Talk to us
by SolarWindsTechBag Intel Page

Security Event Manager

Your logs sit on a hundred servers until an auditor asks for them. They should already be in one place you control — Security Event Manager collects, correlates and keeps your logs on one appliance you run — on your own hypervisor or cloud account, licensed by node rather than by gigabyte.

On-premises SIEM applianceLicensed by node, not by GBStarts at $1,789, unit by quote

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Unit and term not published
From $1,789
Deployment
VMware, Hyper-V, Azure, AWS or GCP
Appliance
Analysts
No MQ or Wave placement for SIEM
None
India
Logs stay where you install SEM
Your hardware

Quick answer

SolarWinds Security Event Manager (SEM) is an on-premises SIEM shipped as a virtual appliance for VMware or Hyper-V, or for your own Azure, AWS or GCP account. It gathers logs through hundreds of connectors, correlates them in memory, triggers Active Response actions and produces ready-made compliance reports. It is licensed by log-emitting nodes rather than gigabytes; SolarWinds lists it at “Starts at $1,789” without naming the unit or term. The logs stay on hardware you choose. Read more ↓ Show less ↑
Part 01 · Orient

The SolarWinds platform family

This page covers Security Event Manager — the on-premises SIEM appliance, its agents and the optional Platform Connect link. The rest:

Quick facts

30-second orientation
Product
On-premises SIEM, delivered as a virtual appliance
Formerly
Log & Event Manager (LEM)
Runs on
VMware vSphere or Hyper-V; your Azure, AWS or GCP
Licence
By log-emitting nodes, not by log volume
Price
“Starts at $1,789” — unit and term not stated
Scale
Up to 10,000 events a second on a large appliance
Storage
250 GB default disk; raw syslog kept 50 days
Analysts
No SIEM analyst placement published
India
Logs stay on the hardware you install it on
In India via
TechBag — INR/GST, sizing and support
Part 02 · Learn

Understand SIEM before you choose one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a SIEM?

Security information and event management gathers logs from every system into one place, spots attack patterns across them, and keeps the record auditors ask for.

Logs scattered across servers vs one SIEM appliance — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionLogs left on each serverSecurity Event Manager
Where logs liveOn each server until they roll overOne appliance on hardware you choose
Finding an eventRDP into boxes and read Event ViewerOne search across every normalised source
Proving complianceSpreadsheets built the week before auditScheduled PCI DSS, HIPAA or ISO reports
Responding to a threatAn email alert someone reads tomorrowActive Response blocks, disables or kills
What the bill tracksPer-GB meters that grow with noiseNodes: servers, devices and workstations
What it is NOT—Not a SaaS SIEM or a SOAR platform

The cheapest test is the 30-day trial: point five critical sources at it, fire one Active Response rule, and schedule one audit report.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where logs are judged

Manager

SEM Manager appliance

One Linux virtual appliance receives every event, normalises it, runs the correlation rules in memory before writing to disk, and serves the web console to analysts and auditors.

02
On the machines you watch

Agents

SEM Agents

Agents on Windows, Linux, AIX, HP-UX and Solaris — or as a Kubernetes DaemonSet — send events, watch file changes, enforce USB policy and carry out Active Response.

03
Devices without an agent

Connectors

Connectors and syslog

Firewalls, switches, routers and appliances send syslog or SNMP traps to the Manager, where prebuilt connectors parse each vendor’s format into one common event schema.

04
The only cloud link

Platform Connect

Platform Connect (optional)

An opt-in link to SolarWinds’ SaaS for anomaly detection, a technical preview in 2026.2. Raw logs stay on the appliance; only anonymised metric counts travel out.

One appliance judges every event — agents and syslog feed it, rules fire in memory, and only an opt-in link reaches the cloud.

Part 03 · Evaluate

Nine capabilities. Collect, detect, respond.

Security Event Manager gathers every log onto one appliance you control and acts when a rule fires.

Collect
Connectors

Hundreds of log formats, one schema

Prebuilt connectors read Microsoft, Linux, Cisco, Palo Alto and many other sources and normalise them so one search covers every device.

