The security information and event management (SIEM) market is now a major battleground with more than 20 vendors included in Gartner’s latest Magic Quadrant report. However, amid the cloud transformation, vendor consolidation, and competition and integration with extended detection and response (XDR), the future is increasingly uncertain.
The impact of these disruptive forces is underscored by recent moves by big names, such as Cisco acquiring leading SIEM vendor Splunk, LogRhythm and Exabeam planning to merge, and Palo Alto Networks announcing an agreement to acquire IBM QRadar.
IBM gives up on SIEM, capitulates to XDR IBM's recent decision to sell its QRadar software-as-a-service (SaaS) assets to Palo Alto Networks marks a significant shift in its security business strategy.
“What it represents to me is that IBM is giving up on the SIEM, SOAR market and they're capitulating to arguably an XDR vendor,” Gartner Distinguished VP Analyst Peter Firstbrook told SDxCentral.
“It's one of the first dominoes to fall in terms of ‘hey, we don't think SIEM/SOAR is the future … XDR is the right way to go,’ and they want their customers to port to XDR,” he added.
The two companies plan to migrate IBM QRadar SaaS customers to Palo Alto Networks’s Cortex XSIAM platform. However, IBM doesn’t anticipate any QRadar SaaS employees to join Palo Alto Networks following the acquisition close.
“[Palo Alto Networks] don't want the technology, they just want the customers, they're just going to end a life of the [QRadar] technology, it'll go away [maybe in] five years,” Firstbrook said, adding the security giant needs more customers to customers to deploy its XSIAM products and to “get quantities of scale rolling.”
Cisco integrates XDR with Splunk SIEM Splunk, a long-time leader in the SIEM space, has been grappling with significant challenges as the market moves toward cloud-native solutions.
On top of that, Networking and security giant Cisco completed its $28 billion Splunk acquisition in March. At RSAC 2024, Cisco announced the integration of its XDR with Splunk’s SIEM solution — Enterprise Security (ES). This integration is designed to feed alerts and detections from Cisco XDR into Splunk ES to accelerate investigation and remediation processes.
Firstbrook pointed out that large enterprises may end up with three or four consoles for their security infrastructure. Splunk customers may say “Look we're not getting rid of Splunk. So, we may have Splunk, and then we may have XDR for security infrastructure, [Cisco] AppDynamics for operations management, and then we may have another data security one, and all of the alerts will flow up to Splunk, which will be the top-level dashboard.”
He added Cisco is trying to figure out how to integrate Splunk with its XDR strategy that Cisco has been building for the past three years. “They're going to have to share Intel. I'm not going to pick one over the other,” Firstbrook said. “They have overlap in both the XDR and observability with Splunk and now they're trying to figure, ‘well, how do we rationalize that [to our customers]?’”
The broader market: acquisition and niche specialization Firstbrook predicts that many existing SIEM vendors will either be acquired by larger firms looking to enhance their platforms or shift toward niche markets where they can maintain relevance, or they may go out of business.
“Some of them will get acquired by product vendors, let's say, Fortinet wants to beef up its integration, so it's going to buy somebody else that already has sort of the fundamental capabilities and they can optimize it for their environment,” he said.
“Some of them will go out of business, some of them will shift into other fields like governance risk and compliance or operations management, or [other] specific niches,” Firstbrook said, adding these vendors may target a niche market like the on-premises or IoT environment, or retail or logistics industries.
Security market will end up with few dominant players with integrated platforms The SIEM market is undergoing a period of transformational changes, driven by the shift to the cloud.
“Over the next 10 years, I think we're going to see a transition, similar to what we saw on the endpoint security market,” Firstbrook said.
“When the endpoint security market went from on-prem management to cloud, that's when we saw CrowdStrike, Microsoft, SentinelOne, Cybereason, all these vendors start to gain market share. And McAfee (now Trellix), Symantec, Sophos, they started to lose relevance and they used to be the big market players in that market,” he added.
As organizations look for consolidation and integration, Firstbrook envisions a security landscape dominated by a few major players offering integrated platforms supplemented by specialized partner solutions.
“It's going to look a lot more like ServiceNow where you have a very dominant provider, let's say, it's Microsoft, or Palo Alto [Networks], depending on your environment, or maybe it's Cisco, but you're gonna have a very dominant provider, and they will have an ecosystem of partners that fill in the problems that they don't solve, like if we don't do governance and compliance, we'll have a partner that you can plug into our environment,” he said.
Comments