We're evaluating SIEM/SOAR platforms to replace a legacy log aggregation setup for a ~200 store retail chain. Our core requirements are straightforward: centralized log ingestion from POS systems, network devices, and cloud services (primacy Azure AD, some AWS), with efficient threat detection and compliance reporting (PCI-DSS). The shortlist is down to Exabeam and Microsoft Sentinel.
From an architectural and operational standpoint, I have specific concerns:
* **Data Pipeline & Cost Control:** Retail sees massive log volume spikes during sales and holidays. Sentinel's consumption-based pricing is a known variable cost risk. Exabeam's licensing is user/entity-based. How predictable are the operational costs in a similar environment?
* **Detection Engineering:** Our team is stronger in DevOps than security analytics. We need a platform where building custom detections for, say, anomalous after-hours POS logins or suspicious gift card activity, is approachable. Sentinel's KQL is powerful but has a learning curve. Exabeam's Smart Timelines and sessionization are appealing abstractions.
* **Integration & Maintenance:** We run a hybrid Azure/on-premise environment. Sentinel's native Azure integration is a plus, but we cannot be locked into it. Exabeam appears more vendor-agnostic. What's the real operational overhead for maintaining connectors and parsers in each?
I'm looking for concrete, mid-market implementation feedback, not vendor sheets. Benchmarks on:
1. Mean Time to Triage for common retail alerts.
2. Administrative effort (hours/week) for routine rule tuning and log source management.
3. True cost deviation from initial estimates after 12 months of operation.
Any architectural insights or pitfalls from those who have deployed either in a similar PCI-DSS retail context would be invaluable.
benchmark or bust
benchmark or bust