SIEMonster is built by professional hackers with 20 years experience in cyber security.
V5 auto deploys providing a SIEM with XDR endpoint protection, SOAR, Threat detection with SOC playbooks, and the ability to process unlimited event-per-second (EPS) ingestion that scales for any-sized business
SIEMonster V5 is the first AWS multi-region, multi-zone auto-deployed SIEM solution to provide you with built-in redundancy.
V5 Deploys in minutes and is ready to ingest all data in your business whether it's on-prem or in the cloud, including SCADA systems. SIEMonster can ingest anything and everything, to give you full protection under your control.
SIEMonster is multi-tenant out of the box so MSSPs can use it for their customer base and even white-label it with role-based access.
We created SIEMonster to disrupt and democratize the cyber security market.
Highlights
Affordable SIEM for every Business with XDR and SOAR capability.
Pricing is based on public rates. Contact sales at sales@siemonster.com for private offer pricing for your region
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay based on usage measured in host hours, tracked as Distinct Concurrent Node Use (HostHrs). This single dimension bills you for each node running at the same time, per hour. Pricing scales directly with how many servers you run. Adding servers as your load grows increases usage; scaling down reduces it. There are no separate editions or tiers to choose between. You get one product that scales from a single server to a global deployment, with billing tied to the servers you actually run.
Top-of-mind questions for buyers
What counts as one node for the HostHrs billing unit?
A node is one hosting server that runs the software. The platform meters each distinct server running at the same time, per hour. You pay per hosting server rather than per edition or per event. Each server you deploy adds to your concurrent node count for that hour.
Does the amount of data or events I ingest affect my bill?
No. Billing is measured only by concurrent host hours, not by events per second or data volume. There are no per-event ingestion charges. Your cost is driven by how many servers run at once, so ingesting more events on the same servers does not raise the software charge.
What happens to my cost when the platform auto-scales servers up or down?
The platform auto-scales servers as load grows and scales back when load falls. Each additional running server adds to your concurrent node count for the hours it runs. When servers scale down, your concurrent node count drops, reducing usage charges. Billing tracks the servers actually running each hour.
www.siemonster.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Quickstart deployment for SIEM cluster. Complete infrastructure rollout including ACM managed certicates, volumes encrypted at rest & DNS.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
All new Incident Reponse module
EKS Update
IDS Update
For support packages, click on the contact form and select Support.
Please note, the product has external dependencies to Lambda functions maintained in Amazon S3 storage buckets for the purposes of deployment and additional tenant provisioning.
Customers should consider deploying into new AWS accounts because the permissions allow the application to create administrative roles, users, or groups.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Auto-deployed SIEM solution with multi-region, multi-zone architecture providing built-in redundancy
Endpoint Detection and Response
XDR endpoint protection integrated with threat detection capabilities and SOC playbooks
Security Orchestration and Automation
SOAR functionality for automated incident response and threat management
Event Processing Scalability
Unlimited event-per-second (EPS) ingestion capacity with infinitely scalable architecture
Multi-Tenant Architecture
Multi-tenant infrastructure supporting role-based access control for managed service providers and white-label deployment
Security Information and Event Management
Real-time monitoring and visibility for threat detection including ransomware, insider threats, and cloud attacks with security analytics for rapid investigation and prioritization of critical threats.
Incident Response Automation and Orchestration
Automation and orchestration of incident response workflows with consistent, optimized, and measurable process execution.
Enterprise-Grade AI and Automation
Embedded artificial intelligence and automation capabilities designed to increase analyst productivity and accelerate incident lifecycle management.
Multi-Source Data Correlation
Correlation of data across users, networks, and cloud-native services to identify threats including cloud misconfigurations, policy changes, and suspicious user activity with alert deduplication.
Hybrid and Cloud Environment Integration
Centralized visibility across hybrid cloud and on-premises environments with deep integrations to AWS security services including Security Hub, CloudTrail, GuardDuty, Network Firewall, WAF, Detective, CloudWatch, and VPC Flow Logs.
Threat Detection Engine
Library of 900+ out-of-the-box detections with user and attacker behavior analytics backed by community threat intelligence
Data Ingestion and Integration
Ingests CloudTrail, GuardDuty, EC2 network traffic, raw logs via SQS from multiple AWS accounts, on-premises networks, remote endpoints, and SaaS solutions
Investigation and Response Capabilities
Visual investigation timeline with detailed log timelines, automated response workflows, and instant actions such as asset quarantining
Deception Technology
Honeypots, honey credentials, and honey files for layered defense mechanisms
Compliance and Monitoring
File Integrity Monitoring (FIM) with support for PCI, HIPAA, and GDPR compliance requirements, plus detection of new AWS regions, services, and EC2 instance types
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.