top of page

Databricks Closes Panther Acquisition to Advance Its AI Security Push

Aug 11
13 min read

Databricks completed its Panther acquisition on August 3, turning a two-month-old agreement into a direct challenge to established security platforms. The deal surfaced through Google News as Databricks moved beyond data analytics and deeper into operational cybersecurity. Its target is no longer simply another data warehouse. Databricks now wants Lakewatch and Panther to replace parts of the security information and event management stack.

That ambition creates the central tension. Panther brings working detection tools, security integrations, and investigation workflows. Databricks supplies the data layer, governance system, and AI infrastructure beneath them. The combined pitch threatens Splunk, CrowdStrike, Palo Alto Networks, Microsoft, and other vendors that already control security operations budgets.

The acquisition does not prove that enterprises will entrust Databricks with their security operations. It does show that the company has assembled the components for a credible attempt. The next contest concerns execution, not architecture diagrams: product integration, detection quality, migration effort, and customer adoption.

The Panther Deal Is Closed, but Integration Has Just Started

Databricks has moved from announcing a security strategy to owning a security operations product with established workflows.

Databricks announced on August 3 that it had officially completed the Panther acquisition. The companies first disclosed their agreement on June 16, without releasing financial terms. Completion gives Databricks control of Panther’s technology and brings its employees into the broader Lakewatch effort.

Panther builds an AI-assisted security operations center platform. A security operations center, usually called a SOC, monitors systems, investigates suspicious activity, and coordinates responses to incidents. Panther’s platform handles the data collection, detection, triage, and investigation work surrounding that mission.

The completed acquisition adds three practical layers to Lakewatch. Panther provides more than 100 packaged integrations, a detection-as-code system, and AI-assisted investigation workflows. These components address a gap in Databricks’ original security proposition.

Detection-as-code means analysts define, test, review, and deploy threat rules through software development practices. Teams can keep rules in version control and route changes through automated testing. That approach contrasts with security products where administrators edit rules inside a proprietary interface.

Panther’s integrations also shorten the path between raw data and useful detections. Security telemetry arrives from cloud services, identity platforms, endpoints, collaboration software, and business applications. Each source uses different formats and produces different signals.

Lakewatch already offered the storage, processing, governance, and AI foundation for analyzing those records. It did not enter the market with Panther’s catalog of mature security workflows. Databricks now owns both sides of that equation.

The transaction followed an existing technical relationship. Panther announced a private-preview Databricks integration in September 2025. Customers could use Databricks as the data lake beneath Panther instead of moving security information into another proprietary repository.

That earlier integration reduced the acquisition’s technical uncertainty. Panther had already designed a deployment path for writing normalized security records into Databricks. Its analysts could search those records from Panther while queries ran against the customer’s Databricks environment.

However, a functioning integration is not the same as a unified product. Databricks must align identities, permissions, administration, support, billing, road maps, and customer contracts. It must also decide where Panther ends and Lakewatch begins.

Those decisions matter because security buyers do not purchase architecture alone. They purchase dependable operations during incidents. An incomplete connection between the data platform and response workflow creates risk at precisely the moment customers need certainty.

The Google News headline captures a completed corporate transaction. The more consequential work begins after closing, when Databricks must convert acquired components into one coherent security experience.

Why Databricks Wants the Security Data Layer Now

Cybersecurity gives Databricks a way to turn its existing data advantage into a new operational market.

Modern security teams collect enormous volumes of event data. Authentication attempts, network connections, cloud configuration changes, endpoint activity, and software audit trails all create records. Those records help investigators reconstruct what happened before and during an attack.

Traditional SIEM products collect and search this telemetry. SIEM stands for security information and event management, a category that centralizes security data and applies rules to detect suspicious behavior. Splunk helped establish the category, while Microsoft, Google, CrowdStrike, and Palo Alto Networks now sell competing approaches.

The category has a structural problem. Collecting more telemetry improves visibility, yet retaining and searching that data raises infrastructure and licensing demands. Some organizations filter records, shorten retention periods, or divide information across multiple systems.

Databricks sees that problem as a data architecture opening. Its lakehouse model combines inexpensive object storage with database management, analytics, and governance. Lakewatch applies that foundation to security information rather than ordinary business analysis.

The company introduced Lakewatch in March 2026. It described the product as an agentic SIEM, meaning software agents can perform parts of triage and investigation under defined controls. Lakewatch uses the Databricks platform to retain and analyze security, IT, and business data together.

