I've seen Exabeam discussed extensively for IT security use cases—UEBA, SIEM workflows, and ITDR. However, in my consulting work, I'm increasingly asked about applying these modern SIEM and SOAR tools to *operational* domains, like physical security. The core value proposition (timelines, anomaly detection, automated playbooks) seems transferable in theory.
I'm curious if any community members have implemented or evaluated Exabeam for converging logical and physical security data. For example:
* Ingesting and correlating data from badge access systems, CCTV metadata, or perimeter intrusion detection with HR or IT asset data.
* Using sessionization to build timelines of a physical security incident (e.g., tailgating event) from disparate sensor logs.
* Deploying behavioral analytics to spot anomalies in facility access patterns that might indicate insider risk.
I'm particularly interested in practical hurdles, such as:
* How did you handle the log onboarding and parsing for non-standard, proprietary physical security systems?
* Was the out-of-the-box rule and ML model library useful, or did it require extensive customization?
* Did you face any licensing or cost model challenges when applying it to a high-volume of physical event data?
Any lessons learned, use case examples, or even "it was a non-starter because of X" would be valuable for the community's knowledge base.