Security operations
The SIEM evaluation checklist: criteria that survive a demo.
Every SIEM (security information and event management) platform demos well — the dashboards are built for it. Evaluations go wrong on the criteria a demo never shows: how the ingest pricing behaves in year two, whether correlation reaches beyond logs, what 180-day retention really does to storage, how deep the response integration goes, and what leaves with you if you exit. This checklist covers the criteria that separate platforms once the demo is over, written for Indian estates where CERT-In obligations shape the retention maths.
Why SIEM evaluations go wrong
Most evaluations are demo-led: vendors drive, dashboards impress, and the shortlist orders itself by interface polish. But the expensive differences between platforms live elsewhere — in the pricing meter, the correlation engine, the retention tiers and the exit terms — and none of those appear on a screen-share. The fix is to walk in with written criteria and score against them, so the demo answers your questions instead of setting them.
1. The ingest pricing model
Ask what the meter is — per gigabyte ingested, per event per second, per device, per user — and then model it against your estate growing for three years. Meters behave differently under growth: device-based pricing survives a logging-verbosity change, per-GB pricing does not. Ask what happens to data you ingest but never query, whether re-indexing old data bills twice, and which log sources the vendor quietly recommends excluding — that last list is where surprise invoices are born.
2. Correlation depth, not rule count
A rule library number tells you little; ask instead what the engine can join. Cross-domain correlation — the same identity seen across endpoint, network, cloud and physical systems in one timeline — is what turns four routine events into one incident. Ask how many of the shipped detections would actually arm on your estate, how tuning works, and who does it. A platform that correlates only what one agent family produces is a narrower product than its rule count suggests.
3. Retention economics and CERT-In reality
For Indian estates the retention floor is not a preference: CERT-In directions require rolling 180-day retention of ICT system logs, and the direction's text places them within Indian jurisdiction — with a CERT-In FAQ qualification on offshore copies that is worth reading before you architect storage abroad. Six months of every log source is a storage bill, so ask how the platform tiers it — hot searchable storage against cold archive — what a search across the full 180 days costs in time and money, and where the data physically resides. A platform that treats long retention as an afterthought will make compliance the most expensive query you run.
4. Response integration depth
If detection ends at an alert email, analysts still do everything else by hand. Ask whether response is native or a separately licensed product, which containment actions exist against your actual stack, and how authority is governed — per-action policies for unattended, approval-required and advisory modes, with a run history you can audit. A bolted-on response module with three connectors is a different proposition from response designed into the platform.
5. Multi-tenancy and access control
Group companies, subsidiaries and multi-site estates need boundaries inside the platform: who sees which entity, which detections apply where, and whether reporting can be cut per business unit. Role-based access that only distinguishes admin from viewer will not carry a real organisation. If a provider will operate the platform for you, ask how their analysts are segmented from your data and what of their activity you can see.
6. The operating question
A SIEM is not an appliance; it is a commitment to tuning, triage and rule maintenance for as long as it runs. Evaluate the platform and the operating model together: who watches it at 3am, who owns detection quality, and what happens to alert volume in month six when the novelty has worn off. If the honest answer is that nobody has those hours, the evaluation should widen from tools to services — a different comparison with different criteria.
7. Exit and data portability
Decide the divorce terms before the wedding. What exports, in what format, at what cost, and how long does history remain accessible after termination? Detection content you wrote, dashboards you built, the case history your auditors may want — ask which of those leave with you. Provider-owned platforms concentrate this question rather than remove it: the convenience of one integrated system is real, and so is the gravity it exerts at renewal time.
Where PrahiX sits
PrahiX answers this checklist from the integrated end of the market: correlation and response run on one platform under one subscription, network and device telemetry feed the same timeline as security logs, and there is no separate SIEM licence inside the price — with ingest from an existing SIEM supported where a licence still has years to run. That model suits estates consolidating tools; it is not automatically right for teams invested in a best-of-breed stack. Either way, the exit question in section 7 applies to us as it does to anyone — ask it.
Have Questions? We've Got Answers.
Seven things a demo will not show: the ingest pricing model under three years of growth, correlation depth across domains, retention economics against your compliance floor, response integration and its governance, multi-tenancy and access control, the operating commitment, and exit terms with data portability.
Feed the POC your real log sources, not samples; count which shipped detections actually arm; measure query time across your intended retention window; run one containment action end to end under an approval policy; and get the year-two price of the POC estate in writing.
Long enough to see noise, not just novelty — typically three to six weeks with real data flowing. The first week shows integration effort, the middle weeks show alert quality, and the final stretch shows whether tuning moved the numbers or just moved the thresholds.
CERT-In directions require ICT system logs to be maintained on a rolling basis for 180 days, with the direction placing them within Indian jurisdiction (CERT-In's FAQs qualify the offshore question — check the current text). For a SIEM evaluation that sets the storage baseline: six months of every in-scope source, searchable when an incident or an auditor requires it.
Yes, with the same checklist — open source changes where the money goes, not whether it goes. Licence savings shift into engineering time for integration, tuning, scaling and upgrades, so the operating question in section 6 becomes the decisive criterion rather than one of seven.
Keep reading
Score the checklist against a live platform
A proof of concept on your own telemetry answers the criteria a demo cannot — ingest behaviour, correlation reach, retention maths and governed response, measured on your estate.