Your logs sit on a hundred servers until an auditor asks for them. They should already be in one place you control — Security Event Manager collects, correlates and keeps your logs on one appliance you run — on your own hypervisor or cloud account, licensed by node rather than by gigabyte.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Security Event Manager — the on-premises SIEM appliance, its agents and the optional Platform Connect link. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Security information and event management gathers logs from every system into one place, spots attack patterns across them, and keeps the record auditors ask for.
What consolidation actually replaces, dimension by dimension.
| Dimension | Logs left on each server | Security Event Manager |
|---|---|---|
| Where logs live | On each server until they roll over | One appliance on hardware you choose |
| Finding an event | RDP into boxes and read Event Viewer | One search across every normalised source |
| Proving compliance | Spreadsheets built the week before audit | Scheduled PCI DSS, HIPAA or ISO reports |
| Responding to a threat | An email alert someone reads tomorrow | Active Response blocks, disables or kills |
| What the bill tracks | Per-GB meters that grow with noise | Nodes: servers, devices and workstations |
| What it is NOT | — | Not a SaaS SIEM or a SOAR platform |
The cheapest test is the 30-day trial: point five critical sources at it, fire one Active Response rule, and schedule one audit report.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
One Linux virtual appliance receives every event, normalises it, runs the correlation rules in memory before writing to disk, and serves the web console to analysts and auditors.
Agents on Windows, Linux, AIX, HP-UX and Solaris — or as a Kubernetes DaemonSet — send events, watch file changes, enforce USB policy and carry out Active Response.
Firewalls, switches, routers and appliances send syslog or SNMP traps to the Manager, where prebuilt connectors parse each vendor’s format into one common event schema.
An opt-in link to SolarWinds’ SaaS for anomaly detection, a technical preview in 2026.2. Raw logs stay on the appliance; only anonymised metric counts travel out.
One appliance judges every event — agents and syslog feed it, rules fire in memory, and only an opt-in link reaches the cloud.
Security Event Manager gathers every log onto one appliance you control and acts when a rule fires.
Prebuilt connectors read Microsoft, Linux, Cisco, Palo Alto and many other sources and normalise them so one search covers every device.
SEM Agents cover Windows 10, 11 and Server 2012 to 2025, Linux, AIX, HP-UX and Solaris, and run in Kubernetes as a node-level DaemonSet.
The event store compresses 40:1 to 60:1; raw syslog is kept 50 days, and an optional original-log store keeps source messages per connector.
Events are normalised and correlated in memory before they reach the database; hundreds of built-in rules ship, and you can build your own.
An integrated, regularly updated threat feed marks traffic from known malicious IP addresses so the correlation rules can act on it at once.
File integrity monitoring ties each change, deletion or permission edit to the Active Directory user who made it, with filters to cut the noise.
A fired rule can block an IP, disable an account, kill a process, log a user off, quarantine a machine or change Active Directory settings.
USB Defender reports every flash-drive connection in real time, blocks unapproved devices automatically and keeps an audit report of USB use.
Ready reports for PCI DSS, HIPAA, SOX, ISO, DISA STIGs, FISMA and NERC CIP, scheduled as CSV or PDF by email or to a server over SFTP.
A two-minute tour of Security Event Manager, setting up file integrity monitoring, and building separate dashboards for separate jobs.
What SEM does, in just over two minutes.
Setting up file and registry change alerts.
Separate dashboards for separate jobs.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
SEM is an appliance you install on your own VMware or Hyper-V host, or in an Azure, AWS or GCP account you control. Raw logs and identifiers stay on it; even the optional Platform Connect link sends only anonymised counts. Keeping logs in India comes down to where you install it.
Licences are sold by node — a Universal licence such as SEM150 covers 150 servers, firewalls or switches, and a Workstation Edition such as SWE250 covers 250 Windows desktops. A firewall that suddenly logs twice as much does not raise the licence, unlike a per-GB SIEM.
Correlation rules, compliance reports, file integrity monitoring, USB control and automated responses are in the box, and SolarWinds says you need not be a security or compliance expert to get value. For an IT team that owns security part-time, that matters more than a query language.
One appliance tops out around 10,000 events a second, retention is only as long as the disk you give it, and the $1,789 starting price names no unit or term. You patch it yourself — CVE-2024-0692, an 8.8 flaw, needed 2023.4.1 — and anomaly detection is still a cloud-linked preview.
List servers, firewalls, switches and Windows desktops by licence type, and measure peak events a second — that sets the appliance size.
Work out the disk that holds 180 days of events for CERT-In, decide whether raw logs are kept, and grow the database disk to match.
Deploy the 30-day trial on VMware or Hyper-V away from the internet, point five critical sources at it and check the connectors parse.
Silence noisy rules, add groups for admins and approved USB drives, then turn on Active Response one action at a time.
Schedule compliance reports to auditors, set backups of the appliance, and name an owner who applies every SEM release.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our regulator wanted the logs inside our own data centre. SEM runs on the Hyper-V cluster we already had, so nothing went to a vendor cloud.”
“The USB rule paid for itself in month one. An unapproved drive on a plant PC was blocked and the account disabled before anyone phoned us.”
