TrustRadius: an HG Insights company

Databricks Lakewatch

Score9 out of 10

1 Reviews and Ratings

What is Databricks Lakewatch?

Databricks Lakewatch is a lakehouse-native Security Information and Event Management (SIEM) platform for security operations centers. It combines Databricks’ open, governed security-data foundation with the detection engineering, integrations, and AI SOC workflows obtained through Databricks’ acquisition of Panther Labs.

Lakewatch centralizes security telemetry, IT logs, and relevant business data in a Databricks environment. It supports petabyte-scale collection, retention, search, correlation, threat detection, and investigation without requiring security data to be moved into a separate proprietary store. Telemetry can be normalized using the Open Cybersecurity Schema Framework (OCSF), while Unity Catalog supplies access controls, lineage, and auditing.

The platform supports detections as code, allowing security engineers to author, test, version, and deploy detection logic through standard development and continuous integration workflows. More than 100 connectors originating from Panther cover cloud platforms, identity systems, SaaS applications, and endpoint products. Analysts can correlate these signals with enterprise context such as asset inventories, HR records, and other governed business data.

Panther Labs acquisition and AI SOC capabilities
Databricks completed its acquisition of Panther Labs in August 2026. Before the acquisition, Panther operated as a cloud-native SIEM and AI SOC platform built around Python-based detection engineering, security-data lakes, automated investigations, and integrations with external security and business systems.

Within Lakewatch, Panther supplies the operational SOC and agentic automation layer. Its agents enrich alerts, investigate activity across the security data lake, summarize findings, draft and refine detection rules, and use analyst feedback to improve subsequent triage. This provides Lakewatch with independently material AI SOC Analyst functionality rather than limiting its AI features to conversational search or alert summarization.

The two technologies have complementary roles:

  • Lakewatch provides open storage, large-scale telemetry processing, governance, search, and access to Databricks data and AI services.
  • Panther contributes detection-as-code workflows, its integration library, alert operations, and production-oriented AI agents for triage and investigation.

Panther remains supported for existing customers while its capabilities are integrated into Lakewatch. Databricks has stated that Panther will transition over time into a unified Lakewatch offering. Lakewatch was initially announced in private preview in March 2026, so prospective customers should confirm current access, packaging, and the availability of individual Panther-derived capabilities.

Technical Details

Technical Details
Mobile ApplicationNo

FAQs

What is Databricks Lakewatch?
Databricks Lakewatch is a lakehouse-native Security Information and Event Management (SIEM) platform for security operations centers. It centralizes security telemetry, IT logs, and relevant business data in a governed Databricks environment for threat detection, investigation, and long-term analysis. It includes technology from Panther Labs, which was acquired by Databricks in June of 2026.