Databricks and Panther Are Now One Platform
Databricks completed the acquisition of Panther on August 3, 2026. Panther is an AI Security Operations Center (SOC) platform. A SOC is the team and tooling that detects threats and responds to incidents. The deal brings Panther's capabilities directly into Lakewatch, Databricks' own agentic SIEM product. SIEM stands for Security Information and Event Management. It is the system security teams use to collect logs, find threats, and triage alerts.
Lakewatch is built on an open lakehouse foundation.
This is not a parallel-track product strategy. Databricks is positioning the combined platform as a direct replacement for traditional SIEM tools.
Why Legacy SIEM Is the Target
Legacy SIEM was built for smaller data volumes and slower threats. Today, those systems force a hard choice. Ingest all logs and absorb escalating SIEM costs and noisy output. Or ingest less and accept coverage gaps.
When alerts do trigger, analysts jump between disconnected tools. They manually stitch together cloud logs, identity data, and endpoint signals.
The cost structure makes this worse. Proprietary SIEM vendors build their business models on proprietary data formats and steep ingestion penalties. Security teams respond by dropping logs. Dropped logs create blind spots. Those blind spots matter most in complex, multi-stage attacks across cloud, identity, and SaaS environments. Early attacker moves can go undetected.
Databricks argues its lakehouse model breaks that pattern. Lakewatch lets organizations retain petabytes of telemetry in open formats without the ingestion costs that make legacy SIEM expensive to run at full fidelity.
What Panther Actually Adds
Lakewatch provides the data foundation. Panther provides the operational layer on top.
The most significant capability Panther brings is detections-as-code. Instead of managing rules through a proprietary graphical interface, security engineers write, test, version-control, and deploy detection logic through standard CI/CD pipelines. CI/CD stands for continuous integration and continuous delivery. It is the same automated build-and-release workflow that software teams use for application code. It brings auditability and repeatability that point-and-click rule management typically lacks.
Panther also adds more than 100 out-of-the-box integrations. The connectors cover AWS, Microsoft Azure, and Google Cloud for infrastructure. They cover Okta and Microsoft Entra ID for identity. SaaS applications and endpoints are included too. That breadth matters. A team evaluating a SIEM replacement must confirm the new platform covers every log source the current one does. Gaps create detection regressions.
On the AI side, autonomous triage agents enrich alerts in real time before an analyst opens a ticket. The agents correlate cloud logs, identity signals, and business context already in the lakehouse. That includes HR records and asset inventories. The goal is fewer alert floods and faster time to actionable context.
The underlying data standards are OCSF, Spark, Unity Catalog, Delta, Parquet, and SQL. Open Cybersecurity Schema Framework (OCSF) is a vendor-neutral log format. It enables normalized correlation across diverse data sources. Unity Catalog is Databricks' governance layer. It handles access control, auditing, and data lineage. Both matter for organizations that need data sovereignty and want to avoid format lock-in.
The Architecture Decision This Forces
For data platform owners already running Databricks, this acquisition changes the security conversation. Security telemetry, IT operations data, and business data can now live in the same governed environment. Teams analyze everything with the same tooling and the same access controls. Unity Catalog governs the entire security estate with unified access control, auditing, and data lineage across all security telemetry.
That unified context is the central claim. A SOC analyst investigating an anomalous login can correlate it against HR offboarding records, asset inventory, and cloud activity logs. No platform switch. No waiting for another team to pull data from a separate system.
For organizations not yet on Databricks, the decision carries more weight. Adopting Lakewatch and Panther means adopting the Databricks Data and AI platform as the foundation for security operations. That is not a lightweight integration decision.
What Data and Security Teams Should Do Now
Three questions are worth answering before this becomes a budget conversation.
First, where does your current SIEM data live, and in what format? Proprietary data formats and steep ingestion penalties are the structural problem Databricks is targeting. If your current vendor locks telemetry in a proprietary schema, moving to an open-format lakehouse requires a data pipeline redesign. That is not a simple tool swap.
Second, does Panther's connector library cover your current log sources? The 100-plus integrations cover major cloud providers, identity systems, and SaaS platforms. Teams with unusual on-premises sources, operational technology environments, or specialized endpoint tools should map their inventory against the connector list before assuming full coverage.
Third, is your organization ready to operate detections-as-code? The CI/CD approach is more rigorous than UI-based rule management. But it requires security engineers comfortable with version control and deployment automation. Teams that rely on point-and-click rule changes should assess the skills gap alongside the technology gap.
Databricks has not published pricing for the combined platform. Any business case will need cost figures from a direct vendor conversation. The key comparison is your current SIEM ingestion costs versus Lakewatch's cloud-scale storage economics at your actual data volumes.

