There’s a new brand of security information and event management (SIEM) startups that are making moves — and gunning for incumbents including Splunk and IBM. Three in particular, Exabeam, Chronicle, and Stellar Cyber, announced significant deals and product news this past week aimed at displacing the old guard and pulling a bigger piece of the lucrative $124 billion market.

All three startups have strong technology, and impressive rosters of investors and founders. But their collective quest to displace Splunk isn’t going to be easy.

Exabeam today said it bought Israel-based SkyFormation, a cloud application security company that collects cloud logs from more than 30 cloud services and can feed them into any SIEM tool. “We’ve been working with the SkyFormation team since 2016,” said Ted Plumis, Exabeam’s vice president of channels, business, and corporate development. “We OEM-ed part of their solution and we called it our Cloud Connecters product.”

Bringing this technology in-house “increases our margins here at Exabeam and makes the revenue better, and helps us on that track to go public,” Plumis explained. It also pushes Exabeam further into cloud security, helps the company establish an office in Israel, and gives them access to sought-after Israeli cybersecurity talent, he added.

This is Exabeam’s first acquisition and follows on the heels of its recent $75 million Series E funding round. “We’re kicking ass in the market and continuing to displace the legacy vendors,” Exabeam CEO Nir Polak said at the time. Who are those legacy vendors? Polak named IBM, McAfee, RSA, and Splunk. “When we go head-to-head with them in replacement deals, we win 72% of the time,” he said.

The SkyFormation acquisition will further this goal by allowing Exabeam to add capabilities to its platform, Plumis said. Exabeam’s platform combines SIEM and user and entity behavior analytics (UEBA) to collect all of a company’s log data from various sources (on-premises data center, clouds, IoT, and other devices) and then use machine-learning-powered behavioral analytics to detect threats and automate response.

“We’ve always had the augmentation play,” Plumis said. “We’ve always been able to augment Splunk and IBM with our advanced analytics, and over time the customers choose to migrate to our data lake and our full SIEM.”

At press time, Splunk and IBM did not respond to requests for comment.

Stellar Cyber

Stellar Cyber is another one of these next-generation SIEMs using artificial intelligence (AI) and machine learning (ML) to automate threat hunting and detection. Last week the startup, which launched under the name Aella Data at last year’s RSA Conference, announced a product update and “hockey stick customer growth.”

The company won’t disclose its annual revenue. “But we’re in the multiple-millions this year,” said John Peterson, chief product officer at Stellar Cyber. “We’re no longer a startup doing hundreds of thousands of dollars.”

Stellar Cyber’s strategy has always been to solve the data problem, Peterson explained. “I call it the Goldilocks syndrome: too much or too little data. Not just enough. I won’t point fingers but Splunk, for example, says throw all your logs into this SIEM tool because it will give me more visibility. We don’t believe that. If you create too large of a haystack, that makes it too hard to find needles.”

The new Starlight 3.1 platform collects data and automates breach detection, investigation, and response. The company claims it is the only product that applies ML to firewall data, allowing administrators to send firewall logs for analysis, detection, and response to anomalous firewall actions and rule usage. This helps “get rid of the noise” like false positives, Peterson said.

“And then we created something else we call it ML-IDS,” he said. Intrusion detection systems, or IDS, “has been around a long time, but people who have deployed it know that it’s a very noisy tool. It generates a lot of alarms, a lot of security analysts have alarm fatigue so when a real alarm goes off because of a breach people don’t pay attention to it.”

Stellar Cyber “married” IDS and ML and “the output is a new thing that has a completely different DNA,” Peterson said. “It’s an improved way of doing IDS and the false alarms that were once common are now eliminated.”

Earlier this year Stellar closed a $13.2 million Series A funding round, and it’s already prepping for a Series B, Peterson said. “We’re taking a look at the activity in the market, we’re seeing this hockey stick customer growth and a lot of investment and acquisition activity, and we’re saying maybe we should put our foot on the gas a little faster. We’re accelerating everything right now.”

And that includes taking on the incumbents. “Splunk is a big fish and the big fish out there are being challenged. There are a lot of littler fish like Stellar, LogRhythm, and Exabeam. I’m envisioning a lot of piranhas coming after the big fish and I think a lot of the larger guys are seeing pressure from little guys like us.”

Chronicle

Chronicle is another competitor that Peterson said customers ask about more regularly. “Probably in the last four months their name has started coming up quite a big. Albeit they are Google, so they are big,” he said. “Our response to that: we’re smaller, but we’re going to out innovate and out sell them.”

Peterson and I spoke early last week, before Chronicle officially became part of its sister company Google Cloud. When asked in a later email what the Google Cloud-Chronicle combo means for Stellar, Peterson said: “I do not see this as a threat/bigger competitor and simply see this as a way for Chronicle to leverage the cloud to deliver security. The cloud will enable massive amounts of storage and compute to provide security analytics, however many customers will not trust their security data in the cloud even if it is delivered by Google.”

Chronicle was born in Alphabet’s secretive X research lab and then rolled out as an independent business in January 2018. Earlier this year it launched its long-awaited security platform called Backstory. It’s a next-generation SIEM tool built on Google infrastructure that lets companies upload, store, and analyze their internal security telemetry to detect and investigate potential threats. Splunk’s stock fell 5% that day.

At the launch event in March — which took place at Google’s offices in San Francisco — Chronicle executives insisted the startup was completely independent from Google. And then last Thursday, Chronicle merged with Google Cloud.

“I guess the benefits of working with GCP outweighed any data privacy concerns that they had, and in the intervening months they discovered it would be beneficial,” said Jon Oltsik, senior principal analyst at ESG and founder of the firm’s cybersecurity service.

The move make sense in terms of consolidating both companies’ security analytics and threat detection efforts, Oltsik said. And when it comes to the larger SIEM market, “Google certainly has a home court advantage,” he added. “But at the end of the day it is going to be about usability, efficiency, and efficacy. There’s a lot going on in the market and Google doesn’t have a monopoly.”

SIEM Moves to the Cloud

Around the same time that Chronicle announced its Backstory product, Microsoft rolled out a new cloud-native SIEM tool called Azure Sentinel, and “we anticipate Amazon will do something similar with its Sqrrl purchase,” Oltsik said. “People are willing to pay” for these types of security tools, he added. “A shrewd player who understands security operations and can write software to that will have a good opportunity in the market.”

Both Stellar Cyber and Exabeam say they fit that bill.

“We started selling about four and a half years ago, and we’ve always sold against bigger competitors,” Exabeam’s Peterson said. Originally those were IBM, McAfee, and Splunk, but “I don’t see any difference with Google or Microsoft or Amazon.” That’s because Exabeam’s platform can run on top of these cloud platforms and analyze data while the cloud companies provide the data store, he explained. “It’s just a different mode of competition for us.”