We operate detection on several platforms, our own included, and the honest position is that the choice matters less than most procurement processes assume. What matters is the operating model around it, and that is rarely what the evaluation measures.
If you are comparing platforms this quarter, here are the questions we would ask, in the order we would ask them.
What does a bad month cost
Almost every platform prices on data volume in some form, and almost every estimate is built from a normal month. Normal months are not the problem.
Ask the vendor to price the month in which you onboard endpoint telemetry from a newly acquired subsidiary, and a noisy application starts logging at debug level, and you retain everything because an incident is under investigation. Then ask what happens when you hit the ceiling: does ingestion stop, does it queue, or does it bill.
We have seen organisations quietly reduce their logging to control spend, which converts a budget problem into a detection gap, which nobody notices until it matters. If a platform's pricing makes you nervous about collecting a log source, it is the wrong platform for you regardless of its detection quality.
Who tunes it in month four
Every platform demos well because the demo environment is tuned. Yours will not be tuned, and detection content decays: your applications change, your estate changes, attacker technique changes.
So the real question is not "how good are the out of the box rules". It is "whose job is it to write rule 431 in November, and are they on your payroll".
If the answer is your team, budget for the headcount honestly. A platform is roughly a full time detection engineer once it is past the first quarter, and organisations that do not staff that end up with an expensive alert forwarder.
If the answer is a managed provider, ask to see the last three detections they wrote for a client in your sector, redacted. Vendors who cannot produce this are selling you a console.
Can you get your data back out
Detection content, enrichment and historical data are all places where switching cost accumulates deliberately. Ask what an export looks like in year three: what format, what does it cost, and does it include the detection logic you wrote or only the events.
This is not a hypothetical concern. Platform consolidation in this market has moved several products under new ownership with new pricing, and the organisations that suffered were the ones with three years of custom content and no export path.
Does it produce evidence an auditor accepts
For an Indian regulated entity this is not a secondary consideration. You need 180 days of logs retained in India under the CERT-In Directions, and if you are under RBI or SEBI supervision you will be asked to demonstrate detection coverage against specific scenarios rather than in the abstract.
Ask where data is stored, in which region, and what the retention actually costs at 180 days rather than at 30. Several platforms are priced attractively at short retention and painfully at the retention you are legally required to hold.
Then ask whether you can produce, on demand, the alert history for a named system across a named period, in a form somebody outside the SOC can read. That is the evidence request that arrives during an inspection.
What we would actually tell you
If you have a mature security team and unusual requirements, the flexibility of a general purpose platform will pay for itself. You will spend the engineering time either way, so spend it somewhere you control the outcome.
If you have a small team and a regulator, buy detection as an outcome rather than a platform as a capability, and hold the provider to detection content you can inspect. The failure mode here is a provider who forwards alerts and calls it managed detection, so put the content review in the contract.
If your estate is largely on one cloud, the native tooling is usually cheaper and better integrated than the market gives it credit for, and the integration tax on a third party tool is real.
None of that is a recommendation of a product, because the right answer genuinely depends on the shape of your team. Any consultant who reaches a product recommendation before asking who tunes it in month four is selling something.












