It is funny how often the industry declares "SIEM is dead," yet the tech (and the acronym) keeps walking around healthier than ever.
It’s one of those fundamental pieces of SecOps that refuses to vanish.
Why?
Because it creates gravity. Every "SIEM-killer" eventually just gets absorbed:
UEBA? Became a feature.
SOAR? Slid into the workflow.
XDR? Tried to become the next gen SIEM but it failed, and is just better telemetry 🤔
Now we are staring at the AI SOC. The cycle is starting again. Will this be a core capability inside the SIEM? Possible
But here is the catch (and where I think we might split):
Path A: The SIEM absorbs AI and Agentic Automation, becoming a massive "SecOps Behemoth" that stores and does everything.
Path B: Data gravity and cost make Path A too expensive. Instead, we see a vendor-neutral investigation layer rise up. A layer blending AI SOC, SOAR, and Agents that sits above the stack, while the SIEM stays the analytics engine underneath.
Anton Chuvakin wrote a great piece on "SIEM Inertia" that touches on this reality : https://lnkd.in/dH2zU9d5
The SIEM isn't dying. It’s just deciding how heavy it wants to get.
Originally posted on LinkedIn on 21 November 2025.
Read the original post and the comments.
Explore the vendor landscape The full map of the AI for SecOps market, updated as it moves.


