Back from vacation and hitting my Friday SIEM post. This week theme is: SIEM ate the SOAR entree, is eating AI SOC as a main dish, and planning for Agent Builder as dessert.
The SOAR entree. Most if not all large SIEMs shipped their own SOAR. Latest was Elastic announcing Elastic Workflows this March. They're calling it the end of the "SOAR automation tax."
The patterns split into a few categories.
Acquisition path: Palo Alto (Demisto), Splunk (Phantom), Google SecOps (Siemplify), Fortinet (CyberSponse).
Took years for some to even get a unified UI. Separate infra, a lot of stitching, you could sense it. Development slowed or got abandoned. What's left is mostly case management with basic automation and integrations stuck within the vendor ecosystem.
Built from scratch: Elastic and Datadog developed natively. Worked with Datadog's for a few months. Decent, simple, but not a true automation platform. More case management orchestration.
EDR turned SIEM turned SOAR: CrowdStrike and SentinelOne. Checkbox items. Great at basic case orchestration within their own ecosystem and automating notifications. That's about it.
The AI SOC main dish. Most major SIEM players now have some form of AI SOC. I expect the same pattern as SOAR. Some acquire, others build. Same fragmentation likely. This connects to what Ross Haleliuk wrote recently about AI agents challenging the SIEM business model. SIEMs charge for ingestion. AI agents don't care if data is centralized. People expect analytics and workflow automation, not just storage.
Agent Builder as dessert. CrowdStrike, Palo Alto, Databricks all have agent builder capabilities now. Most still early beta but that's the direction. Building an agent framework natively inside a SIEM is hard and I don't think most vendors are there yet.
Standalone automation platforms have a real advantage here. Being on the builder side and seeing what it takes, the complexity is significant. I expect many SIEM vendors will go the acquisition route. Same playbook as SOAR.
And we might end up in the same place too. SIEM vendors building agent builders around their own ecosystems rather than connecting to everything. Agents that only work within one vendor's stack defeats the whole purpose.
A SOC doesn't run on one vendor.
Originally posted on LinkedIn on 17 April 2026.
Read the original post and the comments.