“Licensing by node let us point every noisy firewall at it without watching a gigabyte meter. The quote took a while to arrive, though.”
“The PCI DSS report pack covered most of what our assessor asked for. We scheduled it as a PDF to the audit team every Monday.”
“180 days of retention meant growing the database disk well past the default 250 GB. Size storage on day one, not after the first audit.”
“Search slows once a year of events piles up. For our two-person team the built-in rules still beat writing detections from scratch.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SIEM market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
On-prem appliance; from $1,789, unit not stated.
The grid nobody publishes — how much control you keep over where logs are stored, India included, vs how much detection and response content ships in the box.
Appliance only; rules, FIM, USB, Active Response.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against ManageEngine Log360, Splunk Enterprise Security, Microsoft Sentinel, Elastic Security and Wazuh — on deployment, licensing, price, scale, detection and India.
| Dimension | SolarWinds SEM | ManageEngine Log360 | Splunk Enterprise Security | Microsoft Sentinel | Elastic Security | Wazuh |
|---|---|---|---|---|---|---|
| What it is | Appliance SIEM | SIEM suite, India-built | Enterprise reference | Cloud-native SIEM | Open-core SIEM | Free SIEM + XDR |
| Deployment | Your hypervisor or IaaS | On-prem or cloud | Self-host or SaaS | Azure SaaS only | Self-managed or cloud | Self-host or Wazuh Cloud |
| Log sources covered | Hundreds of connectors | Broad device coverage | Splunkbase ecosystem | Connectors, M365 native | Elastic Agent + Fleet | Agent-first coverage |
| Pricing model | Per node, not per GB | Per log source | Ingest or workload | Per GB ingested | Free, tier or usage | Free; Cloud by agents |
| Published entry price | “Starts at $1,789” | $795/yr, 10 sources | Quote only | $6.02/GB, Central India | From $0.09/GB ingest | Free; Cloud $571/month |
| Included vs add-on | FIM, USB, response in | UEBA and AD audit in | SOAR sold separately | Logic Apps billed apart | Features by tier | Everything included |
| Scale and limits | 10,000 EPS per appliance | Mid-market scale | Very large estates | 50,000 GB/day tiers | Scale-out clusters | 500 agents on Cloud list |
| Detection depth | Rules + threat feed | Rules plus UEBA | ESCU content, SPL | KQL rules plus ML | Rules plus ML jobs | Rules, no ML |
| Integrations | Syslog out, CSV export | ManageEngine stack | Largest app catalogue | Azure and M365 native | Fleet integrations | Integrator scripts |
| Governance and access | AD users, session limits | AD sign-in, roles | SAML and RBAC | Entra ID and Azure RBAC | SAML on paid tiers | RBAC and SAML SSO |
| India storage region | Wherever you install it | India DCs or on-prem | Mumbai, or self-host | Central India storage | GCP Mumbai, or self-host | Mumbai ap-south-1 |
| Support | Paid premium tiers | With maintenance | Tiers by contract | Azure support plans | Support by tier | Community, or bespoke |
| Lock-in and exit | Syslog out, CSV out | Rules stay behind | SPL does not port | No term, KQL-bound | Open source exit | GPLv2, self-host exit |
| Best fit | Lean on-prem IT teams | Indian mid-market | Staffed SOCs | Microsoft estates | Engineering-led teams | Budget, hands-on teams |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Security Event Manager is one of 35 siem & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (log-emitting nodes; analyst-hour cost). Estimates model IT time spent pulling logs from individual systems for audits and chasing alerts by hand at an assumed 1.5 hours per node a year, with 70% of it removed by central collection, scheduled reports and automated responses. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published, in USD: SolarWinds lists Security Event Manager as “Starts at $1,789” but does not state the unit or the term, so the figure for your estate comes on a quote. Licences are counted in nodes — Universal nodes for servers and network devices, Workstation Edition for Windows desktops — not in log volume, and a fully functional 30-day trial is free. TechBag counts your nodes and sizes the appliance first, then quotes in INR with GST.
Best for servers and network devices
Best for a broader rollout
Best for watching Windows desktops
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many servers and network devices, and how many Windows desktops? Universal and Workstation Edition licences are counted separately.
What exactly does “Starts at $1,789” buy? Ask for the node count, the term and whether maintenance is included, in writing.
How many days of events will your disk hold? CERT-In asks for 180 days of logs; the default appliance ships with 250 GB.
Does your auditor need original log messages or normalised events? Keeping raw logs adds 50% to CPU and memory sizing.
What is your peak events per second? One large appliance is sized for up to 10,000; beyond that plan a split.
Who applies SEM releases and watches SolarWinds’ Trust Center advisories? Self-hosted means your team patches it.
Will you enable Platform Connect for anomaly detection? It needs internet access and sends anonymised counts to SolarWinds.
Can finance pay SolarWinds in USD, or do you need INR invoicing with GST through a reseller?
Count your servers, devices and desktops first, or let a TechBag advisor size the appliance and disk for CERT-In's 180 days and run a trial on your own hypervisor.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.