Report an Incident Become a Partner Careers Contact
Book a Demo
SIEM

Best SIEM Tools in 2022 — And What Has Changed Since

Heider Albadawi · Senior SOC Analyst 25 September 2026 6 min read
Seven small unlabelled tiles in a row folding down connecting lines into three larger tiles beneath them, with one tile on the far right dimmed and connected to nothing

If you have arrived here looking for a 2022 SIEM shortlist, the most useful thing we can tell you is that most of it no longer exists in the form it did. Three of the names that appeared on nearly every list that year have since been acquired, merged or sold off. A ranked table from 2022 is now a historical document, and treating it as a buying guide would cost you money.

So rather than refresh a list that will date again, here is what actually changed, what did not, and the questions that survive both.

What happened to the 2022 shortlist

The SIEM market consolidated hard, and it happened in a cluster:

  • Splunk is now part of Cisco. The acquisition completed in March 2024. Splunk was the default "enterprise SIEM" answer on most 2022 lists, usually described as an independent vendor. It sits inside a networking and security portfolio now, and the integration story you will be told has changed accordingly — which is a point in its favour if you are a Cisco estate and a consideration if you are not.
  • IBM's QRadar SaaS business went to Palo Alto Networks. Agreed in 2024, with IBM moving customers toward Palo Alto's platform. QRadar was on every serious 2022 shortlist. Anyone evaluating it today is evaluating a different proposition from a different company.
  • LogRhythm and Exabeam merged. Also 2024. Two separate entries on the 2022 lists became one company with an overlapping portfolio to rationalise.

Meanwhile Microsoft has been steadily folding Sentinel into the Defender portal, so the thing described in 2022 as "a cloud SIEM in Azure" is increasingly presented as one console across the Microsoft security estate rather than a SIEM sitting beside it.

The point is not which of these is good news. It is that vendor stability is now part of the evaluation in a way it was not when those lists were written. A SIEM is a five-to-seven year commitment with detection content, trained analysts and integrations built on top of it. Who owns the product matters.

What has not changed at all

Underneath the corporate activity, the things that decide a SIEM choice are almost exactly what they were:

Where your telemetry already lives

This settles more evaluations than any feature comparison. A Microsoft-centric estate points one way. A heterogeneous estate full of appliances, industrial systems and in-house applications points another. An on-premises or air-gapped requirement rules out a good part of the market outright.

How it is charged, and what that does to behaviour

Consumption pricing punishes indiscriminate log collection and rewards thinking about it. Licence-based pricing front-loads that decision and then leaves you alone, at the cost of paying for headroom. Neither is cheaper in the abstract, and the one that is cheaper for you depends on how much you ingest and how predictable it is.

Who operates it

Still the question most comparisons skip, and still the one that decides whether any of this works. Every product on every one of those lists will generate more alerts than an unprepared team can triage.

What is genuinely new since 2022

  • The SIEM/XDR boundary has eroded. In 2022 these were usually separate purchases. Increasingly the detection layer arrives bundled with the endpoint and identity stack, and the SIEM's job shifts toward correlation across everything else.
  • Storage tiering is mainstream. Cheap tiers for high-volume, low-value logs are now standard rather than a differentiator, which changes the old calculation about what you can afford to collect.
  • AI is in every product description, and the range of what that means is enormous — from a natural-language query box to agents that actually work a queue. The word tells you nothing. Ask what it does without a human present, and what happens when it is wrong.

How to choose one now

Four questions, in order. They are duller than a feature table and they will get you a better answer.

  1. Where does most of my security-relevant telemetry already live? If there is a clear answer, it probably decides this.
  2. Can I run this where my data is legally allowed to be? A cloud-only product is not a candidate if your data cannot leave the building.
  3. What does my volume do to the bill, and is my volume predictable? Model it on your real ingest, not on a worked example.
  4. Who is triaging the output at 04:00 on a Sunday? If the answer is "we will work that out", work it out first. It changes which product is right.

Where we stand

We run Managed SIEM and Managed Microsoft Sentinel, and we have run Sentinel since 2019 — so our bias is declared. If your answer to question one points somewhere other than Microsoft, we are not the right people to run it for you, and we would rather say so here than three meetings in.

If it does point at Sentinel, or you are not sure yet, the useful conversation is about what you are ingesting, what it costs to ingest it, and who is on shift when it fires. None of which was on the 2022 list either.

SIEMBuying GuideMicrosoft SentinelSecurity OperationsMarket

Ready to see the agents work?

Book a demo of CYBERSHIELD AI against a real scenario.