Exabeam
SIEM and UEBA vendor formed by the 2024 merger of Exabeam and LogRhythm, combining behavioral-analytics-driven detection with a consolidated on-prem and cloud SIEM.
Visit Website ↗Overview
Exabeam built its reputation on user and entity behavior analytics (UEBA), applying machine learning to baseline normal user activity and flag deviations, an approach aimed at catching insider threats and compromised credentials that rule-based SIEM correlation rules miss. In July 2024, Exabeam completed a Thoma Bravo-orchestrated merger with fellow SIEM/UEBA vendor LogRhythm, with the combined company operating under the Exabeam name and former LogRhythm CEO Christopher O’Malley leading it.
The merger consolidates two SIEM vendors that had each struggled to keep pace independently with cloud-native competitors like Microsoft Sentinel and Google Security Operations, betting that combined scale, LogRhythm’s on-prem installed base, and Exabeam’s AI-driven UEBA and Copilot features can sustain a viable mid-market SIEM alternative.
Innovation Matrix Assessment
Post-merger roadmap is focused on integrating LogRhythm's on-prem customers onto Exabeam's cloud-native New-Scale platform, a multi-year migration rather than a fast-moving product cadence.
UEBA-driven behavioral baselining genuinely helps catch credential-based attacks that pure log-correlation rules miss, a well-established value proposition in the category.
A merger of two mid-market SIEM vendors under private-equity ownership is a consolidation signal reflecting competitive pressure more than independent growth momentum.
UEBA is now a standard feature bundled into most modern SIEM/XDR platforms rather than a differentiator unique to Exabeam.
Both legacy Exabeam and LogRhythm have long production track records in enterprise SOCs, though efficacy evidence is primarily vendor case studies.
Faces direct pressure from cloud hyperscaler SIEMs and platform-consolidation plays like Cortex XSIAM, making its multi-year relevance uncertain.
Why CISOs Should Care
Existing LogRhythm or Exabeam customers get a continued upgrade path with behavioral analytics baked in, rather than being forced into an immediate SIEM replacement project.
What Makes It Different
The combined company's differentiation rests on merging two UEBA-native SIEM codebases rather than introducing a new detection architecture, positioning it as a consolidation play rather than a disruptive one.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A defensive, private-equity-driven merger of two established mid-market SIEM vendors facing pressure from cloud-native and platform-consolidation competitors. Lands in the Incremental Innovator range.
Editorial Note: Claims vs. Verified Findings
Merger terms, completion date, and leadership are confirmed via Thoma Bravo and Exabeam press releases and independent trade coverage. Product-level efficacy claims (e.g., detection-time reduction figures) are vendor-sourced.
Sources
- SDxCentral — https://www.sdxcentral.com/news/siem-and-ueba-vendors-logrhythm-and-exabeam-to-merge-analysts-express-mixed-feelings/
- Thoma Bravo press release — https://www.thomabravo.com/press-releases/exabeam-and-logrhythm-complete-merger-and-announce-new-company-details
- Wikipedia (LogRhythm) — https://en.wikipedia.org/wiki/LogRhythm
Alternatives to Exabeam
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Microsoft Sentinel
Microsoft's cloud-native SIEM, deeply integrated with Azure and Microsoft 365 telemetry, now layering agentic AI (Security Copilot/Sentinel agents)…
Google Security Operations
Google's cloud-scale SIEM/SOAR (formerly Chronicle), unifying a petabyte-scale data lake with Mandiant frontline threat intelligence and Gemini-powered investigation.
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…
Arctic Wolf
Managed detection and response provider delivering a 24/7 human 'Concierge Security Team' as a de facto outsourced SOC…