Skip to content
CloudTweaks

SIEM / Security Analytics

15 providers in this category.

SIEM platforms aggregate logs and security telemetry to detect threats, investigate incidents, and meet audit requirements. Modern options are cloud-native and increasingly bundle SOAR for automated response. Look at detection content, built-in SOAR, deployment model (SaaS versus self-hosted), free tier, and compliance; pricing is typically ingest- or quote-based.

Companies

Neutral ordering. Not a recommendation.

15 results

CrowdStrike Falcon

www.crowdstrike.com

Endpoint & Threat DetectionSIEM / Security AnalyticsCloud Security (CSPM/CNAPP)

CrowdStrike Falcon is a cloud-delivered endpoint protection platform combining endpoint detection and response (EDR), extended detection and response (XDR), and threat intelligence through a lightweight agent.

$ Budgetfrom $5/device/mo · Last reviewed June 2026
Strengths
Capability, Endpoint detection +2Platforms, 3 OS platformsMaturity, operating 15 yearsCompliance, 4 certifications

Datadog Cloud SIEM

www.datadoghq.com/product/cloud-siem

Datadog Cloud SIEM applies real-time threat detection to the logs already flowing through Datadog, correlating security signals with the observability context of the same platform.

$$$ Premiumusage-based pricing
Strengths
Compliance, 5 certificationsCapability, Cloud-native +1Maturity, operating 6 yearsDeployment, Cloud-hosted

Elastic Security

www.elastic.co/security

Elastic Security is a SIEM and endpoint security solution built on the Elastic Stack for threat detection and investigation.

$$ Midusage-based pricing
Strengths
Capability, Cloud-native +2Deployment, Cloud + self-hostedMaturity, operating 14 yearsCompliance, 3 certifications

Exabeam

www.exabeam.com

Exabeam is a SIEM and security analytics platform that uses behavioral analytics (UEBA) to detect threats based on user and entity behavior.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Maturity, operating 13 yearsDeployment, Cloud-hosted

Google SecOps

cloud.google.com/security/products/security-operations

Google Security Operations (formerly Chronicle) is a cloud-native, Google-scale security operations platform that unifies SIEM, SOAR, and applied threat intelligence, with Gemini AI-assisted investigation.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Maturity, operating 8 yearsDeployment, Cloud-hosted

Hunters

www.hunters.security

Hunters is an AI-driven, cloud-delivered next-generation SIEM and SOC platform that automates threat detection, alert triage, and investigation.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Maturity, operating 8 yearsDeployment, Cloud-hosted

IBM QRadar

www.ibm.com/qradar

IBM QRadar is an enterprise SIEM for threat detection, correlation, and response across high volumes of log and network telemetry.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Deployment, Cloud + self-hostedMaturity, operating 15 yearsCompliance, 4 certifications

LimaCharlie

limacharlie.io

LimaCharlie is a cloud-native 'SecOps Cloud Platform' offering EDR sensors, vendor-agnostic telemetry ingestion, a YAML-based detection-and-response engine, and automation APIs.

$ Budgetusage-based pricing
Strengths
Capability, Cloud-native +2Maturity, operating 8 yearsDeployment, Cloud-hosted

Microsoft Sentinel

www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel

Microsoft Sentinel is a cloud-native SIEM and SOAR platform on Azure for collecting, detecting, and responding to security threats.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Compliance, 5 certificationsMaturity, operating 7 yearsDeployment, Cloud-hosted

Panther

panther.com

Panther is a cloud-native, detection-as-code SIEM built on a Snowflake-backed security data lake for engineering-oriented security teams.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Deployment, Cloud + self-hostedCompliance, 3 certificationsMaturity, operating 8 years

Rapid7

www.rapid7.com

Vulnerability ManagementSIEM / Security AnalyticsCloud Security (CSPM/CNAPP)

Rapid7 InsightVM is a vulnerability-management platform spanning endpoint to cloud, using a single Insight Agent plus agentless scan engines.

$$$ Premiumusage-based pricing
Strengths
Capability, Agent-based scanning +5Maturity, operating 26 yearsCompliance, 4 certificationsOpenness, Self-hostable

Securonix

www.securonix.com

Securonix is a cloud-native SIEM and security analytics platform that emphasizes behavior analytics (UEBA) and threat detection.

$$$ Premiumusage-based pricing
Strengths
Capability, Cloud-native +2Maturity, operating 18 yearsCompliance, 3 certificationsDeployment, Cloud-hosted