Databricks Just Bought Its Way Into the SIEM War

Kamal Shah
Kamal Shah
June 17, 2026

Databricks just fired another shot at the SIEM market — this time with an acquisition.

In March, Databricks launched Lakewatch at RSA — their own agentic SIEM built on their data platform. The Data Intelligence Platform is world-class. 

But to compete with Cisco Splunk, CrowdStrike Falcon Next-Gen SIEM, Microsoft Sentinel, Google SecOps, Palo Alto Networks Cortex XSIAM, Elastic SIEM, Datadog Cloud SIEM, SentinelOne Singularity AI SIEM, and Sumo Logic Cloud SIEM, you need more than infrastructure — you need connectors to ingest security data from hundreds of sources and detection rules to find threats in it. Building that from scratch takes years. 

Acquiring Panther, which already has 100+ pre-built integrations and popularized detection-as-code, significantly accelerates that timeline. Panther recently expanded into Agentic SOC capabilities as well, giving Databricks an advantage over SIEM vendors who have not innovated as much in this area. 

This acquisition raises a few questions:

  1. What was the acquisition price?  Panther's last valuation was $1.4B. Did they pay that, more, or less? The terms weren't disclosed, and that number will tell you a lot about how competitive the process was.
  2. How will the incumbent SIEM vendors respond? Every SIEM vendor mentioned above just watched a $134B data and AI company enter their market with an acquisition that signals they're serious. 
  3. How will Databricks’ fiercest competitor Snowflake respond? They have the same data platform advantages Databricks does. They've been watching this play out. Does this force their hand?
  4. And what about Cribl, the data pipeline company with greater data management ambition? They were listed as a Lakewatch ecosystem partner at launch, but they also have Cribl Lake — their own cloud-native data lake for security data. Databricks and Cribl are now competing for the same data layer, while technically still partners. That's an uncomfortable position to be in.

One thing is clear: this accelerates the SIEM disruption that's been building for years. The category is not going to look the same in 24 months.

{{ebook-cta}}

70% of SOCs will pilot AI Agents. Only 15% will see results

This Gartner research arms security operations leaders with a list of specific questions to ask vendors during evaluation

Download Gartner Report
Download Ebook
70% of SOCs will pilot AI Agents. Only 15% will see results

Frequently Asked Questions

News
Exit icon