New feature
Private Preview
Lakewatch
Lakewatch is a Databricks data governance capability, introduced March 2026.
Databricks' agentic SIEM built on the security lakehouse - a security analytics platform built natively on the Databricks Data + AI Platform that unifies security telemetry, IT logs and business data under Unity Catalog governance for threat hunting, detection-as-code and AI-driven detection and response.
- To build a SIEM, Databricks acquired SiftD.ai, a startup founded by the creator of Splunk's own Search Processing Language (SPL) - the query language of the kind of SIEM it set out to replace.
- Its model supplier is also a customer of the idea - Claude models help power Lakewatch, and Anthropic runs its own security lakehouse on Databricks.
- Just over four months after launch it got reinforcements by acquisition - Databricks completed its purchase of Panther, an AI SOC platform, to layer detections-as-code workflows and 100+ integrations on top of Lakewatch.
- Category
- Data governance
- Also known as
- Databricks Lakewatch, agentic SIEM, security lakehouse
- Verified
- 2026-09-27
Sources
- Official Official Databricks / Microsoft docs
- Official Databricks blog: Databricks Announces Lakewatch, New Agentic SIEM (March 24, 2026)
- Official Databricks blog: Databricks Completes Acquisition of Panther (August 3, 2026)
- Official Databricks blog: Alert fatigue is a business risk (April 2026, restates the Private Preview status)