Collect
Agents

Agents from Windows to AIX

SEM Agents cover Windows 10, 11 and Server 2012 to 2025, Linux, AIX, HP-UX and Solaris, and run in Kubernetes as a node-level DaemonSet.

Collect
Storage

Compressed events, raw logs on request

The event store compresses 40:1 to 60:1; raw syslog is kept 50 days, and an optional original-log store keeps source messages per connector.

Detect
Correlation

Rules that fire before the write

Events are normalised and correlated in memory before they reach the database; hundreds of built-in rules ship, and you can build your own.

Detect
Threat intel

Known-bad addresses tagged for you

An integrated, regularly updated threat feed marks traffic from known malicious IP addresses so the correlation rules can act on it at once.

Detect
FIM

File, folder and registry changes

File integrity monitoring ties each change, deletion or permission edit to the Active Directory user who made it, with filters to cut the noise.

Respond
Active Response

Rules that act, not just alert

A fired rule can block an IP, disable an account, kill a process, log a user off, quarantine a machine or change Active Directory settings.

Respond
USB Defender

Unknown USB drives, blocked

USB Defender reports every flash-drive connection in real time, blocks unapproved devices automatically and keeps an audit report of USB use.

Respond
Compliance

Audit reports out of the box

Ready reports for PCI DSS, HIPAA, SOX, ISO, DISA STIGs, FISMA and NERC CIP, scheduled as CSV or PDF by email or to a server over SFTP.

See it, don’t just read it

Watch Security Event Manager in action

A two-minute tour of Security Event Manager, setting up file integrity monitoring, and building separate dashboards for separate jobs.

SolarWinds (official)·Overview

SolarWinds Security Event Manager Overview

What SEM does, in just over two minutes.

SolarWinds (official)·FIM

Configuring File Integrity Monitoring in SolarWinds® Security Event Manager

Setting up file and registry change alerts.

SolarWinds (official)·Dashboards

Security Event Manager 2025.4 Update - Multiple Dashboards

Separate dashboards for separate jobs.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Security Event Manager

Per-gigabyte SIEMs punish noisy logs, and SaaS SIEMs move them offshore. Security Event Manager keeps them on your hardware — billed by device.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Logs that never leave your racks

SEM is an appliance you install on your own VMware or Hyper-V host, or in an Azure, AWS or GCP account you control. Raw logs and identifiers stay on it; even the optional Platform Connect link sends only anonymised counts. Keeping logs in India comes down to where you install it.

02

A bill that counts devices, not gigabytes

Licences are sold by node — a Universal licence such as SEM150 covers 150 servers, firewalls or switches, and a Workstation Edition such as SWE250 covers 250 Windows desktops. A firewall that suddenly logs twice as much does not raise the licence, unlike a per-GB SIEM.

03

Sized for a small security team

Correlation rules, compliance reports, file integrity monitoring, USB control and automated responses are in the box, and SolarWinds says you need not be a security or compliance expert to get value. For an IT team that owns security part-time, that matters more than a query language.

04

Where it stops

One appliance tops out around 10,000 events a second, retention is only as long as the disk you give it, and the $1,789 starting price names no unit or term. You patch it yourself — CVE-2024-0692, an 8.8 flaw, needed 2023.4.1 — and anomaly detection is still a cloud-linked preview.

The idea
One SIEM appliance on your own hardware
The meter
Nodes, not gigabytes of logs
The price
Starts at $1,789; unit by quote
Proof, not promises

The numbers behind the platform

$1789
SolarWinds’ “starts at” price for SEM — the unit and term are not stated, so confirm them on a quote
— Vendor
10000 EPS
the top of the large-deployment sizing — about 864 million events a day on one appliance
— Vendor docs
60:1
the upper end of the event store’s compression, which SolarWinds puts at 40:1 to 60:1
— Vendor docs
50 days
of raw syslog kept in its original format by default, rotated daily
— Vendor docs
250 GB
default disk on a small appliance, 230 GB of it allowed for the SEM database
— Vendor docs
30 days
of a fully functional free trial before you buy
— Vendor

What your Security Event Manager rollout looks like

Week 1Model

Count nodes and measure events

List servers, firewalls, switches and Windows desktops by licence type, and measure peak events a second — that sets the appliance size.

