Security analytics company Exabeam recently made its extended detection and response (XDR) debut official. And while it’s just the latest in a string of other security vendors to move into the buzzy new segment, Exabeam is notable because it’s the first security information and event management (SIEM) vendor to plant its flag in XDR.

XDR, while a still newish security segment, combines elements of SIEM; security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a cloud-based platform. This centralizes security data, threat hunting, and incident response. Some vendors espouse a platform approach, where their XDR collects telemetry from their native endpoint, email, network, and cloud security sensors and tools, while others prefer an open, “best of breed” approach that integrates with customers’ existing infrastructure.

Unlike their security platform vendor and EDR counterparts, SIEM vendors have been slow to make this pivot. Additionally, SIEM remains a cautionary tale for many XDR vendors, and no one wants to be the next SIEM — a once-promising technology that quickly became unruly in customers’ environments, and without orchestration or analysis became just another dumping ground for logs and data.

In fact, according to Forrester analyst Allie Mellen, “XDR and SIEM are not converging but colliding.”

In a recent blog post, Mellen argues that “XDR will compete head to head with security analytics platforms (and SIEMs) for threat detection, investigation, response, and hunting.”

So the choice for SIEMs and security analytics is thus: Innovate or die.

‘XDR and SIEM Are Colliding’

In an interview with SDxCentral, Mellen said that SIEMs have slowly evolved over the past decade. Most now include a SOAR component, along with network analysis, visibility, and user behavior analytics — or, at the least, they integrate with other vendors that provide these tools. “So we’re seeing growth on the side of SIEMs, but they don’t really have this big competitor to the way they approach security analytics in the market today,” she said. “And that’s really my hope for XDR and why I say they’re on this collision course.”

While SIEMs hunt for threats by collecting a ton of data, running security analytics on top of it, and “trying to find a needle in the haystack,” XDR approaches threat investigation and response from a different angle, Mellen said. “The approach that XDR is taking is to continue to increase protections on the endpoints, and then enriching on top of that with all of this really powerful information from the network and different clouds, from identity and access management.”

And while she doesn’t expect to see XDR win market share from SIEM in the next year, “as we come to better understand what the endpoint is, which security practitioners are already doing, it’s really just the vendor side that needs to catch up,” Mellen said. “Then XDRs capabilities will start to really siphon off the threat detection and response use cases from the SIEM.”

XDR’s key differentiator is its basis in endpoint threat detection and response, she added.

Is XDR a Wake-Up Call to SIEM Vendors?

“Without that, you just end up with a security analytics platform or a SIEM,” Mellen said. “With XDR, when vendors are building out their offering, they need to think about it through that lens, and choose very carefully what sources to include starting with the endpoint and then most likely expanding into cloud, which really does seem to be the next place where enterprise data is moving.”

Her message to vendors is to innovate and find better ways to address security operations centers’ (SOCs) pain points. “This needs to serve as a wake-up call for some vendors who are trying to compete on detection and response use cases and be the most-used tool in the SOC,” Mellen said. “One of the most exciting parts about this: It feels like we finally have true competition for the SIEM, so it’s really an opportunity. I’m talking about things like automated root cause analysis, incident investigation instead of individual alerting, recommending response actions to analysts, and lowering the barrier to entry for security teams, which is so critical because one of our biggest issues in this industry is the skills gap.”

How Vendors Differentiate on XDR

Mellen noted early XDR adopters including Palo Alto Networks and Trend Micro as well as endpoint and workload security companies SentinelOne and CrowdStrike, which have more recently launched XDR platforms, as XDR vendors “that have a strong strategy for the future."

And she described Exabeam as a SIEM that is innovating to face XDR players.

“They are very use-case driven for what they’re actually giving to security analysts, and that can really be beneficial to take the analyst through the journey of how to respond to an attack, especially for newer analysts or those who are less experienced,” Mellen said.

She’s referring to Exabeman’s threat detection, investigation, and response (TDIR) use-case packages, which are built into its Fusion XDR. These provide prescriptive workflows and other content around data sources, detection models, watchlists, investigation checklists, and response playbooks designed to assist security analysts.

“Another example that is doing a very interesting job is Rapid7 — they are really expanding their portfolio,” Mellen added.

Just last month Rapid7 acquired Velociraptor, an open-source technology and community used for endpoint monitoring, digital forensics, and incident response. This acquisition will help the security analytics vendor build out its incident response and endpoint capabilities — both of which will play important roles if Rapid7 moves into XDR.

Rapid7 is also moving more into the cloud security market via mergers and acquisitions. In February, it bought Kubernetes security company Alcide, and about a year ago it acquired cloud security posture management provider DivvyCloud.

“In addition, there are some really unique solutions coming to market like Devo,” Mellen said. “They are doing a really impressive job at making the transition from more of that IT-side SIEM to that security side. And the amount of data that they’re able to take in and analyze is baffling.”

SIEM Strikes Back

When asked about how some of these next-generation SIEM players stack up to the grandfather of all SIEMs — Splunk, which has since expanded into infrastructure monitoring, and application monitoring — Mellen characterized the vendor’s new Observability Cloud as an “interesting and innovative” move.

“Rapid7 and Exabeam, in particular, really put a premium on user experience, making it easier to use, and that really does add a lot of value, especially considering most security teams are not large,” she said. “That said, Splunk is absolutely still a leader in the market.”

Splunk isn’t worried about XDR eating the security analytics market, said Jane Wong, VP of security products at Splunk.

“XDR does not replace security analytics platforms or security information and event management (SIEM) solutions today,” she wrote in an email. “XDR feeds into these solutions in a coexistence scenario for the modern security operations center.”

In fact, Splunk’s security analytics platform can give XDR a threat detection boost, she added. “Centralizing all data, with the intent to deliver advanced analytics, streamlined operations through automation and orchestration, with tight collaboration from a thriving and diverse set of ecosystem partners is the formula for modern security operations,” Wong wrote.

Exabeam, meanwhile, takes a similar stance on how XDR and SIEM will evolve. Customers are never going to have just one platform or vendor in their security operations center, Exabeam Chief Product Officer Adam Geller said. And because of this, customers will always need a vendor-agnostic security analytics service that spans all of the data across all of their environments. In other words: a company like Exabeam.

“XDR players today and EDR players, they’re trying to add more of the log collection, storage, and search capabilities with recent acquisitions,” he added. “But most of the companies make that endpoint product, so becoming, all of the sudden, vendor agnostic is a bigger challenge that people can’t necessarily solve. It’s doable, but that’s a pretty big decision to go agnostic when you’re a player in that market.”

Additionally, customers increasingly store data in multiple data lakes and hyperscale cloud providers’ data stores and want a threat detection and response service that can access that data across disparate clouds and data lakes.

“I don’t know that SIEM will continue on forever as the security data lake for the customer, or will the approach be that, because it’s important to be able to access the data wherever it’s stored,” Geller said. “In which case, XDR or SIEM — whichever way you want to converge on the problem — evolves into something different.”