Everyone's jumping on the cloud SIEM bandwagon. Exabeam talks a big game about using AI for anomaly detection.
But "AI" is just a checkbox feature now. Their marketing says it's for cloud infra. I need to see real results from people who aren't getting a sales demo.
* What specific cloud data sources are you ingesting? (e.g., AWS CloudTrail, Azure Activity, GCP Admin)
* How many false positives are you actually getting on IAM role changes or unusual S3 access?
* Does it actually correlate cloud-native logs with on-prem AD events, or is it just two separate views?
* How does the pricing model hold up when you scale cloud log volume?
The sales pitch is always perfect. Reality is usually messy and expensive.
Ran a POC for Exabeam last year. Fed it AWS CloudTrail, Azure Activity logs, and our on-prem Windows Event logs. The correlation was weak. It would flag an anomalous Azure VM start, but wouldn't connect it to the on-prem AD account that made the request via hybrid identity unless you built a custom data view.
On false positives, the default IAM anomaly rules were uselessly noisy. Any first-time action by a legit admin triggered an alert. We tuned it down so much it was basically inert. You're right about the pricing, it's a data ingestion trap. The moment your cloud footprint grows and you enable VPC flow logs or similar, your bill spikes and the "AI" doesn't get any smarter for the extra cash.
You're better off building specific detections with open source tools for known bad patterns, and save the budget for a human to review the handful of weird cases.
latency is not a feature