The market of SIEM is in an inflection point. Enterprises are drowning in security telemetry they cannot afford to store, fighting AI-powered attackers with manual workflows, and losing visibility at the exact moment they need it most. Over the years, security operations teams have been left with an impossible decision to make: pay crippling ingestion fees to store all their data, or to log less and accept dangerous blind spots. Databricks has already joined this market with Lakewatch – an agentic SIEM powered by the Databricks Lakehouse designed to redefine the economics and capabilities of enterprise security operations.
What Is a SIEM — and Why Is It Breaking?
Why Databricks Is Entering Security
Lakewatch: The Open, Agentic SIEM
Key capabilities
- Agent Bricks — Custom AI security agents that autonomously triage telemetry across hundreds of log formats, dramatically reducing mean time to detect (MTTD) and mean time to respond (MTTR). Analysts direct strategy; agents handle the volume.
- Genie AI — Natural language threat hunting across petabytes of data. Analysts can query years of security history in plain English, and Genie automates detection authoring, false-positive tuning, and SQL translation.
- Detection-as-Code — YAML and Python rules managed in Git and deployed via CI/CD pipelines, bringing the rigor of DevOps to the Security Operations Center.
- Anthropic Claude Integration — Advanced reasoning for signal correlation across security, IT, and business data, powering threat triage and executive-ready reporting at machine speed.
- Unity Catalog — Fine-grained access control at the table, row, and column level, with full audit lineage for NIS2, DORA, and SOX compliance built in from day one.
- Multimodal Ingestion — Structured logs plus chat, audio, and video content — capturing the unstructured channels where social engineering and insider threats most often hide.
Ecosystem and Early Validation
“As we were rehydrating our logs, the legacy SIEM simply couldn’t do it. We had to switch gears and go to Databricks. Without Databricks, we wouldn’t have been able to rehydrate and analyze the data.”
— Niels Heijmans, Sr. Principal Security Architect, Atlassian
Royal Cyber’s Lakewatch Implementation Approach
PHASE 1: Telemetry Inventory
- Map data sources: Identify and catalog all enterprise security log sources.
- Design pipelines: Architect the flow of data from ingestion to the Lakehouse.
- Normalize to OCSF: Standardize raw telemetry into the Open Cybersecurity Schema Framework.
PHASE 2: Detection Tuning
- Calibrate AI models: Fine-tune machine learning models for accurate threat detection.
- Custom rule Authoring: Develop YAML and Python rules specific to your environment.
- Backtest vs history: Run new detection logic against historical data to ensure efficacy.
PHASE 3: Agentic Workflows
- Deploy Agent Bricks: Activate custom AI agents to autonomously triage security telemetry.
- Genie Spaces setup: Configure natural language interfaces for analyst threat hunting.
- SOAR/ITSM connect: Integrate Lakewatch with existing ticketing and orchestration platforms.
PHASE 4: Migration & Hybrid
- Splunk/Sentinel/QRadar move: Execute the transition from legacy platforms to a native Lakehouse architecture.
- QRadar migration: Specifically manage the migration of existing security workflows.
- Analyst enablement: Provide hands-on training to SOC teams on AI-driven hunting and response
Bring Security Intelligence Into Your Lakehouse
The transition to lakehouse-native security is not a distant goal, it is already underway, and those organizations that go first will have a long-term edge in the speed of detection, data coverage, and overall cost of ownership. The financials are strong, the technology is tested at scale, and the regulatory pressure is constantly growing. Royal Cyber possesses the accredited expertise, the established implementation approach, and the comprehensive Databricks alliance to assist your organization in doing so with secureness. The Lakewatch team is here to help with your initial assessment, a legacy SIEM migration, or to make the most of your existing Databricks investment.
The future of enterprise security runs on the Lakehouse — let Royal Cyber help you get there.
Frequently Asked Questions
Yes, as long as organizations have already operational Databricks workloads, Lakewatch can be used as the main SIEM. In the case of full-fledged Splunk or Microsoft Sentinel shops, a hybrid solution is the most viable point of departure: Lakewatch takes over analytics, long-term retention and AI-based threat hunting, whereas the current SIEM deals with the alerting and workflow continuity over the migration duration. The route will be based on your existing data maturity and operational capabilities.
All telemetry is stored in Delta Lake or Apache Iceberg format within your own cloud storage account — you own it entirely. You control tiering (hot, warm, cold), and multi-year retention is cost-effective by default with no per-day or per-GB storage surcharge as data ages. This directly addresses one of the biggest pain points with legacy SIEMs, where long retention windows become prohibitively expensive.
Lakewatch entered Private Preview in April 2026. General availability is yet to be announced. Any organization planning to get an early access needs to start the preparation of the readiness by evaluating Databricks footprint, data source inventory, and compliance needs now so that they can get on board as soon as GA is called.
At Royal Cyber, we provide a guided onboarding journey that starts with a SIEM Cost and Coverage Assessment, during which our certified Databricks engineers chart your existing telemetry lapses, ingestion expenses, and compliance requirements against the Lakewatch architecture. There, we work up a phased deployment strategy that fits your environment, be it a greenfield deployment or a migration of Splunk, Sentinel, or QRadar. The majority of clients recognize a significant value in the first 60 days of interaction.
Royal Cyber is an authorized Databricks Consulting Partner with a history of successful enterprise Lakehouse implementations in financial services, healthcare, retail, and manufacturing. Our team consists of cross-functional data engineering and AI/ML, cloud security, and compliance (that is, we do not bootstrap the technology, but rather make it fit your regulatory requirements (NIS2, DORA, SOX) and business environment). Our Databricks practice is committed, immersive, and constantly renewed like the platform itself, unlike generalist SIs.
Author
AI Engineer
Content Writer
Websites used to be something you built once and basically…
Read More »Websites used to be something you built once and basically…
Read More »Websites used to be something you built once and basically…
Read More »
