Security Operations and SIEM
Security operations (SecOps) is where every other security telemetry stream lands, and the category is being reshaped by two forces at once: hyperscaler bundling (Microsoft Sentinel, Google SecOps) and the agentic SOC. Cisco paid ~$28B for Splunk to own this layer, and it is not yet clear how durable ownership of the layer will prove.
What security operations and SIEM cover
Security operations is the discipline of detecting, investigating, and responding to threats. Its tooling stack — historically three separate products now collapsing into one — is:
- SIEM (Security Information and Event Management): ingests logs and telemetry from across the estate, correlates them into alerts, and stores them for search and compliance. The system of record for the SOC; priced by data volume ingested. Splunk, Sentinel, Google SecOps, Securonix, Exabeam.
- SOAR (orchestration & automation): codifies analyst response into automated playbooks. Increasingly a feature of the SIEM, not a standalone category (Palo Alto bought Demisto; Splunk bought Phantom).
- XDR / next-gen SIEM: correlates native endpoint, identity, cloud, and network telemetry without the per-GB ingestion tax — the architecture by which CrowdStrike (LogScale), Palo Alto (XSIAM), and Microsoft (Defender + Sentinel) attack the legacy SIEM from below.
SIEM is the aggregation layer of the SOC — the place all other tools' data flows to. That makes it the highest-leverage position in security operations and the natural control point for AI: the vendor that owns the data lake the detections run on owns the substrate the agentic SOC will automate. It also carries volume-based pricing that increases cost as customers log more data, which is a primary reason the architecture is being disrupted.
How the vendors make money and how they differ
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| Splunk | Cisco (CSCO) | Incumbent / bundler | Most widely deployed enterprise SIEM; per-GB ingestion economics; now Cisco's data/telemetry platform — networking-led SOC bundle |
| Microsoft Sentinel | MSFT | Bundler | Cloud-native SIEM converging with Defender XDR; bundled pricing inside the Microsoft estate, able to price toward near-zero marginal cost |
| Google SecOps (Chronicle) | GOOGL | Bundler / hyperscaler | Petabyte-scale, flat-rate-ish ingestion (priced by users/data, not pure GB); Mandiant intel baked in; furthest "vision" in Gartner MQ |
| Palo Alto (Cortex XSIAM) | PANW | Platform / disruptor | AI-driven "autonomous SOC" rebuild of SIEM; fastest-growing new SecOps platform; the XDR-from-above attack on legacy SIEM |
| CrowdStrike (Next-Gen SIEM) | CRWD | Platform / disruptor | Built on LogScale (Humio); endpoint-telemetry-led; attacks SIEM's ingestion tax with the Falcon data |
| Securonix | Vista-backed | Specialist analytics | UEBA-led cloud SIEM; scaled independent; classic sponsor consolidation candidate |
| Exabeam + LogRhythm | Private (merged 2024) | Specialist consolidator | Exabeam UEBA + LogRhythm SIEM merger — two sub-scale players combining to survive against the platforms |
| Devo, Gurucul, Sumo Logic | various / PE | Sub-scale specialists | Cloud-native or analytics-led; Sumo Logic taken private by Francisco Partners (2023); roll-up/consolidation supply |
| Elastic (Elastic Security) | ESTC | Open-core challenger | Search-engine-led, cost-efficient SIEM; competes on price/openness against per-GB incumbents |
| IBM QRadar | IBM → PANW (SaaS) | Legacy in transition | IBM sold QRadar SaaS to Palo Alto and steers customers to XSIAM — a managed wind-down of a legacy SIEM franchise |
| Sophos Fusion | Thoma Bravo (TB) | Platform integrator | AI-native bundled platform (endpoint + SIEM + identity + MDR); launched Jul 2026 with next-gen SIEM / XDR / MDR components GA on Aug 15, 2026; Taegis (from Secureworks, acquired Feb 2025) + Sophos endpoint + Counter Threat Unit analytics; TB's multi-platform consolidation play to attack legacy SIEM from the endpoint up |
Three camps compete over one pool. The legacy SIEMs (Splunk/QRadar) own the install base and the compliance workflows but carry the per-GB pricing model; their value is the switching cost, not the architecture. The hyperscaler bundlers (Sentinel, Google SecOps) compete on price and data-gravity, and can offer good-enough SIEM at low cost to win the cloud estate. The platform disruptors (XSIAM, CrowdStrike NG-SIEM) reframe SIEM as a by-product of telemetry they already collect, removing the ingestion cost. The scaled specialists (Securonix, Exabeam/LogRhythm, Devo, Gurucul) sit in the middle: too small to out-invest the platforms on AI and too large to compete purely on price, which makes them the clearest consolidation supply in the domain.
