Databricks Completes Acquisition of Panther: Accelerating the Security Lakehouse Era
Databricks finalized its acquisition of Panther, integrating the AI-driven security operations platform with its Lakewatch agentic SIEM to enhance real-time threat detection and response across unified data lakes.
Databricks announced the completion of its acquisition of Panther, an AI SOC platform designed for modern security operations. The deal aims to address the growing challenge of defending enterprises against AI-driven threats by unifying security data in a scalable, real-time environment. Legacy SIEM systems, constrained by high costs and rigid architectures, are increasingly unable to handle the volume and complexity of contemporary cyberattacks. The acquisition is intended to accelerate Databricks' security lakehouse vision, which integrates security, IT, and business data for streamlined detection and response.
The addition of Panther brings mature SOC workflows and over 100 pre-built integrations to Databricks' Lakewatch agentic SIEM. This combination eliminates the trade-off between comprehensive data ingestion and cost control, enabling security teams to process petabyte-scale telemetry without sacrificing performance. Previously, organizations faced a dilemma: either ingest vast amounts of data at prohibitive costs or limit ingestion to manage expenses, leaving blind spots in coverage. The integration of Lakewatch and Panther removes this barrier by providing an open, governed architecture that supports both rich data scale and fast, actionable workflows from day one.
Panther’s software-driven workflow layer complements Lakewatch’s open-data foundation by embedding native AI agents directly into the security lakehouse. These agents automate alert triage, threat hunting, and detection logic refinement, allowing security teams to respond to incidents at machine speed. Unlike traditional SIEMs that rely on manual processes, the combined platform enables intelligent agents to investigate incidents, draft detection rules, and execute response actions autonomously. This integration is engineered for cloud-native teams, aligning security operations with modern software engineering practices.
The partnership between Databricks and Panther reinforces a commitment to open ecosystems, ensuring customers retain ownership of their security telemetry in accessible formats. Unlike legacy SIEM providers that impose proprietary constraints and high ingestion fees, the combined platform promotes interoperability across the enterprise stack. The result is a self-improving security organization capable of outpacing modern threats through scalable automation and real-time data analysis. Databricks and Panther aim to redefine security operations for the agentic era by delivering a unified blueprint for modern SOCs.