My Friday SIEM post is here, probably at this point I should add an edition number 🤔
Today I wanted to discuss the difference between SecOps Agents and AI SOC inside a SIEM versus in a standalone product or SOAR.
SIEMs own the data, so they have the upper hand here.
Especially for teams that send everything into the SIEM, you will get amazing triage results inside it, simply because the SIEM has all the data. If done right, they can query that data the fastest and most optimized way to get you the best results. Timeline analysis, blast radius, all the bells and whistles.
But ONLY if you get all the data there.
This means enrichments as well.
Then you will be limited on response.
As I explained in my previous posts, SIEM vendors were smart to play the SOAR card. The bad part is that they never invested enough to make it shine. In my opinion, unless you have all response in a single ecosystem, you need a vendor agnostic agentic, automation, and orchestration layer.
Where the pure play and SOAR vendors have the upper hand is when you don't send everything to your SIEM.
They do enrichment better, but they are somewhat limited on what APIs they have available with the SIEM to run queries and retrieve data, or with any other system from which you ingest alerts and detections.
And SOAR-like vendors will shine with the response. Slapping MCP for response won't make the cut.
On this and more, I will join Chris Hughes on May 4th where we will discuss this and other fun topics.
ʜᴀᴠᴇ ᴀ ɢʀᴇᴀᴛ ᴡᴇᴇᴋᴇɴᴅ!
Originally posted on LinkedIn on 24 April 2026.
Read the original post and the comments.


