A 2025 Gartner Magic Quadrant Leader you can run on your own hardware — Gurucul Next-Gen SIEM is available as SaaS, cloud or self-hosted, per Gartner's own report text. Of the six 2025 Leaders, it is the only one an Indian buyer under an on-premises mandate can actually deploy.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Where data lives
Yours, if you self-host
Gartner’s own 2025 MQ text confirms the platform runs SaaS, cloud OR self-hosted. Self-hosted puts collection scope and physical storage under your control — on-premises or your own cloud account, in India if you choose — which is how you hold 180 days of logs in Indian jurisdiction and evidence it.
Two things we could NOT verify
Air-gap, and any India region
A genuine air gap is marketed but we could not confirm it independently, and self-hosted is not the same thing — air-gap affects licence activation, threat-intel updates and support access. We also found no evidence of a vendor-run India data region. Get both in writing before you commit.
Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs stay producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it becomes unambiguous is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, self-hosting stops being a preference. Note too that people in India and data in India are different things — the Pune engineering centre is real, and it is not a data region.
Quick answer
This page covers Gurucul Next-Gen SIEM — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A next-generation SIEM on the REVEAL platform, converging log management with behavioural analytics, identity analytics, network traffic analysis and SOAR on one data model.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Gurucul |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Monitored users — grows with headcount |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
SIEM, UEBA, identity analytics, network traffic analysis and SOAR run against the same data rather than as separately licensed products stitched together. Most of this market was assembled by acquisition, which is why the seams show as duplicated storage and separate consoles. Gurucul built the analytics first in 2010 and grew the SIEM around it, so the behavioural layer is not an add-on you reconcile later.
Gartner's own Magic Quadrant text confirms all three. Self-hosted is the one that matters for a regulated Indian buyer, because it puts both the collection scope and the physical storage location under your control — which is how you answer CERT-In's requirement to hold 180 days of logs within Indian jurisdiction and evidence it to an auditor.
Baselines each user and entity, correlates identity, access and activity, and scores deviation. This catches the attacker who signs in correctly with stolen credentials and does permitted things — every step allowed, so no rule fires. It is the gap rule-based detection structurally cannot close, and closing it is what the company was founded to do.
Entitlements and access patterns scored for risk rather than catalogued: excess privilege, dormant high-risk access, and the permissions that accumulate around people over a decade of role changes. Because it shares the platform's identity model, access risk and detection reason over the same picture of who your users are.
Traffic analysis on the same platform, so network evidence lands in the same timeline as endpoint and identity events. Useful precisely when an endpoint is compromised and its own telemetry can no longer be trusted.
Playbooks and automated response included on the platform rather than sold as a separate product with its own meter — which is how Splunk and several others price it. Stage automated response carefully before letting it act on production, as with any SOAR.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Collects logs and telemetry from endpoint, network, identity, cloud and SaaS sources into one platform.
Runs on infrastructure you control if a mandate requires it — confirmed by Gartner rather than only by the vendor.
Correlates entitlements and access data with activity, so detections carry who-can-do-what context rather than just what happened.
Adds wire-level evidence to the same timeline, which matters when a compromised endpoint's own telemetry cannot be trusted.
Models normal behaviour per user and entity and scores deviation, catching credential abuse and insider misuse that break no rule.
Accumulates risk across identity, endpoint and network signals rather than treating each alert as an isolated event.
Ships and updates detection logic so the platform produces useful alerts without a dedicated detection-engineering function.
Analysts move from a risk score to the underlying raw events on the same platform, without exporting to a second tool.
Automated response workflows included on the platform rather than licensed as a separate product with its own meter.
Reporting for the frameworks Indian regulated buyers report against, including material mapped to SEBI's CSCRF.
Endpoint protection, XDR and Security Copilot.
The SIEM the 2025 MQ evaluated.
The converged platform underneath.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
This is the entire reason the page exists, so we will be direct. There are six Leaders in the 2025 Gartner Magic Quadrant for SIEM and TechBag sells all six. Microsoft Sentinel is cloud-only on Azure. Google Security Operations is cloud-only. Securonix is cloud-native — our own Securonix pages state plainly that no configuration of it answers an air-gap mandate. Exabeam is cloud-led, with LogRhythm providing its self-hosted path. Splunk does self-host, and prices accordingly. Gartner's report text says Gurucul Next-Gen SIEM is available as SaaS, cloud or self-hosted. So for the buyer whose mandate requires the platform on infrastructure they control, this is the one Leader that qualifies. Until now our honest answer to that buyer was Elastic Security or Wazuh — both genuinely capable, both requiring you to operate the platform yourself, one a Visionary and the other carrying no analyst standing at all. That is a fine answer for a team with platform engineers and a poor one for a bank that wants a commercial product with a vendor behind it.
