- Best for
- SMB and mid-market teams that want managed SIEM and SOC coverage without building their own SIEM program
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
Your team still owns
- Choosing which endpoints, cloud services, identity systems, network tools and SaaS sources are in scope
- Approving response authority, escalation paths and the incident-response plan
- Completing business remediation, recovery and user communication after confirmed incidents
- Buying or managing optional endpoint security, vulnerability management, incident support and extended retention
- Tracking any roadmap, support or migration changes after Lumifi's acquisition of Netsurion
Pricing
| Line | Figure |
|---|---|
| Published price | Quote-based, with pay-as-you-grow packaging referenced for MSP buyers |
| Billing model | Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Co-managed model fits buyers that want SOC help while keeping visibility into the security operations platform
- Managed SIEM and log retention make it useful for compliance-driven buyers that need more than endpoint MDR
- MSP-oriented packaging, multi-tenant management and pay-as-you-grow language are clearer than many enterprise-only SOC providers
- Public integration material gives buyers a concrete way to check whether their stack can feed the platform
Watch out for
- Public pricing is quote-based, with no current numeric list price for Managed Open XDR
- Response ownership is not the same as full provider-owned containment or DFIR
- Feature depth depends on Essentials, Enterprise and optional modules, so package comparison matters
- Review history includes useful service feedback but many detailed reviews are older EventTracker-era reviews
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Customers like
- Reviews mention managed SIEM support, useful reports and alert tuning that gives internal teams time back
- MSP and mid-market users call out co-managed SIEM as a practical way to add SOC coverage
- Reddit discussion often places EventTracker or Netsurion among MSP-oriented managed SIEM options
Watch out for
- Some reviewers describe setup, search or dashboard work as less simple than expected
- Older G2 reviews include communication and public-cloud service-model caveats
- Reddit evidence is mostly shortlisting and category discussion, not detailed current Netsurion customer experience
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which Open XDR package are we buying, and which data-source integrations are included versus optional?
- Which automated response actions can the platform take, and which remediation steps only come as SOC guidance?
- Will support, renewal and roadmap ownership sit with Netsurion, Lumifi, an MSP or another channel partner?
Integrations
Editorial notes
Why co-managed SOC
Netsurion's public material describes Managed Open XDR as a co-managed service with Open XDR, managed SIEM, workflow automation, 24/7 monitoring, threat hunting, tuning, training and customer success. That is broader than alert forwarding but still leaves incident-response authority and business remediation with the buyer or MSP.
Response boundary
Official material supports automated response by Open XDR and guided remediation by the 24/7 SOC. It also says successful incident response centers on the customer and that partners may be enlisted for hands-on DFIR, so the profile should not imply Netsurion owns every containment or recovery step.
Package boundary
The 2024 solution brief separates Essentials and Enterprise features. Threat hunting, full compliance reports, full data-source integrations, data-source tuning, implementation project management, incident and audit support and extended retention can vary by package or option.
Pricing boundary
Netsurion references pay-as-you-grow pricing for service-provider buyers but does not publish current Managed Open XDR list pricing. Old EventTracker Log Manager prices are legacy product signals and are not used as current public pricing.
Ownership change
Lumifi acquired Netsurion on May 21, 2024 and said the acquisition added more than 400 Netsurion clients. Buyers should ask how Lumifi's SOC, SHIELDVision platform, support model and roadmap affect Netsurion Open XDR customers.