How Netgraph compares — by category, not by brochure
Across the three dominant categories of incumbent platforms — legacy enterprise SIEM, hyperscaler-bundled XDR, and AI-SOC overlays — each covers a slice. Netgraph covers the stack on one graph, with open data, at SMB-feasible compute. Specific vendor names are omitted by design — use the evaluation checklist below to test any named candidate, including us, against your own environment.
| Capability | Netgraph | Legacy enterprise SIEM | Hyperscaler-bundled XDR | AI-SOC overlay |
|---|---|---|---|---|
| Native security knowledge graph | Yes — substrate | No | Partial | No |
| SIEM + XDR + NDR + SOAR unified | Yes | Bolted-on | Partial | No |
| CNAPP · DSPM · VM native | Yes | No | Partial | No |
| Detection-as-Code with BAS gate | Yes | No | No | No |
| Open columnar & telemetry formats | Yes | Proprietary | Proprietary | N/A |
| Air-gapped deployment | Yes | Partial | No | No |
| DPDP · CERT-In · RBI built-in | First-class | Add-on | Add-on | No |
| SMB compute footprint (32 vCPU) | Yes | No | Cloud-only | Cloud-only |
| Made in India · India-resident ops | Yes | No | No | No |
The three incumbent categories
What each category does well — and where it stops
Legacy enterprise SIEM (+ bolted-on SOAR)
Strengths: Mature detection content, broad log-source support, familiar to auditors.
Trade-offs: Ingest-priced economics punish full-fidelity telemetry; SOAR, UEBA, and TIP are acquisitions stitched via dashboards; proprietary storage formats make leaving expensive; India-specific statutory clocks (CERT-In 6-hour, DPDP 72-hour) are custom work.
Hyperscaler-bundled XDR / cloud-native SIEM
Strengths: Excellent coverage of that hyperscaler's own estate; fast setup if you are single-cloud.
Trade-offs: Cross-cloud and on-prem telemetry are second-class; data residency follows the hyperscaler's regions and terms; air-gapped deployment is generally impossible; costs scale with the same cloud bill you're trying to control.
AI-SOC overlay
Strengths: Genuinely reduces triage toil on top of an existing stack; quick pilot.
Trade-offs: It investigates alerts on someone else's data plane — it cannot fix detection gaps, storage costs, or coverage holes underneath; adds a vendor rather than consolidating any; answer quality is bounded by the context the underlying tools expose.
Run this against every candidate — including us
The six-point SIEM evaluation checklist
- 1
Run the same 30 days of your real telemetry through each candidate and compare detection counts, false-positive rates, and query latency — not demo data.
- 2
Price the full retention story: hot, warm, and cold tiers at your actual EPS, including the cost to re-query year-old data during an incident.
- 3
Test the exit: export a day of data and confirm you can query it with tooling you don't license from the vendor.
- 4
Time the statutory workflow: from detection to a CERT-In-ready 6-hour report and a DPDP 72-hour notification draft.
- 5
Validate AI claims with a closed loop: does an investigation produce a drafted detection, and can the platform prove that detection fires (BAS) and would have fired historically (retro replay)?
- 6
Check the compute floor: what does the vendor's minimum viable deployment cost to run for a 500-2,000-employee organisation?
Comparison questions
Asked in every evaluation
Why doesn't this comparison name specific vendors?+
Because capabilities within each category are more stable than any single vendor's feature list, and because we would rather you verify claims against your own environment than argue about a competitor's brochure. The categories — legacy enterprise SIEM, hyperscaler-bundled XDR, and AI-SOC overlays — cover the platforms Indian security teams actually shortlist. Run the evaluation checklist above against named candidates yourself; it is designed to be vendor-fair.
How should I compare SIEM total cost of ownership (TCO)?+
Include four lines that vendor quotes usually hide: ingest/retention growth over three years at your real EPS; the point tools the platform does NOT replace (UEBA, TIP, SOAR, BAS licences); engineering time spent stitching and maintaining integrations; and exit cost — what re-platforming from proprietary storage would take. Netgraph's claim of ≤ 15% of legacy ingest cost at equivalent retention is specifically about the first line, and consolidation addresses the second.
Is a graph-native SIEM worth the migration effort?+
If your analysts spend most of an investigation pivoting between consoles and joining CSVs, yes — that pivot time is exactly what a shared knowledge graph removes. Migration risk is bounded by open formats: Netgraph ingests via OCSF/ECS and can run in parallel with an incumbent during evaluation, so you compare like-for-like before committing.
What about sovereignty requirements — RBI, SEBI, IRDAI, government?+
Regulated Indian entities increasingly need India-resident processing, auditable data planes, and sometimes air-gapped deployment. Hyperscaler-bundled options fail the air-gap test structurally; legacy SIEMs treat Indian statutory clocks as custom work. Netgraph is Made in India end-to-end, GeM-listed, air-gap-deployable, and ships CERT-In/DPDP/RBI evidence workflows as first-class features.
Test us against the checklist