Databricks also acquired Antimatter and SiftD.ai to support the launch. Antimatter brought experience with authorization and agent security. SiftD.ai contributed engineers with backgrounds in large-scale search and detection systems.

The earlier acquisitions gave Databricks specialized talent and technology. Panther adds a more complete operating layer. It already supports investigations, rule management, integrations, and workflows used by security teams.

This sequence explains why the closing matters more than another AI acquisition headline. Databricks is not adding a small feature to an analytics platform. It is assembling a vertical product that can compete for an established security budget.

Security also fits the company’s underlying economics. Telemetry is continuous, large, and operationally important. Customers must retain some records for investigations, internal controls, and regulatory obligations. Queries can become compute-intensive when analysts search long time ranges or correlate many sources.

Those characteristics create steady demand for storage, processing, governance, and AI inference. Databricks already sells each underlying capability. Security packages them around a specific buyer and a recurring operational need.

Timing matters as well. Enterprises are introducing AI agents into development, customer support, administration, and internal research. Each agent creates new activity records and potential access risks. Security teams need to monitor both conventional systems and software that acts with greater autonomy.

Attackers can also use automation to discover weaknesses, generate convincing messages, and adjust tactics faster. That does not make every attack an advanced AI operation. It does increase pressure on defenders to correlate more data without expanding manual work at the same rate.

Databricks argues that a shared data layer helps close that gap. Security agents can examine historical telemetry alongside identity, asset, and business context. Panther supplies the detection and investigation machinery that turns those records into daily SOC work.

This is why the company acted now. Lakewatch needed operational depth, while Panther needed a larger data and AI foundation. The acquisition combines those needs in one organization.

Google News Signals a Larger Fight With SIEM Incumbents

The real opponent is the proprietary SIEM stack, not another young AI security company.

Google News is an aggregation channel in this story, not a participant in the acquisition. Its visibility reflects the broader significance of Databricks entering an established security category. The company is challenging how customers store, analyze, and act on security data.

Databricks’ primary argument targets the traditional coupling of storage, processing, and security workflows. Legacy platforms often expect customers to ingest records into a vendor-controlled environment. Costs and performance can then influence how much data customers retain.

Lakewatch proposes a different arrangement. Customers keep telemetry in open lakehouse formats while Databricks supplies governance, processing, and AI tools. Panther runs detections and investigations against that foundation.

The company lists Delta, Parquet, Spark, SQL, and the Open Cybersecurity Schema Framework among its supported standards. Open formats can make information accessible to more than one tool. They can also reduce the technical friction of moving or reusing data later.

Panther’s current data lake architecture supports both Snowflake and Databricks backends. Customers can also deploy Panther in an AWS account they control. Those choices reinforce the open-data argument, although product ownership may eventually reshape its positioning.

The direct pressure falls first on Cisco’s Splunk. Splunk built a large business around indexing machine data for search, monitoring, and security. Many organizations already rely on its query language, detection content, dashboards, and operational expertise.

Replacing that installed base takes more than offering cheaper storage. Customers have years of custom rules and institutional knowledge embedded in existing systems. They also depend on integrations with case management, endpoint security, threat intelligence, identity tools, and response platforms.

Microsoft brings a different advantage. Sentinel connects security analytics to Azure, Microsoft 365, Entra identity services, and Microsoft’s broader security portfolio. Customers already committed to that environment can consolidate vendors without adopting another core data platform.

Google offers its own security operations platform, built from Chronicle and later integrations. It similarly emphasizes large-scale telemetry analysis and threat intelligence. CrowdStrike and Palo Alto Networks approach the contest from endpoint and network security positions, where they already observe high-value activity.

Databricks enters with control of the analytical data plane. That can appeal to enterprises whose engineering teams already use the platform. A customer could avoid copying records into a separate SIEM while applying shared governance and analysis tools.

The approach also opens correlations that conventional security stores may not handle easily. A detection can combine login activity with an asset inventory, employee status, application ownership, or transaction context. Those business records can help distinguish routine behavior from a meaningful threat.

That advantage has boundaries. Combining security and business information expands the value of the analysis, but it also raises access-control questions. Analysts and automated agents should not receive unrestricted access to sensitive human resources or customer data merely because it improves context.

Databricks will rely heavily on Unity Catalog, its governance layer for managing permissions, lineage, and data discovery. The architecture can define controls. Customers still need to configure and audit those controls correctly.

The competitive fight therefore concerns operating models as much as features. Incumbents offer vertically integrated security products. Databricks offers a governed data foundation plus acquired security workflows. Buyers must decide whether consolidation around the data layer improves control or concentrates too much responsibility.

