Detection across the tools you already bought — Gurucul Open XDR ingests telemetry from your existing endpoint, network, cloud and identity products and layers identity and behavioural analytics on top. Test the connector depth on your own stack: every XDR vendor claims openness.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Where data lives
Yours, if you self-host
Gartner’s own 2025 MQ text confirms the platform runs SaaS, cloud OR self-hosted. Self-hosted puts collection scope and physical storage under your control — on-premises or your own cloud account, in India if you choose — which is how you hold 180 days of logs in Indian jurisdiction and evidence it.
Two things we could NOT verify
Air-gap, and any India region
A genuine air gap is marketed but we could not confirm it independently, and self-hosted is not the same thing — air-gap affects licence activation, threat-intel updates and support access. We also found no evidence of a vendor-run India data region. Get both in writing before you commit.
Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs stay producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it becomes unambiguous is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, self-hosting stops being a preference. Note too that people in India and data in India are different things — the Pune engineering centre is real, and it is not a data region.
Quick answer
This page covers Gurucul Open XDR — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Detection and response across the security tools you already own — endpoint, network, cloud and identity telemetry ingested into one platform, with identity and behavioural analytics layered on top.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Open XDR |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Monitored users — grows with headcount |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
SIEM, behavioural analytics, identity analytics, network traffic analysis and SOAR run against the same data rather than as separately licensed products stitched together. Gurucul built the analytics first in 2010 and grew the SIEM around them, which is why there is one store and one query surface rather than two that disagree.
Confirmed in Gartner's own 2025 Magic Quadrant text. Self-hosted is the option that matters for a regulated Indian buyer, because it puts collection scope and physical storage under your control — which is how you hold 180 days of logs in Indian jurisdiction and evidence it to an auditor.
Models how each user and entity normally behaves, correlates identity, access and activity, and scores deviation. This is what catches the attacker who signs in correctly with stolen credentials — every step permitted, so no rule fires.
Entitlements and access patterns are scored for risk on the same platform, so when behavioural analytics flags a user an analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated.
Telemetry from existing endpoint, network, cloud and identity products is ingested rather than replaced. Test connector depth on your own stack during the proof of concept: rich normalised telemetry and forwarded alerts are both called integrations, and only one supports an investigation.
Playbooks and automated response ship on the platform rather than as a separate product with its own meter, which is how several competitors price it. Stage automated response carefully before letting it act on production.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Runs on infrastructure you control where a mandate requires it — confirmed by Gartner rather than only by the vendor.
Collects logs and telemetry from endpoint, network, identity, cloud and SaaS sources into one platform.
Correlates entitlements and access data with activity so detections carry who-can-do-what context, not just what happened.
Adds wire-level evidence to the same timeline — which matters most when a compromised endpoint's own telemetry cannot be trusted.
Models normal behaviour per user and entity and scores deviation, catching credential abuse and insider misuse that break no rule.
Builds risk across identity, endpoint and network signals rather than treating each alert as an isolated event.
Surfaces excess privilege, dormant high-risk access and permissions accumulated across years of role changes.
Ships and updates detection logic so the platform produces useful alerts without a dedicated detection-engineering function.
Analysts move from a risk score to the underlying activity on the same platform, without exporting to a second tool.
Automated response workflows included on the platform rather than licensed separately with their own meter.
Endpoint protection, XDR and Security Copilot.
The vendor-neutral ingestion story.
The platform it runs on.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
Most organisations do not get to start clean. You have an EDR chosen three years ago, a firewall estate from a different decision, an identity provider nobody will migrate off, and a cloud platform your developers picked. An XDR that requires its own agent everywhere is asking you to re-run all of those decisions at once, which is why so many XDR deployments stall at the pilot. Open XDR's premise is to take telemetry from what you have. For an Indian mid-market buyer with a heterogeneous estate assembled over a decade, that is often the difference between a project that ships and one that becomes a migration programme nobody funds.
Collecting alerts from six tools into one console is not detection, it is a queue. What makes this worth more than aggregation is what runs on top: behavioural and identity analytics that ask whether this activity is normal for this user and whether the access being used should even exist. Identity-based attacks are the specific case where this matters, because there is nothing anomalous to see in any individual tool — the login succeeded, the file access was permitted, the cloud API call was authorised. Only correlating them against a behavioural baseline and an entitlement model surfaces the pattern.
Because Open XDR runs on REVEAL alongside the SIEM and UEBA, the telemetry it ingests is the same telemetry the SIEM reasons over — one data model, one store, one query surface. The alternative pattern, which is common, is an XDR that maintains its own copy of your data next to your SIEM's copy, so you pay to store everything twice and analysts learn two query languages to answer one question. Avoiding that is a real operational saving, and it compounds as data volume grows.
We are going to be direct about this because it is the thing most likely to disappoint you. Every XDR vendor claims openness. The claim is almost never false and almost never means what a buyer assumes. The meaningful question is depth: does the connector for your EDR pull rich process, authentication and file telemetry that analytics can reason over, or does it receive that product's finished alerts and forward them? Both are legitimately called an integration. Only one supports investigation. Pick the two or three tools you most depend on, and during the proof of concept check exactly what arrives for each. If a connector turns out to be alert-forwarding for a tool that carries half your detection value, that changes the product's value to you substantially — and it is far better learned in a PoC than in an incident.
Open XDR is not a managed service. Nobody at Gurucul is watching your alerts or responding on your behalf, and buyers conflate XDR with MDR routinely enough that it is worth stating. It is also not a replacement for your EDR — it consumes endpoint telemetry, it does not provide endpoint prevention, so you still need whatever is doing the blocking. And it is not sold standalone: you are buying the REVEAL platform, of which this is one capability. If what you actually need is somebody watching your environment around the clock, that is a different purchase and we can point you at it.