A rule only catches what somebody thought to write down in advance. A stolen credential signs in correctly, from a plausible location, and accesses exactly what that account is entitled to access — every individual step permitted, so nothing fires. The only way to catch it is to know what normal looks like for that specific user and score the deviation. Gurucul was founded in 2010 to do precisely that and grew a SIEM around the analytics, which is the reverse of how most of this market was assembled. The practical consequence is that UEBA is not a separately licensed layer you reconcile with your SIEM later — the risk score and the raw events live on the same platform, so an analyst moves between them without switching tools or waiting on an export.
Most SIEM platforms meter on data ingested, which creates a genuinely damaging dynamic: every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Gartner records that Gurucul offers all-inclusive per-asset and per-user pricing among its options, and that axis removes the pressure entirely — asset and user counts change slowly and forecast cleanly, which is a far easier conversation with a finance function than a variable data bill. Now the precision, because this is where enthusiasm outruns the evidence: Gurucul offers per-asset pricing as an ALTERNATIVE to per-GB, not instead of it. Data-volume and EPS-based options sit on the same list, and at least one public reviewer references a 10 GB/day tier. Which axis you land on is negotiated, so settle it in the order form.
Saryu Nayyar founded Gurucul in 2010 and is still its CEO — confirmed as recently as its Black Hat USA 2026 materials. For a platform you are betting detection on, a founder-led company with no investor pressure toward a licence change or a forced exit is worth something concrete, and buyers who lived through other vendors being acquired and repriced will recognise why. The India dimension is real rather than decorative: Gurucul Solutions Private Limited has been incorporated in Pune since June 2013, Pune is the principal engineering base, and the company publishes India-specific material mapped to SEBI's CSCRF — which is unusual for a vendor this size and suggests the India go-to-market is deliberate.
Gurucul is privately held and bootstrapped, having taken no institutional funding in fifteen years. That is genuinely unusual and Gurucul markets it as stability. The other half of the same fact is that it has no war chest, and it is competing directly against Microsoft, Google and Cisco, all of whom can bundle a SIEM into estates you already own. Its analyst standing is also Gartner-specific rather than universal: it is absent from the June 2025 Forrester Wave for Security Analytics Platforms, where the other five Leaders all appear, and its KuppingerCole Overall Leader award is from the 2024 report. None of this makes it a poor product — the Gartner placement is real and hard-won. It means vendor scale is a question your risk function should answer deliberately rather than discover at renewal.
Buy Gurucul Next-Gen SIEM when the deployment constraint is doing the deciding: a regulator, a contract or your own posture requires the platform on infrastructure you control, and you want an analyst-recognised commercial product rather than an open-source stack you operate alone. In that specific situation it is close to unique on our shelf. Buy something else in three cases. If your estate is standardised on Microsoft 365 with E5 licences, Sentinel's bundled economics are very hard to beat and we will tell you so. If cloud is acceptable and you want the largest possible vendor behind you, Securonix or Sentinel are the safer institutional choices. And if you need a genuine air gap with no internet path at all, get that confirmed in writing first — self-hosted is verified, air-gapped is not, and we would rather you establish it now than at your audit.
Does a regulator, a contract or your own posture require the platform on infrastructure you control? That single answer eliminates most of the Leaders quadrant before any feature comparison, and it is the reason Gurucul is on your list at all. If SaaS is acceptable to you, price Sentinel and Securonix too — they are larger companies and the case for a boutique weakens considerably.
Self-hosted is confirmed by Gartner. A genuine air-gapped deployment is marketed but we could not independently verify it, and we found no evidence of a vendor-run India data region. If either matters to you, make them written pre-conditions rather than assumptions. TechBag obtains both as part of the quote.
Gurucul can meter per asset, per user, per module, by data volume or by EPS. The per-asset and per-user axes are the ones that break the logging-costs-more dynamic, but they are a negotiation outcome rather than a default. Confirm which axis your order form specifies — this is the single highest-value clause in the contract.
Behavioural analytics is bounded by directory quality. Peer groups built on a stale directory produce confident nonsense, and unowned service accounts generate alerts nobody can adjudicate. Do this work first — it improves your posture regardless of which vendor ultimately wins.
