Exabeam headquartered in San Mateo, Exabeam Fusion, a SIEM + XDR. The vendor states the modular Exabeam platform allows analysts to collect unlimited log data, use behavioral analytics to detect attacks, and automate incident response. The Exabeam platform can be deployed on-premise or from the cloud. Exabeam can also integrate information from the Exabeam Threat Intelligence Service, or into a third-party SIEM.
N/A
SolarWinds Threat Monitor
Score 7.8 out of 10
N/A
SolarWinds Threat Monitor empowers MSSPs of all sizes by reducing the complexity and cost of threat detection, response, and reporting. You get an all-in-one security operations center (SOC) that is unified, scalable, and affordable.
As a SIEM tool for investigations, Exabeam is the best in class. The AI assigns numeric values to observed logs them presents high scores to the analyst in a simple dashboard. We can see what is a real threat and ignore so many false positives. Exabeam is the best SIEM was used from an alert fatigue perspective. The simple interface allows other teams not just InfoSec to utilize the tool; helpdesk for asset diagnoses, HR for staffing questions, etc.
Due to the high price that SolarWinds has, I do not recommend it for small companies. And if I recommend SolarWinds in large companies with complex infrastructures where constant monitoring and review of the network is required, this system is very complete and helps everyone in the technology team, both network administrators, database administrators, Security Administrators, and Server Administrators are all very happy with this system.
More and better drop-down menus, some items in threat hunter require you know subsets.
Less dashboards, combine AA and DL without having separate logins.
More complete playbooks are already built out. You have the structure set up for templates like malware and phishing, go further and completely build them out from start to finish, most companies would just use them and not personalize their configurations.
Quarterly health checkup diagnostics of systems sent out to users.
Exabeam is very good at processing lots of logs without excessive licensing costs. It has a professional support team that's very quick to resolve any issues and provides custom parsers quickly and enables our analysts to search vast data sets without having to wait long for results to be returned. The product is getting more mature with new features every major release.
Exabeam Fusion has so many diffferent out reach meetings, webinars, community virtual coffees, and events that you can always stay abreast of what if happening and get new ideas for use cases. Their support actually answers their phones and can respond in chat instantly. With our cloud deployment Exabeam support teams can instantly see our systems and help us.
SolarWinds offers live chat support for all its products built-in. So if you are working on something you can just reach out to someone at that time, and usually get an answer pretty quick. If you are trying to get something done it's a lot better than submitting a ticket and waiting for the email response.
Threat Monitor is very new on the scene. Its obviously not at the same level as some of the established vendors yet. We also deploy Alienvault for example and its nowhere near the same level as this, however the cost model between these two products reflects that. Alienvault however does have a physical footprint on the environment, whereas Threat Monitor doesnt. If you have the paitence to wait, Threat Monitor will surely only improve over time.
The positive impact that this system has on our company is that it has saved us a lot of expenses when it comes to investigating what the bank's network and systems are.
This saving translates into administrators' time when it comes to finding the problem quickly, expeditiously, and effectively.
It has helped us a lot and we have even required fewer hours from external providers when it comes to solving a problem.