A stolen credential does nothing malformed — Gurucul UEBA baselines every user and entity and scores the deviation, which is the only way to catch an attacker who logs in correctly and does permitted things. It is the capability the company was founded on in 2010, not one it acquired.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Where data lives
Yours, if you self-host
Gartner’s own 2025 MQ text confirms the platform runs SaaS, cloud OR self-hosted. Self-hosted puts collection scope and physical storage under your control — on-premises or your own cloud account, in India if you choose — which is how you hold 180 days of logs in Indian jurisdiction and evidence it.
Two things we could NOT verify
Air-gap, and any India region
A genuine air gap is marketed but we could not confirm it independently, and self-hosted is not the same thing — air-gap affects licence activation, threat-intel updates and support access. We also found no evidence of a vendor-run India data region. Get both in writing before you commit.
Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs stay producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it becomes unambiguous is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, self-hosting stops being a preference. Note too that people in India and data in India are different things — the Pune engineering centre is real, and it is not a data region.
Quick answer
This page covers Gurucul UEBA — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Analytics that learn how each user and entity normally behaves and score deviation — the capability Gurucul was founded on in 2010 and grew a SIEM around.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Gurucul UEBA |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Monitored users — grows with headcount |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
SIEM, behavioural analytics, identity analytics, network traffic analysis and SOAR run against the same data rather than as separately licensed products stitched together. Gurucul built the analytics first in 2010 and grew the SIEM around them, which is why there is one store and one query surface rather than two that disagree.
Confirmed in Gartner's own 2025 Magic Quadrant text. Self-hosted is the option that matters for a regulated Indian buyer, because it puts collection scope and physical storage under your control — which is how you hold 180 days of logs in Indian jurisdiction and evidence it to an auditor.
Models how each user and entity normally behaves, correlates identity, access and activity, and scores deviation. This is what catches the attacker who signs in correctly with stolen credentials — every step permitted, so no rule fires.
Entitlements and access patterns are scored for risk on the same platform, so when behavioural analytics flags a user an analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated.
Telemetry from existing endpoint, network, cloud and identity products is ingested rather than replaced. Test connector depth on your own stack during the proof of concept: rich normalised telemetry and forwarded alerts are both called integrations, and only one supports an investigation.
Playbooks and automated response ship on the platform rather than as a separate product with its own meter, which is how several competitors price it. Stage automated response carefully before letting it act on production.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Runs on infrastructure you control where a mandate requires it — confirmed by Gartner rather than only by the vendor.
Collects logs and telemetry from endpoint, network, identity, cloud and SaaS sources into one platform.
Correlates entitlements and access data with activity so detections carry who-can-do-what context, not just what happened.
Adds wire-level evidence to the same timeline — which matters most when a compromised endpoint's own telemetry cannot be trusted.
Models normal behaviour per user and entity and scores deviation, catching credential abuse and insider misuse that break no rule.
Builds risk across identity, endpoint and network signals rather than treating each alert as an isolated event.
Surfaces excess privilege, dormant high-risk access and permissions accumulated across years of role changes.
Ships and updates detection logic so the platform produces useful alerts without a dedicated detection-engineering function.
Analysts move from a risk score to the underlying activity on the same platform, without exporting to a second tool.
Automated response workflows included on the platform rather than licensed separately with their own meter.
Endpoint protection, XDR and Security Copilot.
The behavioural analytics, demonstrated.
Where the analytics sit.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
This is the whole argument for behavioural analytics and it is worth stating precisely. A rule only catches what somebody thought to write down in advance. An attacker with stolen credentials does nothing malformed — they sign in correctly, from a plausible location, at a plausible hour, and access what that account is entitled to access. Every step is permitted. No signature matches, no correlation rule fires, and the SIEM records it as ordinary activity. The only way to see it is to know what normal looks like for that specific user and score the deviation: this person has never touched that system, never at this volume, never at this hour, and their peer group does not either. The same logic is the only thing that catches an insider misusing access they legitimately hold, which is by definition invisible to any rule about unauthorised access.
Most UEBA in this market arrived by acquisition, bolted onto a SIEM that already existed — which is why so many deployments involve two consoles, two data stores and an analyst exporting from one to the other. Gurucul did it the other way round: the analytics came first in 2010 and the SIEM grew around them. The practical consequence is that a risk score and the events that produced it live on the same platform. An analyst who wants to know why a user scored 87 clicks through to the underlying activity rather than filing a request. That sounds minor and is not — the friction of switching tools is what stops analysts investigating borderline scores, which is exactly where the interesting cases sit.
Behavioural scoring is much stronger when it knows what a user is entitled to do, not merely what they did. Because identity analytics runs on the same platform, deviation is assessed against entitlements: this access was dormant for a year and has suddenly been used, this person accumulated permissions across three role changes and is now using all of them at once. That context is what separates a genuine finding from an anomaly that turns out to be someone doing their new job. It also means access risk and detection reason over one picture of who your users are rather than two that disagree.
We would rather say this plainly than have you discover it in month three. Peer-group analysis compares a user against people like them, and it derives that grouping from your identity data. If your directory is stale — leavers still active, roles not reflecting actual jobs, groups that accreted over a decade — the peer groups are wrong and the model produces confident nonsense. Service accounts are the sharpest version: they behave nothing like humans, they are frequently unowned, and without a named owner nobody can adjudicate an alert about one. Budget the identity hygiene work before deployment, not after. It is unglamorous, it is not the vendor's fault, and it improves your security posture regardless of which product you eventually buy.
