Try our new research platform with insights from 80,000+ expert users

ArcSight Analytics vs Exabeam vs Securonix Next-Gen SIEM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

User Entity Behavior Analytics (UEBA) Market Share Distribution
ProductMarket Share (%)
ArcSight Analytics1.3%
Exabeam9.6%
IBM Security QRadar9.3%
Other79.8%
User Entity Behavior Analytics (UEBA)
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Exabeam1.6%
Wazuh10.9%
Splunk Enterprise Security9.3%
Other78.2%
Security Information and Event Management (SIEM)
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Securonix Next-Gen SIEM1.1%
Wazuh10.9%
Splunk Enterprise Security9.3%
Other78.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

Subhadip Pakrashi - PeerSpot reviewer
A scalable solution that provides a deeper insight and threat analysis about the network
ArcSight Analytics is used to get a deeper insight and threat analysis about the network. The solution's threat analysis gives a good view of the network. We can then compare those vulnerabilities and CVS scores worldwide and get a good understanding of how likely the network is to be hit. The kind of report ArcSight Analytics gives is really good. ArcSight Analytics is a very scalable solution that is easy to deploy.
Stephen-Armstrong - PeerSpot reviewer
The SIEM provides a user-friendly UI experience
When events come into the system, the dashboard categorizes them by the highest risk score, not when they appear on the system. When you've got multiple ongoing incidents you can only see the highest risk score at the top of the list rather than the most recent detection. Exabeam's reporting dashboard could have included a filtering option to filter by the most recent detection.
Mohammed Nadeem Rais - PeerSpot reviewer
The visibility and analytics from Securonix SIEM have become indispensable in identifying and stopping potential threats before they escalate.
The most valuable feature of Securonix Next-Gen SIEM is its advance analytics, flexibility and scalability. We ingest billions of logs without worrying about resource allocation. This makes it a robust and cost-effective solution for our needs. Its user entity and behavior analytics (UEBA) are also integral for detecting insider threats and lateral movements within the organization. These features help organizations strengthen their security posture, protect sensitive data, and maintain compliance with strict regulatory requirements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution allows us to identify connections for all users."
"Allows multiple integrations with multiple systems in a stable and flexible fashion."
"The solution is easy to implement."
"Less resource consumption in terms of memory and processing."
"The data collection and the integration with different products are valuable features."
"ArcSight Analytics has improved our system and network policy monitoring."
"ArcSight Analytics is used to get a deeper insight and threat analysis about the network."
"One of the most valuable features is the alerts."
"Exabeam has improved our organization by speeding up the investigation process."
"The most valuable feature of Exabeam is the timeline creation based on log sources, which helps in security investigations."
"Exabeam includes machine learning features and out-of-the-box rules that we rely on."
"The setup is not difficult. It was easy."
"The UI was very clean."
"Exabeam Fusion SIEM has a good performance and more advantages than traditional solutions."
"The way it can connect with AWS is very useful, and the integrations are pretty good."
"I have customers that like the EUBA functionality of it. The solution has the ability to build a session, basically. It pulls a lot of information together, for example, everything a user does in a specific timeframe. It's quite helpful."
"One of the most valuable features it has is the thread chaining. One of the common issues that we always had was the number of anomalies that we used to get and the number of alerts that we used to get. But with this approach of thread chaining, we've found the false-positive rate has decreased very significantly. That was something that we never could have achieved before."
"Risk scoring was nice. We could exactly see which user had the highest risk score, and then we could pick it up and work on it."
"There aren't any positive aspects of the solution. It was a complete failure. There are no redeeming features."
"[The solution has] incident-management or case-management functionality. If someone were to download a high number and we decided we needed to investigate it, I could open a case right in the tool. It would be able to directly reference the data that they downloaded and we could open and shut the case directly in the tool, as well as report from it."
"The solution has proven to be stable so far...The solution is easy to scale up."
"The feature that I have found most valuable is their analytics platform where they have the open security data-link, which they introduced. This is typically different from the other vendors."
"One of the valuable features of Securonix is the auto-incident creation, which was not available two or three years ago."
"The solution's AI features reduce the need for manual analysis and help in decision-making. It displays the report in seconds. It saves my resources three to four hours of work."
 

