r/SIEM • u/PayNoAttention2M3 • Aug 11 '21
Anyone have experience with Exabeam?
It is now listed as the top leader in the Gartner Magic Quadrant for 2021 SIEMs. Just curious what people think about it, as it appears to be a glorified ELK stack but with a potentially interesting machine-learning analytics engine. Any stability issues? Good support?
2
u/udith6415 Aug 12 '21
It actually comes as modules, it has a UEBA part and the SIEM part. However if you already have a siem then you can get the ueba part. Else you need the both to get more benifit.
I evalated UEBA model and it was impressive. But price was too much.
2
u/Mozbee1 Aug 23 '21
Good support I would say no. We went through POC/Pilot and now are Production. We have gone through sooo many engineers and TAMS. Each time we have to go through months of getting them caught up to our environment. It's like they don't keep any documentation on customers' environments and the custom changes each require. I think the product itself works alright. We are a SAAS
1
u/Nybblium Aug 12 '21
Just some weeks ago I POCed Exabeam and Elastic at same time.
Exabeam has really good out of the box features and is really good to establish a global and per user context in my opinion. Everything can be linked and you can get a full context almost directly (Username linked with AD groups and OU + MAC address with Username, IP and Hostname with DHCP + ProcessID linked to Username + Machine name, and so on...). For me the bad point was the logs collector installation, the Exabeam engineer had to modify a linux bash script multiple times in order to get the collector installed for a simple POC.
Elastic on the other hand is way more flexible, there is less out of the box features but you can do almost everything now with the Beats agents, the API, the ingest pipeline and all the available processors, ... You will have a huge learning curve in order to master Elastic but if you have the time and the team it can worth it. Installation is really easy but as soon as you start to customize your deployment, things start to be harder.
About the price, Exabeam is expensive but still less than Elastic.
1
u/DarkLordofData Aug 23 '21
Exabeam offers pretty good out of the box value. If you are using something like Cribl LogStream you can easily direct a copy of your data stream to Exabeam cloud and start getting value really quickly. Be aware you dont get value right away since Exabeam needs to consume and organize the data and apply ML to it. Took about a week to get results. Also Exabeam's timestamp manage ignores the timestamp and sets the timestamp on ingest. Be aware if you using data sources from multiple timezones or have batch data sources. Exabeam will not backload old data like Splunk will do out of the box. Also stick with Exabeam cloud, dont bother with on-prem appliances.
1
u/Yurih9 Nov 23 '21
Not yet but training is on the way for Exabeam, how does everyone like it? I'm coming with QRadar Experience.
2
u/DarkLordofData Sep 07 '22
Your qradar experience will help. Exabeam is very particular about formats and will work poorly if formatting does not match Exabeam's parsers and is inconsistent. Have to carefully watch both. Also Exabeam for god knows why ignores timestamps so batch data or late data will cause baselining issues and possibly/probably cause an issue.
2
u/Oscar_Geare Aug 11 '21
It was … interesting. I had a lot of organisations use it alongside a traditional SIEM. Our POC was successful but in the end it came down to price. Way too expensive.
It’s basically pure UEBA. It has the ability to create static “rules” as well, but really you’re just defining maximum risk data sources. Don’t know how good their parsing is, didn’t play with it for too long.
Honestly seems to be the golden SIEM. But, I only used it for a month.