Panther Supplies the Mechanism Lakewatch Was Missing

Panther converts Databricks’ security lakehouse from a place to analyze logs into a system that can run security operations.

A security lakehouse can retain information, execute queries, and apply governance. Those capabilities are necessary, but they do not automatically create useful detections. Security teams still need parsers, normalized schemas, rules, investigation workflows, and response actions.

Panther brings those mechanisms. Its connectors collect records from major cloud platforms, identity providers, code repositories, endpoints, and software services. The system parses incoming records and writes structured data into the selected backend.

The Databricks integration allows Panther to use the customer’s lakehouse as that backend. Analysts search from Panther, while the underlying query runs inside the Databricks environment. The customer can retain direct control of the data infrastructure.

Panther’s Databricks integration describes three important actions. It writes normalized security records into the lake, applies real-time detection rules, and lets analysts investigate those records without duplicating them elsewhere.

Consider a compromised cloud administrator account. Authentication logs could show an unusual login. Cloud audit records might reveal newly created credentials, while code-hosting logs show an unexpected repository download.

A conventional investigation may require several tools and manual correlation. Panther can normalize the sources and trigger rules. Lakewatch can supply longer history and business context, such as the administrator’s role or the affected application’s owner.

An AI agent could then assemble the evidence, recommend a severity level, and draft an investigation summary. Databricks says its agents can also assist with threat hunting and detection logic. Those remain company claims until customers validate them across production environments.

Detection-as-code provides another connection between the products. Security engineers can write a rule, test it against historical lakehouse records, review it through version control, and deploy it through a pipeline. The process resembles established software engineering practice.

That mechanism matters because AI-generated detections need review. A plausible rule can still create false positives, miss edge cases, or query the wrong fields. Version control and testing give teams a way to inspect changes before they influence incident handling.

Panther also adds an interface designed for security analysts. Databricks cannot assume every investigator wants to work directly in notebooks or write SQL. Analysts need alerts, cases, evidence, assignments, approvals, and timelines organized around incidents.

The acquisition therefore fills a product-design gap as much as a technical one. Databricks supplies flexible infrastructure. Panther supplies the specialized interaction model used by SOC teams.

This combination also clarifies the role of AI. The models are not expected to detect every threat from raw logs without predefined structure. Instead, they operate within pipelines that collect, normalize, enrich, and govern the underlying information.

That distinction separates useful automation from a chatbot attached to a dashboard. An agent needs access to the correct records, a defined objective, permission boundaries, and an audit trail. It must also surface evidence so a human can evaluate its conclusion.

Panther’s product updates show that it has been moving in this direction. Its July 15 release added threat-intelligence enrichment and Slack controls for triggering AI triage. A June update added telemetry support for Claude Code and Claude Cowork activity.

Those releases illustrate how the combined platform can monitor emerging AI tools while using AI for investigation. They also reveal the operational burden ahead. Databricks must preserve Panther’s release cadence while integrating its components into Lakewatch.

The mechanism is credible because many parts already exist. The unresolved question is whether the combined experience becomes simpler than using separate products. Integration that merely bundles two interfaces would weaken the acquisition’s central promise.

Open Data Does Not Remove Security Risk

Databricks’ architecture addresses data portability, but it does not settle accuracy, governance, or operational trust.

The company presents openness as an answer to proprietary security platforms. Keeping telemetry in standard formats can reduce dependence on a single query engine. Customers can apply additional analytical tools and retain more control over long-lived records.

However, open storage does not make detection content portable by itself. Rules depend on normalized fields, enrichment pipelines, query behavior, alert logic, and workflow integrations. A customer may own the underlying files while remaining dependent on Panther’s control plane.

Portability also becomes more complicated after an acquisition. Panther currently supports Snowflake and Databricks as data lake backends. Databricks has not publicly explained whether both options will receive equal long-term investment.

That uncertainty matters to Panther customers using Snowflake. Databricks has an incentive to optimize the combined product for its own platform. Existing customers will watch release notes, support commitments, and feature parity for evidence of the actual direction.

The competitive story creates another risk. Databricks argues that combining security, IT, and business information supplies better context. Yet broad access can increase the consequences of a permission mistake or compromised automation.

A security agent might need employee status to assess a login. It probably does not need unrestricted access to compensation records or private communications. Customers must design narrow access paths and test whether agents stay within them.