Behavioural models need time observing normal before their output should be acted on. Teams that evaluate alert quality in week two are deciding on bad evidence. Agree the baselining period up front so nobody mistakes an immature model for a poor product.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Self-hosting was not a preference for us, it was the mandate. This was the only Gartner Leader that could meet it.”
“The behavioural side caught an account takeover our previous SIEM had logged and ignored. Same data, better question.”
“Get the pricing axis written into the order form. We assumed per-asset and had to negotiate our way back to it.”
“Smaller vendor, and you feel it in the ecosystem. You also feel it in how quickly someone senior picks up the phone.”
“Budget the identity data work before deployment. Peer groups built on our old directory were not worth acting on.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
2025 MQ Leader — and the only one that self-hosts.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
One data model — SIEM, UEBA, identity and NTA.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Gurucul | Securonix | Exabeam | Microsoft Sentinel | Splunk ES |
|---|---|---|---|---|---|
| 2025 Gartner MQ | Leader — first year, after 3 as Visionary | Leader, 6 consecutive years | Leader, 6th time | Leader | Leader, 11th consecutive |
| Self-hosted / on-premises | YES — SaaS, cloud or self-hosted per Gartner | No — control plane is always their cloud | Via LogRhythm, a second platform | Cloud-only on Azure | Yes, and priced accordingly |
| Pricing axis | Per asset / per user, OR data volume / EPS | GB/day in tiered bands | Monitored users and sources | Per GB ingested per day | Ingest or workload — the priciest here |
| Behavioural analytics | The founding capability, built 2010 | The founding capability | The founding capability | UEBA included | Available, add-on heritage |
| India data residency | Self-hosted: yours. No vendor India region found | BYO-AWS/Snowflake can hold data in India | Self-hosted via LogRhythm | Azure India regions available | Self-hosted: yours to place |
| Vendor scale | Bootstrapped boutique — no war chest | VC-backed, ~450 engineers in India | Post-merger with LogRhythm | Microsoft | Cisco-owned |
| Analyst breadth | Gartner-specific — absent from 2025 Forrester Wave | In both Gartner and Forrester | In both | In both | In both |
| The thing to plan around | Air-gap unverified; confirm the pricing axis | No air-gap at all; 120% default overage | Two platforms post-merger | Azure portal retires 31 Mar 2027 | Untuned, it is the costliest log archive there is |
| Best fit | On-premises mandates needing an analyst-recognised product | Cloud-accepting estates wanting retention solved | User-based economics, or on-prem via LogRhythm | Microsoft estates with E5 | Engineers who will build with it |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Gurucul Next-Gen SIEM is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Gurucul can meter per asset or per user as an alternative to per-gigabyte ingest. That is the comparison worth modelling, because it is the one that changes behaviour: on an ingest-priced SIEM every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Move both sliders — the assets you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number, since Gurucul is quote-only. It is the shape: asset counts change slowly, log volume only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. And remember the precision that matters here: Gurucul offers per-asset pricing as an alternative to per-GB, not instead of it — data-volume and EPS options exist on the same list. Which axis you land on is negotiated, so make it a clause rather than an assumption.
Gurucul is quote-only — no published list price. What Gartner does record is the set of metering axes: all-inclusive per-asset and per-user pricing, enterprise agreements, module-based, data-volume and EPS-based, and platform-based. The per-asset and per-user axes are the valuable ones because they break the dynamic where logging more costs more — but be precise, they are offered as an alternative to per-GB, not instead of it. Which axis your order form specifies is a negotiation outcome and the single highest-value clause in the contract. TechBag quotes in INR with GST.
Breaks the logging-costs-more trap
What you may be offered instead
The reason to shortlist it
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does a regulator, contract or posture require the platform on infrastructure we control?
If we need a genuine air gap, do we have Gurucul's written confirmation? Self-hosted is not the same thing.
Where will the platform run, and can we evidence that placement to an auditor?
If we want vendor-hosted SaaS inside India, have we asked directly? We found no evidence one exists.
Does our order form specify per-asset, per-user, per-module, data volume or EPS?
Is our directory clean enough for peer groups to mean anything, and do service accounts have owners?
How many weeks will we allow before judging alert quality?
Has our risk function accepted a bootstrapped boutique competing against Microsoft and Google?
Have we priced Sentinel and Securonix too, in case the deployment constraint does not actually bind us?
Are we citing the Gartner position specifically, rather than implying universal analyst consensus?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.