
Why the SIEM market is poised for disaggregation
Recently, I was at the RSAC event in San Francisco and at the Data & Analytics Summit in Orlando. As I walked through the expo hall looking at the various vendors, I observed a few things.
- There is a surge in the number of data pipeline vendors feeding into SIEM (Security Information & Event Management) systems. This space is not new. Eight years ago or so, I practically sold such solutions to Oil & Gas companies that were dealing with a ton of telemetry data being ingested and getting stuck in Splunk, which was proving super expensive at the time. I couldn’t believe we are still trying to solve it with a hundred other tools like it.
- Data management vendors were now leveraging open source table formats such as Apache Iceberg to solve for cheap storage and easier access. This was digging into the territory of some of these SIEM tools as well.
- There is an ongoing tug-of-war between XDR (Extended Detection and Response) and SIEM tools in terms of overlapping messaging, capabilities, and market share.
- And there were quite a few product announcements in the news that made me want to write about this
Let’s start by saying that SIEM is not dying, but it is being pulled apart. The old idea of a single platform that ingests everything, stores everything, correlates everything, and drives every security workflow is losing economic and architectural credibility. SIEM remains relevant because security teams still need broad telemetry aggregation, investigation, and compliance reporting. But the stack around SIEM is being reallocated across XDR, data pipelines, data lakes, AI agents, and response platforms.
The origin of SIEM and its current state
The category began as the convergence of SIM (Security Information Management) and SEM (Security Event Management), a way to centralize security logs, correlate events, and support audit and compliance. For years, that model worked because the data estate was smaller, the attack surface was narrower, and most organizations were willing to pay a premium for centralized visibility. That model now strains under cloud scale, telemetry sprawl, and modern attack speed (maybe even with AI agents). Even Databricks, in its own security lakehouse blueprint, frames the pain points in familiar terms such as high ingestion costs, rigid schemas, and limited scalability.
This is why some pundits concluded that SIEM was dying. In reality, the market was revolting against legacy SIEM economics, not abandoning SIEM outcomes. Forrester’s 2025 market view is explicit that legacy SIEM vendors are now in a heated battle with surging XDR providers. That is a sign of category mutation, not category extinction. The value of detection, investigation, and long-term forensic visibility remains intact. The delivery model is what is being challenged.
XDR and SIEM are colliding, not replacing one another
XDR sits at the center of that challenge. It offers tighter native integration across endpoint, identity, network, and cloud signals, and it promises faster time-to-value than traditional SIEM deployments. Palo Alto’s XSIAM pitch is essentially that the future of SecOps is a consolidated operational platform that absorbs SIEM, SOAR (Security Orchestration, Automation, and Response), and XDR into one system. Microsoft is taking a different path by tying Sentinel more closely to its broader AI security platform. Splunk under Cisco is also pushing agentic AI into SecOps. So XDR is not killing SIEM. It is compressing the standalone SIEM layer and forcing it to coexist with platformized detection and response.
Consolidation is changing the market structure
Consolidation has accelerated this shift. Cisco’s $28 billion acquisition of Splunk was one of the clearest signals that security analytics, observability, and platform control now belong in larger strategic portfolios. Palo Alto’s acquisition of IBM’s QRadar SaaS assets showed how quickly legacy SIEM franchises can be folded into broader XDR-led architectures. The Exabeam and LogRhythm merger created a larger pureplay SecOps vendor with combined strength in analytics, AI, and trusted data ingestion. Put simply, the market is consolidating around platforms with stronger control over data, analytics, and workflow.
The current competitive field reflects that reality. Forrester’s 2025 security analytics evaluation included CrowdStrike, Elastic, Exabeam, Google, Microsoft, Palo Alto Networks, Rapid7, Securonix, Splunk, and Sumo Logic. That list itself is instructive. It mixes classic SIEM vendors, cloud security analytics vendors, and endpoint-led XDR players that are now extending upward into SIEM. The center of gravity has moved from log management to security analytics platforms.
The real challenge with traditional SIEM platforms
The hard truth is that traditional SIEM platforms created their own opening. Most security teams do not object to the concept of SIEM. They object to long onboarding cycles, custom parsing, high ingestion bills, and the operational drag of constantly deciding what data can be afforded. Databricks describes the pattern as costly legacy SIEM architectures that struggle with data silos and alert overload. Databahn describes the same problem from the pipeline side, arguing that the real challenge is collecting, normalizing, enriching, and routing modern telemetry across hybrid environments before it ever becomes useful in a SIEM.
Why data pipeline vendors matter more now
That is where data pipeline vendors become strategically important. They are increasingly becoming the control plane in front of SIEM. Vendors such as Cribl and Databahn do not need to replace SIEM to become influential. They can reduce cost, preprocess data, enrich signals, route high-value telemetry to the analytics tier, and send lower-value or long-retention data elsewhere. In effect, they separate data movement and data shaping from the SIEM itself. That is one of the clearest forms of disaggregation in the market.
Databahn takes on in-stream data intelligence
Databahn is a useful example because it is not just talking about pipeline efficiency in the abstract. Its March 11, 2026 announcement with Microsoft describes deeper integration with Sentinel, distribution through Content Hub and Marketplace, onboarding from more than 500 sources, and intelligent routing between Sentinel analytics tiers and lower cost retention options. Databahn’s differentiation is not that it wants to be the SIEM. Its value is that it wants to make the SIEM deploy faster, cost less, and ingest more selectively. That is exactly the kind of vendor that benefits when SIEM disaggregates.
What Databricks Lakewatch means to the space
Databricks Lakewatch raises the stakes by pushing the data platform one layer higher. Databricks announced Lakewatch last week as an open, agentic SIEM now in private preview. The company says it unifies security, IT, and business data in a governed environment, supports OCSF (Open Cybersecurity Schema Framework) plus Delta Lake and Apache Iceberg, decouples storage from compute, and adds agentic capabilities for log ingestion, detection creation, tuning, and investigation. That matters because Databricks is no longer just arguing for SIEM augmentation, but it is entering the SIEM conversation directly.
Why data vendors want to enter this market
Because security telemetry is one of the largest, fastest growing, and most economically attractive data workloads in the enterprise. Databricks has already been positioning cybersecurity as a data problem and promoting a lakehouse model that can offload expensive queries, retain more telemetry, and integrate with existing SIEM and SOAR tooling. Lakewatch suggests the company now believes the data layer can own more of the detection and investigation plane as well. The strategic logic is straightforward. Control the data, and over time, it becomes possible to control the analytics, the AI, and eventually the workflow.
What disaggregation means going forward
The likely outcome is not one winner taking the whole market. It is a division of labor. XDR and platform vendors will own high-speed operational detection and response for tightly integrated ecosystems. SIEM vendors will continue to own compliance, broad log search, and cross-domain investigation where analyst workflow maturity matters. Data pipeline vendors will own collection, normalization, routing, and cost control. Data platforms such as Databricks and Snowflake will try to own long retention, enrichment, advanced analytics, AI-driven hunting, and increasingly parts of detection engineering.
Key observations and predictions
As a way of closing this post, I would like to throw out three near-term observations –
- First, more SIEM value will move upstream into pipelines and downstream into data platforms.
- Second, AI will reward vendors that have the broadest, cleanest, and most governable telemetry foundation, not just the flashiest copilot.
- Third, the winning architectures will be modular. Buyers will increasingly prefer open schemas, decoupled storage and compute, and flexible integration over monolithic lock-in.
That is what disaggregation really means. SIEM is still here, but it is no longer the unquestioned center of the SOC universe.
