defensible order.

Detect
Network

NetMon traffic analysis

Visibility into traffic that never generates a log line — lateral movement, unexpected egress, protocol anomalies.

Respond
Cases

Investigation workflow

Evidence, timeline and assignment in one place. The July 2026 release focused specifically here.

Respond
SmartResponse

Automated actions

Execute containment from an alarm — disable an account, block an address, isolate a host — gated by approval where policy demands.

Respond
Compliance

Mandate reporting

Prebuilt modules for ISO 27001, PCI DSS, HIPAA, SOX, NIST and CIS — the evidence requests that otherwise consume an analyst quarterly.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Exabeam (official)·Product

New LogRhythm SIEM Dashboards

The self-hosted SIEM, from Exabeam.

Exabeam (official)·Portfolio

Exabeam SIEM Overview

Where LogRhythm sits after the merger.

Exabeam (official)·Platform

The AI-Driven Exabeam Security Operations Platform

The wider platform it belongs to.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why LogRhythm SIEM

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

It qualifies where cloud-only SIEMs are disqualified before price

Microsoft Sentinel runs as SaaS in Azure. Google SecOps runs as SaaS on Google Cloud. Palo Alto Cortex XSIAM is SaaS. Each is capable, and TechBag will sell you any of them. But if your regulator, your contract with a client, or your own board has ruled out SaaS for security telemetry, none is a candidate at any discount — the architecture is the disqualifier, not the quote. LogRhythm SIEM sits on the much shorter list that clears that gate at all. This is the single most useful thing to understand about the product: its advantage is structural rather than featural. On a like-for-like comparison of analytics sophistication against a well-funded cloud-native SIEM, it will not win every row. On a shortlist where SaaS is prohibited, it does not need to — it is competing against a handful of peers rather than the whole market.

02

Mature on-prem, not a cloud product bent into an on-prem shape

Several vendors say they support on-premises deployment. Read the fine print, because the word covers at least three different things: a genuinely self-contained installation, a hosted appliance that still phones home for detection content or licensing, and a cloud product with an on-prem collector in front of it. Only the first survives a serious air-gap or sovereignty requirement. LogRhythm SIEM has been self-hosted for over twenty years — the on-premises path is the original design, not a retrofit, and the components run inside your boundary rather than proxying to someone else's. That heritage shows in the unglamorous places that decide whether a deployment succeeds: an installation model that assumes your hardware, upgrade paths that assume your change windows, and a support organisation used to customers who cannot simply hand over a cloud tenant for diagnosis.

03

Data residency and processing residency in one stroke

Cloud SIEM residency conversations get complicated fast, because there are two questions and vendors often answer only the first. Where is the data stored, and where is it processed? A vendor may hold your logs in an Indian region while performing analytics, support access or model inference elsewhere. Establishing exactly what happens where takes a documentation exercise, contractual commitments and usually a legal review. Self-hosting collapses both into one answer: the data never leaves your estate, so storage and processing are wherever your racks are. Under the DPDP Act, and against RBI, SEBI and IRDAI expectations about where regulated data lives and is handled, that is a materially shorter conversation with your compliance function and your auditor. It is also more durable — a cloud vendor's residency posture can change with a regional consolidation; your own data centre's cannot change without your say-so.

04

Detection content that arrives populated, with compliance evidence beside it

A SIEM with no content is a database with a query language. Over 1,100 prebuilt correlation rules, mapped to MITRE ATT&CK and to specific compliance mandates, mean the platform produces meaningful alarms early rather than after a long authoring project. For a lean security team — and most are leaner than the estate they defend — that difference decides whether the deployment delivers value in the first quarter or becomes an expensive log archive. The compliance modules matter for the same reason: ISO 27001, PCI DSS, HIPAA, SOX, NIST and CIS reporting is prebuilt, so the quarterly evidence request stops consuming an analyst for a week. Treat the rule library as a strong starting position rather than a finished strategy — it still needs tuning against your estate, and any vendor claiming otherwise is selling you noise.

