Hey folks, I've been deep in the SIEM weeds lately evaluating platforms for our security ops team (yes, they dragged marketing ops into this because of all those pesky campaign logins and API calls we generate 😅). We've got a solid look at QRadar's pricing and workflow, but the licensing model is giving our finance team heartburn.
So we're hunting for alternatives that aren't the usual Splunk or Microsoft Sentinel mentions. Nothing against them, but we've already ruled them out—Splunk's cost curve is a cliff and we're not fully Azure-native for Sentinel to make sense. I'm curious about the other players in the space that handle log aggregation, correlation, and threat detection without needing a dedicated PhD to maintain.
What's everyone using that's actually holding up at scale? I've heard whispers about LogRhythm, Exabeam's Behavioral Analytics approach, and even some newer cloud-native options like Panther or Chronicle. But real-world workflow stories are gold. How's the integration story with CRMs or marketing clouds for those of us tracking user account anomalies? Any love for something like Securonix or even rolling with Elastic SIEM if you've got the in-house muscle?
Basically, what's in your stack that makes you *not* miss QRadar's event processors? Bonus points for anything with a cleaner pricing tier or better cloud data source ingestion.
Automate all the things.