/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Databricks launches Lakewatch, a security information and event management service, and announces acquisitions of security startups Antimatter and SiftD

Databricks has grown from startup into major software company, generating billions by processing data and running generative artificial intelligence models for clients.

CNBC Jordan Novet

Context & Ripple Effects

Databricks had been extending its data-and-AI platform into user-facing analytics and natural-language data access, including AI/BI chart-building tools and LakehouseIQ's natural-language querying. Adding security operations broadens the set of workloads customers can keep around the same data foundation.

The move also begins a security acquisition thread that later included an agreement to acquire Panther Labs as a third cybersecurity deal. That makes this more than a standalone product launch: it is an early step toward building security capabilities through both product development and M&A.

First-order effects

  • Databricks gains a SIEM offering and the teams and technology of Antimatter and SiftD, giving its existing customers a security-operations product alongside data and AI workloads.
  • Antimatter and SiftD are absorbed into Databricks' platform strategy, while Lakewatch users can evaluate security monitoring within the vendor they already use for data processing and AI.

Second-order effects

  • SIEM vendors competing for customers that centralize data and AI work on Databricks face a more integrated alternative, particularly where customers value using the same data environment for analysis and security workflows.
  • The acquisitions make security technology a more direct build-versus-buy consideration for data-platform providers, as product breadth increasingly depends on specialized security capabilities.

Third-order effects

  • If Databricks continues to add security products and acquisitions, the data platform could evolve into a broader operational control layer rather than remain primarily an analytics and AI environment.
  • The pattern points to AI-data vendors competing through platform consolidation: security may become a core adjacent workload, though adoption will depend on whether customers prefer integrated tooling over specialist SIEM products.

The trend: Data and AI platforms are expanding into security operations as they seek to consolidate more enterprise workflows around a common data layer.

Discussion

  • @jaminball Jamin Ball on x
    Databricks: The “Spark” company The “Lakehouse” company The “Data and AI” company The “Agentic AI” company Awesome pace of innovation
  • @databricks @databricks on x
    Today we're announcing Lakewatch — a new open, agentic SIEM. Security has changed. Attackers now use agents, operating 24/7 at machine scale, while legacy security tools were built for human-speed threats. We need tools where agents work alongside humans to keep up. Lakewatch [im…
  • @nikitabase Nikita on x
    This is a big deal. Any proprietary data management system (in this case Splunk) will be inferior to the Databricks open platform