05

The honest caveat — two platforms, one roadmap, and iron you must run

Exabeam now maintains two SIEM platforms. New-Scale is cloud-native with the louder growth story; LogRhythm SIEM is self-hosted with the longer history. That is a fair position, and LogRhythm SIEM is demonstrably still shipping — April and July 2026 both added real capability. But the merger's own record is instructive: where products overlapped, Exabeam consolidated, retiring Axon in favour of New-Scale. The platforms do not overlap today, because one is self-hosted and one is not. Still, ask for the roadmap in writing before you sign, with named release commitments and a support horizon, as a contractual attachment rather than a slide. Separately, price the second half of the deal honestly: self-hosted means you buy, run, patch and capacity-plan the infrastructure, and you own the upgrade windows and storage growth. That is often cheaper than a per-GB cloud meter at scale, and sometimes it is not. Model it over three years, not one.

06

The honest positioning

Buy LogRhythm SIEM when self-hosting is a requirement rather than a preference — because a regulator, a client contract, a sovereignty rule or a board decision has ruled out SaaS for your security telemetry, or because you operate genuinely disconnected environments. In that situation it is one of a small number of serious candidates, with two decades of on-premises heritage and detection and compliance content already populated. If SaaS is permitted, the calculus changes and you should look hard at Exabeam's own New-Scale, at Microsoft Sentinel if you are already deep in Azure, and at Google SecOps and Cortex XSIAM — you will likely get more analytics per rupee and no infrastructure to run. And if self-hosting IS required, still compare honestly against Elastic Security, ManageEngine Log360, Fortinet FortiSIEM, Kaspersky KUMA, Splunk and Wazuh. TechBag sells across that field, and we would rather place you on the platform your constraints actually point to than defend the wrong one at renewal.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

1100+ rules
Prebuilt correlations, ATT&CK-mapped
Exabeam
over 20 years
Of on-premises SIEM engineering heritage
Exabeam
9 frameworks
With prebuilt compliance reporting
Exabeam
2 releases
Shipped in 2026 — April and July
Exabeam
2024
Exabeam and LogRhythm merged, July
Company
0 cloud deps
Required to operate — self-hosted by design
Deployment

What your LogRhythm SIEM rollout looks like

Weeks 1–2Qualify

Qualify the constraint

Establish in writing WHY self-hosting is required: the regulation, contract clause, board decision or air-gap reality. Get compliance to state it precisely — 'data must not leave India' and 'data must not be processed by a third party' lead to different shortlists.

Weeks 2–6Size

Size the estate and the iron

Inventory log sources and measure actual ingest, then add the sources you will onboard in years two and three. Size indexer storage against your real retention obligation, not current practice. This phase produces the number that decides the business case.

Months 2–5Deploy

Deploy, onboard and tune

Stand up the platform, connect high-value sources, and let the prebuilt rules run before you touch them. Then tune against your own environment and map coverage against ATT&CK honestly. Bring in LogRhythm Intelligence once baseline data is meaningful.

OngoingOperate

Operate and review

Run it as a production system with change control on rule definitions, tracked upgrade windows and monitored storage growth. Review coverage quarterly. Re-confirm the roadmap annually at renewal — and revisit the self-hosting constraint itself every couple of years.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
Our regulator's position on SaaS for security logs made the shortlist for us. Three of the platforms we liked most simply were not eligible. LogRhythm was, and it works.
Head of Information Security
Banking
Financial Services
The 1,100 rules are real and they are useful. They are also not tuned for your environment, and nobody tells you that clearly enough at the start. Budget a proper tuning project.
SOC Manager
Financial Services
Government
Support understands customers who cannot just hand over a cloud tenant. That sounds minor until you have argued with a vendor who cannot debug anything without remote access to your data.
Security Architect
Government
Manufacturing
Investigation workflow has genuinely improved this year. The case handling in the recent releases is a step up from where we started.
Senior Analyst
Manufacturing
Insurance
Honestly, the infrastructure is the hard part, not the software. We under-sized storage in year one and paid for it in year two when retention requirements went up.
Infrastructure Lead
Insurance
Healthcare
Compliance reporting saves us about a week a quarter. That was the line item that got the renewal signed, not the detections.
GRC Manager
Healthcare
Telecom
We asked directly about the roadmap versus New-Scale before signing. We got a straight answer and put it in the contract. I would advise anyone to do the same.
CISO
Telecom
IT Services
Behavioural analytics through LogRhythm Intelligence found a credential-misuse pattern our correlation rules had no way of catching. That justified the add-on on its own.
Threat Detection Lead
IT Services
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ExabeamThis page

