Databricks has unveiled Databricks Lakewatch, a new Security Information and Event Management (SIEM) system engineered to combat the escalating threat of AI-driven cyberattacks. This move marks a significant pivot in security operations, aiming to replace traditional SIEM limitations with an open, agentic approach.
Traditional SIEMs struggle with the sheer volume and variety of data generated by modern enterprises. Coupled with the increasing sophistication of AI-powered attacks, this architectural mismatch creates critical gaps in defense. Databricks asserts that Lakewatch addresses this by unifying 100% of an organization's telemetry on its open security lakehouse.
Fighting Fire with AI Agents
The core of Lakewatch's strategy lies in its use of embedded AI and specialized "Genie" agents. These agents are designed to automate threat detection, enable natural language-based threat hunting, and accelerate incident response at machine speed. This contrasts with legacy systems that often require manual analysis and slow, multi-day workflows.