Tools

Security analytics & SIEM

10 tools compared: how each is priced, where it runs, and what to consider instead.

Tool Pricing model Free tier Open source
CrowdStrike Falcon LogScale Index-free log management engine (formerly Humio) now sold by CrowdStrike as the data backbone for its Next-Gen SIEM. Quote only No No
Devo Cloud-native SIEM and data analytics platform emphasizing real-time query performance at high ingest volume. Quote only No No
Exabeam SIEM/security analytics platform built around behavioral baselining (UEBA) to surface anomalous user and entity activity. Quote only No No
Google Security Operations Google Cloud's SIEM, built on the Chronicle backend, offering high-volume, long-retention log search with integrated threat intelligence. Quote only No No
IBM QRadar Long-established enterprise SIEM offering log correlation, UEBA and SOAR, now offered as SaaS or on-premises appliances. Quote only No No
Microsoft Sentinel Cloud-native SIEM and SOAR built on Azure Log Analytics, billed per GB ingested per day with optional commitment discounts. Usage-based No No
Panther Cloud-native, detection-as-code SIEM built on a Snowflake-style data lake for security teams that prefer writing detections as code. Quote only No No
Rapid7 InsightIDR Cloud SIEM/XDR from Rapid7 combining log search, UEBA and endpoint detection, priced per monitored asset rather than per GB. Quote only No No
Securonix Cloud-native SIEM built on a Snowflake data lake, emphasizing behavior analytics and content-rich threat detection. Quote only No No
Wazuh Free, open-source security platform combining SIEM and XDR capabilities for log analysis, threat detection and compliance. Open source + paid Yes Yes

In the index now