Cons

"[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training."
"The customer service could be improved, and additional integrations with other APIs could be added."
"ArcSight is not a user-friendly solution and the interface needs to be improved."
"The interactive dashboard is complicated and you need to have training in order to use it, so I think that it could be made easier to use."
"Inactive connections from servers, which are upgraded or downgraded within a VM, should be automatically revoked."
"It's a difficult product to navigate, it's complex."
"It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."
"Network integration is very crucial, and you need to have the knowledge to get it done."
"The organzation is rigid and not flexible in the way they operate"
"Exabeam lacks customizable dashboards, which might be a limitation if visualization is a key requirement."
"The initial setup of Exabeam Fusion SIEM is complex because it needs to integrate with the SIEM solution, but after this is complete it is straightforward."
"Exabeam needs to improve its adaptive nature towards rules and its capability to understand the entire client environment faster."
"The solution's reporting and dashboarding could be improved."
"One area for the solution's improvement is integration capabilities, particularly out-of-the-box integration which sometimes requires additional professional services."
"Updating the new release of Exabeam Fusion SIEM takes time and slows our performance."
"We had a large volume right from the beginning and they weren't quite prepared for that. That's something that they should think about when it comes to customers that have a large volume to start off with."
"Securonix implements risk scores based on different policies that are triggered. We've seen some challenges with the risk scores and how they trigger. These are things that Securonix has recognized and they've been working with us to help improve things."
"The pricing. I'm not sure how they are proceeding with the identity based pricing compared with DB pricing which most of the vendors are using today."
"The dashboards in Securonix Next-Gen SIEM need more customization and informational capabilities."
"Securonix could open up information regarding the indicators of compromise or cyber-threat intelligence database that they use. The idea is that they share what threats they are detecting."
"We have compliance needs. We have investigation needs. And we have situations where an analyst needs to look at threats. These three things require a different view of how they look at the threats. What would be good is to have Securonix create three different views of their Security Command Center so that, depending on the persona of the person logging in, they'd get the relevant data they need and not see everything."
"There is room for improvement in the product's integration with ServiceNow and in the reporting features."
"When dealing with a large amount of data, such as when firewall logs increase, queries sometimes crash or get stuck."
"SIEM could have better integration with other technologies."
 

Pricing and Cost Advice

"My customers pay a yearly licensing fee for ArcSight Analytics."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"This solution is expensive."
"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"There is an annual license required to use Exabeam Fusion SIEM. The price of the solution should be reduced."
"The solution is expensive."
"They have a great model for pricing that can be based either on user count or gigabits per day."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
"Exabeam Fusion SIEM's pricing is reasonable."
"Exabeam is not a cheap solution."
"Compared to other brands it seems more affordable to us."
"The solution's price is double the competitors."
"I rate the pricing an eight on a scale of one to ten, where one is cheap, and ten is very expensive. It is a pretty expensive tool."
"A good thing about Securonix is that they don't charge by volume of data or number of devices... They charge by the number of employees, which is a much more predictable number for me, versus data. Our costs are in the $100,000 range over a three-year subscription."
"The pricing is good, but by adding more things, the licensing becomes more complex because an EPS license fluctuates a lot. This licensing concept is going to be problematic in the long run."
"I had heard that it was much cheaper than Splunk and some of the other tools, and they gave us a nice package with support. They accommodated the number of users and support very well."
"Compared to other known brands in the industry, the overall cost of the licenses is a bit higher than what customers expect."
"We have an annual license. We pay $200,000 for the base licensing and we pay another $50,000 for the software as a service."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
868,570 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
12%
Computer Software Company
12%
Manufacturing Company
9%
Government
7%
Computer Software Company
17%
Financial Services Firm
9%
Healthcare Company
7%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise3
Large Enterprise7
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise5
Large Enterprise19
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about ArcSight Analytics?
ArcSight Analytics is used to get a deeper insight and threat analysis about the network.
What is your experience regarding pricing and costs for ArcSight Analytics?
My customers pay a yearly licensing fee for ArcSight Analytics.
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on...
What needs improvement with Exabeam Fusion SIEM?
We use the on-prem Exabeam product and face limitations using the web UI and administration of custom models and rule...
Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was ...
What is your primary use case for Securonix Security Analytics?
We work with CrowdStrike, Securonix Next-Gen SIEM, and other cybersecurity products such as Gurucul. We are a service...
What do you like most about Securonix Next-Gen SIEM?
The two major features of this product we extensively use are the UEBA capability and the multi-tenant approach with ...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
No data available
Securonix Security Analytics
 

Overview

 

Sample Customers

Information Not Available
Hulu, ADP, Safeway, BBCN Bank
Dtex Systems, Pfizer, Western Union, Harris, ITG
Find out what your peers are saying about IBM, Exabeam, Cynet and others in User Entity Behavior Analytics (UEBA). Updated: August 2025.
868,570 professionals have used our research since 2012.