Why Hasn’t the Buyout Begun?
So I got a question for everyone. Why hasn’t the SIM or log analysis market consolidated?
The SIM market is about 5 years old now. There are many players in this field, both pure SIM players and players expanding into the SIM space.
Some of the pure players include
- ArcSight
- netForensics
- Open Service
- e-Security
- GuardedNet
- Network Intelligence
- TriGeo
- Protego
- LogLogic
- Consul Risk Management
- High Tower Software
- SenSage
Other non-pure players that are either getting into or already in the SIM space include
- Aelita (acquired by Quest Software)
- Symantec (acquired Riptech, Mountain Wave and Recourse)
- MicroMuse
- Computer Associates eTrust
I was expecting the wave of buyouts to begin when Symantec acquired the 3 companies, but nothing has happened.
I can think of a couple reasons
- SIM vendors haven’t proved their value. There’s a lot of good technologies out there, but most of them are very high priced. I think the SIM vendors have a tough time justifying the ROI.
- Most SIM vendors have gotten several rounds of funding now, probably anywhere from $15 to $60 million. Most companies don’t want to spend a whole lot of money buying these vendors. Symantec bought Mountain Wave for $20 million, Riptech for $145 million and Recourse for $135. Both Riptech and Recourse brought more than just log analysis products.
What do you think? I would love to hear your thoughts on this issue.
The issue with this market is that a lot of customers are willing to accept “good enough” solutions, including many home-grown scripts and systems. So while the various technologies provide clear value, there is a tendency to either 1. demand of individual security vendors to provide a full log analysis system 2. write a lot of perl scripts by hand to get the job done. Between #1 and #2, it is difficult to develop a vibrant market with clear winners.
This is very true. Most of the customers we encountered had home grown solutions. The problem is that a lot of times the cost of maintaining the software as well as adding features (once you have something, people’s gonna want more) becomes very expensive.
Wrt to #1, can you elaborate on “full log analysis system” mean?