UEBA heritage, with a real self-hosted answer.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
ExabeamThis page

Behavioural depth, and a meter that suits big volume.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

LogRhythm SIEM vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionExabeamSecuronixSplunk Enterprise SecurityMicrosoft SentinelElastic Security
PositionUEBA-led SecOps, cloud AND self-hostedThe other UEBA-led vendorThe reference SIEMSIEM for Microsoft estatesSearch-engine-native SIEM
Pricing axisMonitored users + sources + modulesGB/day, hybrid commitment + PAYGIngest or workload — historically costlyPer GB ingested per daySubscription tier + resources
Behavioural analyticsThe founding capabilityThe founding capabilityAvailable, an add-on heritageUEBA includedEntity risk scoring
Self-hosted optionLogRhythm SIEM — genuinely on-premCloud-native onlyCloud, on-prem or hybridSaaS only, on AzureSelf-managed, even air-gapped
Analyst standing (SIEM MQ 2025)Long-running MQ presenceLeader, six times runningLeaderLeaderVisionary, not Leader
Augments a SIEM you ownNew-Scale Analytics, licensed separatelyUEBA availableBuy the platformBuy the platformBuy the platform
AI in the SOCNova — seven agents, named jobsSam, the AI SOC analystCisco AI AssistantSecurity Copilot + MCPElastic AI Assistant
Talent poolSmaller than the incumbentsSmaller than the incumbentsSPL — the largest by farKQL — widely knownLarge for the engine, smaller for security
The thing to plan aroundTwo platforms post-merger — ask the roadmapCloud-only; model the GB/dayCisco integration reshaping roadmapAzure portal retires 31 Mar 2027You operate it unless you buy Cloud
Best fitLarge log volume, small team — or on-premUEBA-led with Leader standingEngineers who will build with itMicrosoft-standardised estatesAir-gapped, or existing ELK
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does LogRhythm SIEM fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Exabeam if…

  • Your log volume is large relative to your security headcount — the user-based meter favours exactly that shape
  • You need behavioural analytics rather than more rules, and you want the vendor that built on it
  • Your mandate rules out cloud — LogRhythm SIEM is a genuine self-hosted platform, not a retrofit
  • You want to add analytics to a SIEM you already own rather than replace it

Choose Securonix if…

  • You want the other UEBA-led vendor, with six consecutive Gartner MQ Leader placements — and cloud-native suits you

Choose Splunk if…

  • You have engineers who will build with it, and you want the deepest content and the largest talent pool (TechBag sells it)

Choose Microsoft Sentinel if…

  • Your estate is Microsoft — first-party logs ingest free and SIEM shares the Defender incident queue

Choose Elastic Security if…

  • You need air-gapped deployment, or your engineers already run Elasticsearch

LogRhythm SIEM is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Exabeam meters on monitored users; most of the category meters on gigabytes ingested. Which is cheaper depends entirely on the ratio between your log volume and your headcount — and it genuinely goes both ways, so this calculator will tell you when a rival is the better buy. Illustrative only: Exabeam is quote-only with no published list, and the comparator is an ingest-metered SIEM at roughly ₹249/GB. Move both sliders to find your crossover.