Governance tools can enforce boundaries, but configuration remains a human responsibility. Teams must determine which records each workflow can read, which actions require approval, and how long agent activity remains auditable.

Model behavior adds uncertainty. AI-generated summaries can omit evidence or present an uncertain inference too confidently. Automated triage can also reinforce weak rules if teams treat machine output as authoritative.

Databricks says Panther’s agents can learn from analyst feedback and refine detection logic. Buyers should ask how that feedback is stored, reviewed, and separated across customers. They should also ask whether a model can deploy a rule or response action without human authorization.

False positives provide a practical test. A platform that analyzes more telemetry can uncover more context, but it can also create more signals. The important measure is not how many alerts the system generates. It is whether analysts resolve genuine incidents faster without overlooking important evidence.

Security buyers should demand controlled evaluations. A useful test would replay known incidents against representative telemetry and compare detection coverage, investigation time, analyst interventions, and false-positive rates. Marketing claims about autonomous agents cannot replace those results.

Migration presents a separate challenge. Large organizations have accumulated custom Splunk searches, Sentinel analytics rules, dashboards, playbooks, and operating procedures. Translating them into Panther detections requires engineering work and security validation.

The process may expose undocumented assumptions. A legacy rule can depend on a specific parser, lookup table, or field naming convention. Moving the underlying data does not automatically preserve that behavior.

Databricks also faces a credibility hurdle. Its reputation comes primarily from data engineering, analytics, and AI infrastructure. Security operations teams will expect incident-response expertise, dependable support, and conservative change management.

Panther helps supply that expertise. The acquisition also risks disrupting it if key employees leave or product priorities shift. Customers should track leadership continuity and the pace of security-specific releases.

The skeptical case is not that the architecture cannot work. It is that the hardest problems appear after the data becomes accessible. Accurate detections, controlled automation, predictable investigations, and trusted response actions require sustained product discipline.

Three Signals Will Show Whether the Security Push Is Working

The next evidence should come from product convergence, customer use, and competitive response rather than another acquisition announcement.

The first signal is a unified Lakewatch and Panther release. Databricks has explained how the products complement each other, but buyers need details about administration and daily use. A credible release should show shared identity controls, case workflows, deployment tooling, and governance.

Feature parity will matter within that release. Panther customers should watch whether Snowflake support continues alongside Databricks development. Databricks customers should examine whether the integration operates as one product or requires switching between loosely connected systems.

A coherent release would strengthen the claim that Databricks can challenge established SIEM vendors. Delays, overlapping interfaces, or unclear packaging would suggest that the acquisition remains a collection of components.

The second signal is independently described production adoption. Customer stories should include migration scope, retained data volume, detection coverage, investigation time, and analyst workload. They should also explain which incumbent product the customer replaced or retained.

Databricks and Panther have published examples of cost reduction and faster triage. Those vendor-selected results help identify potential use cases, but they do not establish typical performance. Buyers need repeatable evidence across industries and operating environments.

A particularly useful case would involve an enterprise already using Databricks for business data. It could show whether reusing the existing platform reduces data movement and governance effort. It should also document the new controls required when security agents access broader context.

Production retention will matter as much as new wins. Existing Panther customers can reveal whether service quality and development pace remain stable after the acquisition. Their renewal behavior will provide a harder signal than launch-day enthusiasm.

The third signal is how incumbents respond. Splunk, Microsoft, Google, CrowdStrike, and Palo Alto Networks will not leave the open-data argument unanswered. They can adjust storage options, expand integrations, introduce migration tooling, or strengthen their own AI workflows.

A competitive response would validate Databricks’ direction by showing that established vendors take the threat seriously. It could also weaken Databricks’ differentiation if incumbents match its portability and automation claims without forcing customers through a major migration.

Independent analysts have already identified the deal as an attempt to enter the agentic SIEM market. An industry assessment noted that Panther contributes a cloud-native SIEM and more than 100 integrations. The next assessment needs to examine adoption rather than intent.

The Google News attention around the closing is therefore an early marker, not a verdict. Databricks has acquired a credible security workflow layer and connected it to a large-scale data platform. It has also chosen a difficult market filled with entrenched products and cautious buyers.

Security leaders should now test the combined proposition against their own environment. Map current telemetry, detection rules, retention requirements, analyst workflows, and response controls before considering migration. Then ask Databricks to demonstrate each step with representative data.

The decisive question is straightforward: can Lakewatch and Panther reduce data compromises without creating new operational ones? Over the next several months, unified releases, measurable deployments, and incumbent reactions should provide the answer.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page