{"id":208548,"date":"2026-03-25T12:21:24","date_gmt":"2026-03-25T11:21:24","guid":{"rendered":"https:\/\/liora.io\/en\/databricks-lakewatch-disrupts-siem"},"modified":"2026-03-25T12:21:24","modified_gmt":"2026-03-25T11:21:24","slug":"databricks-lakewatch-disrupts-siem","status":"publish","type":"post","link":"https:\/\/liora.io\/en\/databricks-lakewatch-disrupts-siem","title":{"rendered":"Databricks Lakewatch disrupts SIEM with open agentic platform"},"content":{"rendered":"<p><strong>\nDatabricks announced its entry into the cybersecurity market on March 24, 2026, launching Lakewatch, an AI-powered security platform that promises to slash costs by up to 80% compared to traditional systems. The new platform uses <a href=\"https:\/\/liora.io\/en\/all-about-ai-agents\">autonomous AI agents<\/a> to automate threat detection and response while storing data in customers&#8217; own cloud environments, directly challenging market leaders Splunk and Microsoft Sentinel.\n<\/strong><\/p>\n<p>The platform represents what <b>Databricks<\/b> calls an &#8220;agentic SIEM,&#8221; where AI agents serve as primary actors in automating security workflows to match the velocity of modern cyberattacks, according to the company&#8217;s blog post. Unlike traditional systems that depend on human-written rules, <b>Lakewatch<\/b> employs <a href=\"https:\/\/liora.io\/en\/all-about-ai-and-cybersecurity\">AI to continuously analyze data, detect threats<\/a>, triage alerts, and initiate threat hunting.<\/p><br><p>A key feature named <b>&#8220;Genie&#8221;<\/b> automates complex tasks including parsing new log sources into the Open Cybersecurity Schema Framework, authoring detection rules from threat intelligence, and translating natural language queries into SQL for threat hunting, Databricks stated in its announcement.<\/p>\n\n<h2 style=\"margin-top:2rem;margin-bottom:1rem;\">Strategic Acquisitions and Early Adopters<\/h2>\n\n<p>To accelerate its market entry, Databricks acquired security research firm <b>Antimatter<\/b> and <b>SiftD.ai<\/b>, founded by the creator of Splunk&#8217;s Search Processing Language, signaling direct intent to attract talent and customers from the market leader, according to the company&#8217;s press release.<\/p><br><p>The platform launched in Private Preview with early customers including <b>Adobe<\/b>, <b>Dropbox<\/b>, and <b>National Australia Bank<\/b>, Databricks announced. The pricing model bases costs on compute consumption rather than data ingestion volume, a key differentiator designed to attract large enterprises struggling with legacy SIEM costs, DigitalToday reported.<\/p>\n\n<h2 style=\"margin-top:2rem;margin-bottom:1rem;\">Technical Architecture and Partner Ecosystem<\/h2><figure class=\"wp-block-image size-large\" style=\"margin-top:var(--wp--preset--spacing--columns);margin-bottom:var(--wp--preset--spacing--columns)\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"572\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-1024x572.jpg\" alt=\"Screenshot of a SQL editor displaying code and tables on a computer monitor, showcasing Databricks Lakewatch functionality.\" class=\"wp-image-208542\" srcset=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-56x56.jpg 56w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-115x64.jpg 115w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-150x150.jpg 150w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-210x117.jpg 210w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-300x167.jpg 300w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-410x270.jpg 410w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-440x246.jpg 440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-448x448.jpg 448w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-587x510.jpg 587w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-768x429.jpg 768w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-785x438.jpg 785w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-1024x572.jpg 1024w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-1250x590.jpg 1250w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-1440x680.jpg 1440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-1536x857.jpg 1536w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-2048x1143.jpg 2048w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/sql-editor-databricks-lakewatch-scaled.jpg 2560w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><\/figure>\n\n<p>Lakewatch employs a decoupled architecture built on the <a href=\"https:\/\/liora.io\/en\/databricks-on-gcp-a-powerful-synergy\">Databricks Lakehouse Platform<\/a>, where storage and compute operate separately. Data resides in open formats like <b>Delta Lake<\/b> within customers&#8217; own cloud storage, governed by Unity Catalog, eliminating vendor lock-in, the company explained.<\/p><br><p>The platform integrates with an &#8220;Open Security Lakehouse Ecosystem&#8221; including partners <b>Cribl<\/b>, <b>Zscaler<\/b>, <b>Okta<\/b>, <b>Palo Alto Networks<\/b>, and <b>Wiz<\/b> to streamline data ingestion, Databricks announced. Through Delta Sharing, an open protocol for sharing live data without replication, partners like Obsidian Security can feed normalized telemetry directly into customers&#8217; Lakewatch environments, eliminating ingestion overhead, according to Obsidian Security&#8217;s blog post.<\/p><br><p>The system analyzes all forms of security telemetry, including multi-modal data such as chat logs, video, and audio, which are often sources of social engineering and insider threats missed by traditional systems, Databricks stated on its product page.<\/p>\n<div style=\"margin-top:3rem;padding-top:1.5rem;border-top:1px solid #e2e4ea;\">\n  <h3 style=\"margin:0 0 0.75rem;font-size:1.1rem;letter-spacing:0.08em;text-transform:uppercase;\">\n    Sources\n  <\/h3>\n  <ul style=\"margin:0;padding-left:1.2rem;list-style:disc;\">\n    <li>databricks.com\/company\/newsroom<\/li><li>digitaltoday.co.kr<\/li><li>obsidiansecurity.com\/blog<\/li>\n  <\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Databricks announced its entry into the cybersecurity market on March 24, 2026, launching Lakewatch, an AI-powered security platform that promises to slash costs by up to 80% compared to traditional systems. The new platform uses autonomous AI agents to automate threat detection and response while storing data in customers&#8217; own cloud environments, directly challenging market leaders Splunk and Microsoft Sentinel.<\/p>\n","protected":false},"author":87,"featured_media":208543,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[2417],"class_list":["post-208548","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/users\/87"}],"replies":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/comments?post=208548"}],"version-history":[{"count":0,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208548\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media\/208543"}],"wp:attachment":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media?parent=208548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/categories?post=208548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}