/
New feature Private Preview

Lakewatch

Lakewatch is a Databricks data governance capability, introduced March 2026.

Databricks' agentic SIEM built on the security lakehouse - a security analytics platform built natively on the Databricks Data + AI Platform that unifies security telemetry, IT logs and business data under Unity Catalog governance for threat hunting, detection-as-code and AI-driven detection and response.

  • To build a SIEM, Databricks acquired SiftD.ai, a startup founded by the creator of Splunk's own Search Processing Language (SPL) - the query language of the kind of SIEM it set out to replace.
  • Its model supplier is also a customer of the idea - Claude models help power Lakewatch, and Anthropic runs its own security lakehouse on Databricks.
  • Just over four months after launch it got reinforcements by acquisition - Databricks completed its purchase of Panther, an AI SOC platform, to layer detections-as-code workflows and 100+ integrations on top of Lakewatch.
Open in REbricked →
Category
Data governance
Introduced
March 2026
Announced at
Launch blog and Private Preview, March 2026
Also known as
Databricks Lakewatch, agentic SIEM, security lakehouse
Verified
2026-09-27

Sources

Related in Data governance