Week 2Scope

Size storage for the mandate

Work out the disk that holds 180 days of events for CERT-In, decide whether raw logs are kept, and grow the database disk to match.

Week 3Pilot

Trial on your own hypervisor

Deploy the 30-day trial on VMware or Hyper-V away from the internet, point five critical sources at it and check the connectors parse.

Month 2Tune

Tune rules and switch on responses

Silence noisy rules, add groups for admins and approved USB drives, then turn on Active Response one action at a time.

Month 3Commit

Schedule reports and a patch rhythm

Schedule compliance reports to auditors, set backups of the appliance, and name an owner who applies every SEM release.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
140+ reviews*
82% would recommend
Ease of setup4.4
Compliance reports4.4
Active Response4.2
Search at high volume3.7
Pricing clarity3.6
5★
44%
4★
36%
3★
12%
2★
5%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Cooperative Banking
“Our regulator wanted the logs inside our own data centre. SEM runs on the Hyper-V cluster we already had, so nothing went to a vendor cloud.”
Head of IT Infrastructure
Cooperative Banking
Manufacturing
“The USB rule paid for itself in month one. An unapproved drive on a plant PC was blocked and the account disabled before anyone phoned us.”
IT Manager
Manufacturing
Logistics
“Licensing by node let us point every noisy firewall at it without watching a gigabyte meter. The quote took a while to arrive, though.”
Network Security Engineer
Logistics
Payments
“The PCI DSS report pack covered most of what our assessor asked for. We scheduled it as a PDF to the audit team every Monday.”
Compliance Officer
Payments
Healthcare
“180 days of retention meant growing the database disk well past the default 250 GB. Size storage on day one, not after the first audit.”
Systems Administrator
Healthcare
Education
“Search slows once a year of events piles up. For our two-person team the built-in rules still beat writing detections from scratch.”
IT Security Lead
Education
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SIEM market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag SIEM Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
SolarWinds SEMThis page

On-prem appliance; from $1,789, unit not stated.

Grid 02 · The architecture

Log Custody × Built-in Content

The grid nobody publishes — how much control you keep over where logs are stored, India included, vs how much detection and response content ships in the box.

Deep content, vendor cloudDeep content, host anywhereCloud-first basicsSelf-host toolkits
SolarWinds SEMThis page

Appliance only; rules, FIM, USB, Active Response.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Security Event Manager vs the SIEM field

Against ManageEngine Log360, Splunk Enterprise Security, Microsoft Sentinel, Elastic Security and Wazuh — on deployment, licensing, price, scale, detection and India.

DimensionSolarWinds SEMManageEngine Log360Splunk Enterprise SecurityMicrosoft SentinelElastic SecurityWazuh
What it isAppliance SIEMSIEM suite, India-builtEnterprise referenceCloud-native SIEMOpen-core SIEMFree SIEM + XDR
DeploymentYour hypervisor or IaaSOn-prem or cloudSelf-host or SaaSAzure SaaS onlySelf-managed or cloudSelf-host or Wazuh Cloud
Log sources coveredHundreds of connectorsBroad device coverageSplunkbase ecosystemConnectors, M365 nativeElastic Agent + FleetAgent-first coverage
Pricing modelPer node, not per GBPer log sourceIngest or workloadPer GB ingestedFree, tier or usageFree; Cloud by agents
Published entry price“Starts at $1,789”$795/yr, 10 sourcesQuote only$6.02/GB, Central IndiaFrom $0.09/GB ingestFree; Cloud $571/month
Included vs add-onFIM, USB, response inUEBA and AD audit inSOAR sold separatelyLogic Apps billed apartFeatures by tierEverything included
Scale and limits10,000 EPS per applianceMid-market scaleVery large estates50,000 GB/day tiersScale-out clusters500 agents on Cloud list
Detection depthRules + threat feedRules plus UEBAESCU content, SPLKQL rules plus MLRules plus ML jobsRules, no ML
IntegrationsSyslog out, CSV exportManageEngine stackLargest app catalogueAzure and M365 nativeFleet integrationsIntegrator scripts
Governance and accessAD users, session limitsAD sign-in, rolesSAML and RBACEntra ID and Azure RBACSAML on paid tiersRBAC and SAML SSO
India storage regionWherever you install itIndia DCs or on-premMumbai, or self-hostCentral India storageGCP Mumbai, or self-hostMumbai ap-south-1
SupportPaid premium tiersWith maintenanceTiers by contractAzure support plansSupport by tierCommunity, or bespoke
Lock-in and exitSyslog out, CSV outRules stay behindSPL does not portNo term, KQL-boundOpen source exitGPLv2, self-host exit
Best fitLean on-prem IT teamsIndian mid-marketStaffed SOCsMicrosoft estatesEngineering-led teamsBudget, hands-on teams
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Security Event Manager if…