2,000
25050,000
300
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is cheaper for your shape and you should buy that one — a large workforce with modest logs is exactly the case where Exabeam’s meter works against you. Neither figure is a quote. TechBag models both properly before recommending either.

An ingest-metered SIEM, at your GB/day
₹2,72,26,080
Difference vs Exabeam’s user meter
₹2,43,26,080
₹12,16,30,400 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Self-hosted licensing, quote-only, and you supply and run the infrastructure. The reason this page exists separately is that after the July 2024 merger LogRhythm SIEM is exclusively on-premises — LogRhythm's own cloud product, Axon, was retired in favour of New-Scale. So if your mandate rules out SaaS, this is a mature product rather than a cloud product bent into an on-prem shape. Do ask about roadmap investment relative to New-Scale, in writing. TechBag scopes and quotes in INR with GST.

LogRhythm SIEM

Quoteself-hosted licence

Best when cloud is ruled out

  • On-premises only — you supply the infrastructure
  • 1,100+ prebuilt correlation rules
  • Residency answered by definition: data never leaves

+ LogRhythm Intelligence

Quoteanalytics add-on

Best for detection depth

  • Behavioural intelligence on the self-hosted platform
  • The UEBA heritage, on-prem
  • Ask how it maps to New-Scale Analytics

+ NetMon

Quotenetwork monitoring

Best for network visibility

  • Network monitoring alongside the SIEM
  • Available on self-hosted and cloud
  • Scoped as an add-on, not bundled

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Constraint

Is self-hosting an actual requirement in writing — regulation, contract or board decision — or an inherited preference nobody has re-tested?

2
Residency

Does your obligation cover PROCESSING as well as storage, and have you asked every cloud vendor about both separately?

3
On-prem claims

For each competitor claiming on-premises support, does it run fully inside your boundary, or depend on a vendor cloud for content or licensing?

4
Infrastructure

Have you sized storage against your real retention obligation plus three years of ingest growth, and costed the hardware and staffing?

5
Roadmap

Have you obtained a WRITTEN commitment on release roadmap and support horizon relative to New-Scale, as a contract attachment?

6
Content

Who owns rule tuning after go-live, and is there a named person with budgeted days in the first six months?

7
Compliance

Do the prebuilt modules map to the mandates your auditor tests — and have you shown a sample report to that auditor before signing?

8
Alternatives

Have you compared against Elastic Security, Log360, FortiSIEM, KUMA, Splunk and Wazuh on the same self-hosted criteria?

FAQ

Questions buyers ask

LogRhythm SIEM is a self-hosted security information and event management platform. You install it on infrastructure you own and control — your data centre, your racks, or a private cloud you manage — and it collects, parses, stores, correlates and alerts on log and event data from across your estate. It has been developed as an on-premises product for over twenty years. Exabeam and LogRhythm merged in July 2024 under Thoma Bravo ownership. Chris O'Malley, who had led LogRhythm, ran the combined company through the integration; Pete Harteveld, previously chief revenue officer, became CEO in October 2025. The merger changed three things that matter to a buyer. First, it clarified positioning: LogRhythm SIEM is now unambiguously the self-hosted platform in a two-platform portfolio, with New-Scale as the cloud-native one. Second, it retired LogRhythm Axon — LogRhythm's own cloud SIEM — in favour of New-Scale, because the two overlapped and New-Scale had the traction. If you were an Axon customer, that consolidation affected you directly. Third, it brought Exabeam's behavioural analytics to the self-hosted side as LogRhythm Intelligence, and added a sync service aligning case status, risk scores and ATT&CK data between the platforms for organisations running both. What the merger did not do is end development. LogRhythm SIEM shipped releases in April and July 2026, adding investigation workflow, archiving automation and broader telemetry coverage. That is a live product, not a maintenance-mode one — though we would still advise getting the forward roadmap in writing.

Ready to evaluate LogRhythm SIEM?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.