Value migrating off legacy SIEM
Signature deals & events
- Cisco → Splunk (~$28B, announced Sep 2023, closed Mar 18 2024) — the largest SecOps deal ever; Cisco buys the SOC data layer to anchor a networking-led security platform. The integration's success (or struggle) is the bellwether for whether legacy SIEM franchises survive platform absorption.
- IBM QRadar SaaS → Palo Alto Networks — IBM exits the SaaS SIEM business, migrating customers to Cortex XSIAM; a legacy vendor conceding the architecture and a platform vendor buying an install base to convert.
- Exabeam + LogRhythm merger (2024) — two sub-scale specialists combining to reach survival scale against the platforms; the template for specialist consolidation in the domain.
- Sumo Logic → Francisco Partners (~$1.7B, 2023) — a cloud-native log/SIEM player taken private; the sponsor playbook on a sub-scale analytics asset.
- Sophos Fusion platform launch (Jul 2026) — Thoma Bravo's TB-owned Sophos integrates endpoint (Sophos Intercept X), SIEM (Taegis, from Secureworks), identity management, and MDR (Unit42-sourced threat intel) into a single AI-native platform; a platform consolidation play to compete against Palo Alto XSIAM by bundling endpoint-first with SIEM. The capabilities reach general availability in a phased sequence from August through October 2026: Sophos Next-Gen SIEM, the expanded Sophos MDR, and Sophos XDR rebuilt on Secureworks Taegis analytics became generally available August 15, 2026; Sophos AI Defense (shadow-AI discovery, policy enforcement and data protection for AI tools in use) enters early access in August with general availability in October; and Sophos CISO Advantage (continuous control validation, compliance mapping, peer benchmarking, delivered through the MSP channel) becomes available from October. The pricing model is the structurally significant part: Next-Gen SIEM is priced by users and servers rather than by data volume, removing the incentive to withhold telemetry that per-GB ingestion economics create — the same attack on the ingestion tax that CrowdStrike NG-SIEM and Palo Alto XSIAM run, now carried into the mid-market through an MSP-led channel. Sophos reports 625,000 organizations on the platform and over 40,000 MDR customers, with 52% of cases resolved entirely by AI and an average alert-to-automated-response time of 89 seconds. See Sophos press release (Jul 15, 2026).
- Abstract Security — $25M round, co-led by Cheyenne Ventures and AVP (announced Jul 23 2026) — with Olive Hill Ventures, Crosslink Capital, and Rally Ventures participating, bringing total funding to nearly $50M at a valuation the company said had tripled since its prior round. Abstract sells a "streaming-first," composable security-operations platform that runs detections in-stream on the telemetry pipeline rather than after full ingestion into a SIEM. The company cited annual recurring revenue up 380%, net revenue retention of 264%, and a tripled customer base over the prior year. The print is a signal that the security-data-pipeline layer — reducing what must be ingested and paid for per-GB — is drawing venture capital as a distinct attack on legacy SIEM economics.
- The agentic-SOC pivot — XSIAM, CrowdStrike Charlotte AI, Google's agentic SecOps, and Microsoft Security Copilot all reposition SecOps around AI agents that triage and respond — the demand catalyst (and the disruption) reshaping the category. Sophos Fusion's Aug 15 SIEM GA adds another platform contender to the agentic-SOC race. See AI Security.
The bear case
The SecOps bull case is that all telemetry must land somewhere, so the SIEM/SOC data layer is permanent and the winner compounds. The bear case is that the category is being commoditized from two directions at once. From above, the hyperscalers (Sentinel, Google SecOps) can bundle SIEM into the cloud contract at near-zero marginal price; from the side, the platform disruptors (XSIAM, CrowdStrike NG-SIEM) make the standalone SIEM redundant by deriving detections from telemetry they already own. The legacy SIEM's main durable asset is switching cost, and the agentic SOC, by automating the migration and re-tuning of detections, lowers that switching cost over time. A falsifiable test is Splunk's growth and renewal economics inside Cisco relative to XSIAM's and Microsoft Sentinel's net-new SIEM wins. If Splunk decelerates while XSIAM and Sentinel take the net-new SOC budget, the thesis that legacy SIEM is a durable franchise is breaking, and Cisco would have overpaid for a declining system of record.
→ Cross-references: Vendors, Endpoint, Network/SASE, AI Security, Earnings, Bear Case.
Adjacent market: the observability and telemetry-pipeline industry this page borders is mapped on Observability & Data Pipelines.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.