  • ✓Logs must stay on hardware you control, and a SaaS SIEM is not an option
  • ✓You want a bill that counts devices rather than gigabytes of noisy firewall logs
  • ✓A small IT team needs built-in rules, audit reports and automated responses on day one

Compare alternatives if…

  • ✓You ingest far beyond 10,000 events a second — Splunk or Elastic scale out further
  • ✓You live in Microsoft 365 and Azure — Sentinel ingests Microsoft’s own data free
  • ✓Budget is near zero and you have engineers — Wazuh costs nothing to license

Do not expect…

  • ✓A published per-node price — the $1,789 figure names no unit or term
  • ✓A SaaS edition — SEM is an appliance you run and patch
  • ✓Machine-learning detection on premises — anomaly detection is a cloud-linked preview

Security Event Manager is one of 35 siem & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does chasing logs by hand cost you?

Drag the sliders (log-emitting nodes; analyst-hour cost). Estimates model IT time spent pulling logs from individual systems for audits and chasing alerts by hand at an assumed 1.5 hours per node a year, with 70% of it removed by central collection, scheduled reports and automated responses. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual log-handling time cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Published, in USD: SolarWinds lists Security Event Manager as “Starts at $1,789” but does not state the unit or the term, so the figure for your estate comes on a quote. Licences are counted in nodes — Universal nodes for servers and network devices, Workstation Edition for Windows desktops — not in log volume, and a fully functional 30-day trial is free. TechBag counts your nodes and sizes the appliance first, then quotes in INR with GST.

Universal licence (SEM)

Best for servers and network devices

  • Counts Windows Server, Unix and non-agent devices
  • Firewalls, switches and routers each one node
  • e.g. SEM150 covers 150 universal nodes

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Workstation Edition (SWE)

Best for watching Windows desktops

  • Counts Windows workstations running the agent
  • FIM, USB Defender and responses on desktops
  • e.g. SWE250 covers 250 workstation nodes

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Licence

How many servers and network devices, and how many Windows desktops? Universal and Workstation Edition licences are counted separately.

2
Price

What exactly does “Starts at $1,789” buy? Ask for the node count, the term and whether maintenance is included, in writing.

3
Retention

How many days of events will your disk hold? CERT-In asks for 180 days of logs; the default appliance ships with 250 GB.

4
Raw logs

Does your auditor need original log messages or normalised events? Keeping raw logs adds 50% to CPU and memory sizing.

5
Throughput

What is your peak events per second? One large appliance is sized for up to 10,000; beyond that plan a split.

6
Patching

Who applies SEM releases and watches SolarWinds’ Trust Center advisories? Self-hosted means your team patches it.

7
Cloud link

Will you enable Platform Connect for anomaly detection? It needs internet access and sends anonymised counts to SolarWinds.

8
Billing

Can finance pay SolarWinds in USD, or do you need INR invoicing with GST through a reseller?

FAQ

Questions buyers ask

SEM is an on-premises SIEM from SolarWinds, delivered as a virtual appliance. It collects logs from agents and network devices, normalises and correlates them in memory, stores them in a compressed event store, runs automated Active Response actions and produces compliance reports. It was once sold as Log & Event Manager.

Ready to evaluate Security Event Manager?

Count your servers, devices and desktops first, or let a TechBag advisor size the appliance and disk for CERT-In's 180 days and run a trial on your own hypervisor.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.