Choose Open XDR when you have real telemetry spread across tools you cannot or will not replace, and you want identity-aware detection over all of it rather than six consoles nobody has time to watch. It is strongest for exactly the estate that makes pure-play XDR awkward — heterogeneous, accumulated, politically difficult to consolidate. Look elsewhere if you are standardised on a single vendor's stack already, because CrowdStrike or Microsoft will give you deeper native integration within their own estate than any open platform will across it. And look elsewhere if you need someone else to operate it, because this is a product, not a service.
This is part of the REVEAL platform, so the deployment question is the platform's: SaaS, cloud or self-hosted. If a regulator or contract requires infrastructure you control, that is the reason Gurucul is on your shortlist at all, and it should be settled before features.
Peer groups and access risk are both bounded by directory quality. Leavers still active, roles that do not match actual jobs, and unowned service accounts all produce output you cannot act on. This work improves your posture regardless of vendor, so start it before procurement finishes.
Identity, endpoint and cloud control-plane telemetry first — they carry the highest detection value per unit of effort. Resist the urge to connect everything at once; a smaller, well-understood set produces better baselines than a large noisy one.
Behavioural models must observe normal before deviation means anything, and that is weeks rather than days. Agree the period up front with everyone who will evaluate the deployment, and resist heavy suppression during the noisy phase — early over-tuning tends to survive long after the reason for it is gone.
Turn the output into a documented review rhythm with named owners and dated decisions. The evidence trail is worth as much as the findings when RBI or SEBI ask how you govern access, and it is far easier to maintain than to reconstruct.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Behavioural scoring found an account takeover our rule-based SIEM had logged and ignored for eleven days.”
“The identity context is what makes the scores actionable. Without it you are guessing at why someone scored high.”
“Budget the directory clean-up first. We did not, and spent six weeks arguing with output we could not trust.”
“Smaller vendor than the alternatives we shortlisted. The trade is a slimmer ecosystem for faster access to real engineers.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
2025 MQ Leader — and the only one that self-hosts.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
One data model — SIEM, UEBA, identity and NTA.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Gurucul | Securonix | Exabeam | Microsoft Sentinel | Splunk ES |
|---|---|---|---|---|---|
| 2025 Gartner MQ | Leader — first year, after 3 as Visionary | Leader, 6 consecutive years | Leader, 6th time | Leader | Leader, 11th consecutive |
| Self-hosted / on-premises | YES — SaaS, cloud or self-hosted per Gartner | No — control plane is always their cloud | Via LogRhythm, a second platform | Cloud-only on Azure | Yes, and priced accordingly |
| Pricing axis | Per asset / per user, OR data volume / EPS | GB/day in tiered bands | Monitored users and sources | Per GB ingested per day | Ingest or workload — the priciest here |
| Behavioural analytics | The founding capability, built 2010 | The founding capability | The founding capability | UEBA included | Available, add-on heritage |
| India data residency | Self-hosted: yours. No vendor India region found | BYO-AWS/Snowflake can hold data in India | Self-hosted via LogRhythm | Azure India regions available | Self-hosted: yours to place |
| Vendor scale | Bootstrapped boutique — no war chest | VC-backed, ~450 engineers in India | Post-merger with LogRhythm | Microsoft | Cisco-owned |
| Analyst breadth | Gartner-specific — absent from 2025 Forrester Wave | In both Gartner and Forrester | In both | In both | In both |
| The thing to plan around | Air-gap unverified; confirm the pricing axis | No air-gap at all; 120% default overage | Two platforms post-merger | Azure portal retires 31 Mar 2027 | Untuned, it is the costliest log archive there is |
| Best fit | On-premises mandates needing an analyst-recognised product | Cloud-accepting estates wanting retention solved | User-based economics, or on-prem via LogRhythm | Microsoft estates with E5 | Engineers who will build with it |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Gurucul Open XDR is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Gurucul can meter per asset or per user as an alternative to per-gigabyte ingest. That is the comparison worth modelling, because it is the one that changes behaviour: on an ingest-priced SIEM every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Move both sliders — the assets you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number, since Gurucul is quote-only. It is the shape: asset counts change slowly, log volume only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. And remember the precision that matters here: Gurucul offers per-asset pricing as an alternative to per-GB, not instead of it — data-volume and EPS options exist on the same list. Which axis you land on is negotiated, so make it a clause rather than an assumption.
Open XDR is part of the platform rather than a separate purchase with its own meter, so the commercial question is the platform’s pricing axis. The evaluation question is different and more important: connector depth. Every XDR vendor claims openness, and the claim is almost never false and almost never means what a buyer assumes — rich normalised telemetry and forwarded alerts are both called integrations, and only one supports an investigation. Test it on your own stack. TechBag quotes in INR with GST.
Not a separate meter
The thing that decides its value
Scope limits
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does a mandate require the platform on infrastructure we control? That decides the shortlist.
Is our directory clean enough for peer groups and access risk to mean anything?
Do our service accounts have named owners who can adjudicate an alert about them?
How many weeks will we allow before judging output quality?
Are we clear this is part of the platform rather than a standalone purchase?
What do we already own that this must work with rather than replace?
What review cadence and audit trail will we maintain for RBI or SEBI?
If we need a genuine air gap, do we have it in writing? Self-hosted is not the same thing.
Has our risk function accepted a bootstrapped boutique competing with hyperscalers?
If the deployment constraint does not bind us, have we priced Sentinel and Securonix too?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.