Behavioural models need to observe normal before deviation means anything. That period is genuinely weeks, not days, and during it the alerts will be noisier and less useful than they will be later. The failure mode we see is a team evaluating alert quality in week two, concluding the product is poor, and either abandoning it or over-suppressing so aggressively that they blind it permanently. Agree the baselining period up front with everyone who will judge the deployment, so nobody mistakes an immature model for a bad product. And do not over-tune early — suppression added in the noisy phase tends to survive long after the reason for it has gone.
Gurucul UEBA is right when your threat model genuinely centres on credentials and people — insider risk, account takeover, privilege misuse — and you want the behavioural layer on the same platform as your log data rather than alongside it. It is not right as a standalone purchase: it is part of the platform, so you are really deciding on Gurucul Next-Gen SIEM and this is a reason to choose it. And if your identity data is in poor shape and nobody will own fixing it, buy something else, because no UEBA product will work for you until that changes. We would rather tell you that now than sell you an outcome you cannot reach.
This is part of the REVEAL platform, so the deployment question is the platform's: SaaS, cloud or self-hosted. If a regulator or contract requires infrastructure you control, that is the reason Gurucul is on your shortlist at all, and it should be settled before features.
Peer groups and access risk are both bounded by directory quality. Leavers still active, roles that do not match actual jobs, and unowned service accounts all produce output you cannot act on. This work improves your posture regardless of vendor, so start it before procurement finishes.
Identity, endpoint and cloud control-plane telemetry first — they carry the highest detection value per unit of effort. Resist the urge to connect everything at once; a smaller, well-understood set produces better baselines than a large noisy one.
Behavioural models must observe normal before deviation means anything, and that is weeks rather than days. Agree the period up front with everyone who will evaluate the deployment, and resist heavy suppression during the noisy phase — early over-tuning tends to survive long after the reason for it is gone.
Turn the output into a documented review rhythm with named owners and dated decisions. The evidence trail is worth as much as the findings when RBI or SEBI ask how you govern access, and it is far easier to maintain than to reconstruct.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Behavioural scoring found an account takeover our rule-based SIEM had logged and ignored for eleven days.”
“The identity context is what makes the scores actionable. Without it you are guessing at why someone scored high.”
“Budget the directory clean-up first. We did not, and spent six weeks arguing with output we could not trust.”
“Smaller vendor than the alternatives we shortlisted. The trade is a slimmer ecosystem for faster access to real engineers.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
2025 MQ Leader — and the only one that self-hosts.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
One data model — SIEM, UEBA, identity and NTA.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Gurucul | Securonix | Exabeam | Microsoft Sentinel | Splunk ES |
|---|---|---|---|---|---|
| 2025 Gartner MQ | Leader — first year, after 3 as Visionary | Leader, 6 consecutive years | Leader, 6th time | Leader | Leader, 11th consecutive |
| Self-hosted / on-premises | YES — SaaS, cloud or self-hosted per Gartner | No — control plane is always their cloud | Via LogRhythm, a second platform | Cloud-only on Azure | Yes, and priced accordingly |
| Pricing axis | Per asset / per user, OR data volume / EPS | GB/day in tiered bands | Monitored users and sources | Per GB ingested per day | Ingest or workload — the priciest here |
| Behavioural analytics | The founding capability, built 2010 | The founding capability | The founding capability | UEBA included | Available, add-on heritage |
| India data residency | Self-hosted: yours. No vendor India region found | BYO-AWS/Snowflake can hold data in India | Self-hosted via LogRhythm | Azure India regions available | Self-hosted: yours to place |
| Vendor scale | Bootstrapped boutique — no war chest | VC-backed, ~450 engineers in India | Post-merger with LogRhythm | Microsoft | Cisco-owned |
| Analyst breadth | Gartner-specific — absent from 2025 Forrester Wave | In both Gartner and Forrester | In both | In both | In both |
| The thing to plan around | Air-gap unverified; confirm the pricing axis | No air-gap at all; 120% default overage | Two platforms post-merger | Azure portal retires 31 Mar 2027 | Untuned, it is the costliest log archive there is |
| Best fit | On-premises mandates needing an analyst-recognised product | Cloud-accepting estates wanting retention solved | User-based economics, or on-prem via LogRhythm | Microsoft estates with E5 | Engineers who will build with it |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Gurucul UEBA is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Gurucul can meter per asset or per user as an alternative to per-gigabyte ingest. That is the comparison worth modelling, because it is the one that changes behaviour: on an ingest-priced SIEM every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Move both sliders — the assets you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number, since Gurucul is quote-only. It is the shape: asset counts change slowly, log volume only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. And remember the precision that matters here: Gurucul offers per-asset pricing as an alternative to per-GB, not instead of it — data-volume and EPS options exist on the same list. Which axis you land on is negotiated, so make it a clause rather than an assumption.
Gurucul UEBA is part of the platform entitlement rather than a separate meter, so the commercial question is the platform’s pricing axis rather than a per-user analytics licence. What it costs you elsewhere is preparation: peer-group quality is bounded by your identity data, and the models need weeks observing normal before their output should be acted on. Neither is a product fault and both are where deployments actually fail. TechBag quotes in INR with GST.
Not a separate meter
The dependency nobody prices
Plan for this
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does a mandate require the platform on infrastructure we control? That decides the shortlist.
Is our directory clean enough for peer groups and access risk to mean anything?
Do our service accounts have named owners who can adjudicate an alert about them?
How many weeks will we allow before judging output quality?
Are we clear this is part of the platform rather than a standalone purchase?
What do we already own that this must work with rather than replace?
What review cadence and audit trail will we maintain for RBI or SEBI?
If we need a genuine air gap, do we have it in writing? Self-hosted is not the same thing.
Has our risk function accepted a bootstrapped boutique competing with hyperscalers?
If the deployment constraint does not bind us, have we priced Sentinel and Securonix too?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.