Cybersecurity Operations
SIEM and SOC Platforms: from ArcSight to AI agents
SIEM and SOC platforms are moving from log correlation that humans triage to AI agents that triage and investigate alerts themselves. ArcSight and QRadar collected events. Splunk Cloud and Sentinel moved them to the cloud. Today agents from Microsoft, CrowdStrike, Google and Torq close false positives on their own, while analysts still approve containment.
Autonomy level
2.9 of 5 · Supervised agents
launch score
Projected 4.0 by 2031
- Tasks automated
- 2.8
- Approval load
- 2.6
- Production maturity
- 3.3
Overall is the mean of the three sub-scores. How scores work
The same job, five eras
Drag across the eras to see who did the work, with what, and what broke.
What job does SIEM and SOC platforms software do?
A SIEM exists to answer one question fast: is something bad happening in my environment right now, and how bad is it? It collects logs and events from firewalls, endpoints, identity systems and cloud services, correlates them into alerts, and gives a security operations center (SOC) the evidence to decide what to do.
The job has never been the collection. It is the judgment. Every SOC drowns in alerts, and most of them are false positives. The history of this category is the history of trying to get a human to the one alert that matters before the attacker moves. CrowdStrike puts the average eCrime breakout time at 29 minutes in 2025. That number is why the job is moving to agents.
Era 1 · Before SaaS · 2000-2012
How did SIEM and SOC platforms work before SaaS?
The SIEM started as a box in the data center. ArcSight and Q1 Labs QRadar collected syslog and event data from firewalls, IDS sensors and servers, normalized it, and ran correlation rules over it. Gartner analysts named the category SIEM in 2005, merging security information management and security event management into one term.
The big vendors bought in. HP closed its roughly $1.5 billion ArcSight deal in October 2010, and IBM completed its Q1 Labs acquisition in October 2011 and built a security division around QRadar. The pitch was a single pane of glass. The reality was an appliance that needed a dedicated team to keep running.
Correlation rules were hand written. Every new data source meant a new parser, and every new attack meant a new rule. Storage was expensive, so teams kept 30 to 90 days of logs and dropped the rest. Much of the deployment budget was justified by compliance: PCI and SOX auditors wanted log retention and review, and the SIEM was the receipt.
What broke was the human at the end of the pipe. Rules fired thousands of alerts, a tier-1 analyst opened each one, pivoted across four consoles, and closed most as noise. I built SOC 2, PCI and ISO programs at Sageworks, and log review was the control everyone could prove they owned and almost nobody could prove they did well. The manual triage queue was born here.
Era 2 · The Cloud Move · 2013-2019
What changed when SIEM and SOC platforms moved to the cloud?
Splunk changed the economics first. It indexed any machine data without a fixed schema, and in October 2013 it made Splunk Cloud generally available on AWS. Search replaced rigid correlation for many teams. The bill moved to data volume, which meant every new log source became a budget fight.
The cloud natives followed. Alphabet's Chronicle launched Backstory in March 2019 to search petabytes of security telemetry, and Microsoft made Azure Sentinel, now Microsoft Sentinel, generally available in September 2019 as a cloud SIEM priced on ingestion. Elastic offered the open stack for teams that wanted to run it themselves.
SOAR arrived to automate the repetitive work around alerts. Splunk closed its roughly $350 million Phantom acquisition in April 2018, and Palo Alto Networks built Cortex XSOAR on the same idea. Playbooks enriched an IP, pulled a user's recent logins, or quarantined a host on a trigger.
What broke was the playbook. It only handled what someone had already written down, and it broke when an API changed. Alert volume kept climbing as companies added SaaS apps and cloud accounts, and the tier-1 queue grew faster than headcount. Automation saved clicks. It did not replace judgment.
Era 3 · The Copilot Years · 2020-2024
What did AI copilots change in SIEM and SOC platforms?
Machine learning had been in SIEMs for years as user behavior analytics, scoring anomalies on top of rules. Generative AI changed the interface. Microsoft announced Security Copilot in March 2023 and made it generally available in April 2024, priced by security compute unit. CrowdStrike introduced Charlotte AI in May 2023 as a generative assistant for Falcon.
The copilot did real work for analysts. It summarized incidents, translated plain questions into KQL or SPL, explained a suspicious script, and drafted the incident report. Microsoft claimed analysts using it worked 22% faster and 7% more accurately in its own studies. Every vendor shipped one, which is the shift the AI security copilots prediction tracks.
The market consolidated around data platforms. Google bought Siemplify in 2022 and folded it into Chronicle, now Google Security Operations. Cisco completed its Splunk acquisition in March 2024. Exabeam and LogRhythm merged in July 2024, and Palo Alto Networks took over IBM's QRadar SaaS business in September 2024 and offered customers a path to Cortex XSIAM.
What broke was the premise that a faster human was enough. A copilot waits for a prompt. The analyst still opened every alert, still decided, and still clicked. Attackers were using the same models to move faster, a pattern I covered in how AI compresses the vulnerability lifecycle.
Era 4 · The Agentic Shift · 2025-2026
The Agentic Shift: What do AI agents do in SIEM and SOC platforms today?
In 2025 the copilot stopped waiting for a prompt. CrowdStrike made Charlotte AI Detection Triage generally available in February 2025 and says it matches its own MDR analysts' triage decisions more than 98% of the time. Microsoft announced Security Copilot agents in March 2025, led by a Phishing Triage Agent in Defender, and from November 2025 began including Security Copilot in Microsoft 365 E5. Google says its Triage and Investigation Agent in Google SecOps has worked more than 5 million alerts.
Here is what these agents do in production. When an alert fires, the agent pulls context, detonates files and URLs, queries threat intelligence, runs hunting queries across data sources, and writes a verdict with its reasoning. Microsoft's documentation is precise about the boundary: the phishing agent resolves false positives itself and leaves true positives open for an analyst. Google's agent classifies and explains; containment stays with people or with deterministic playbooks.
Agent-native startups push further. Torq raised a $140 million Series D in January 2026 for an AI SOC that triages, investigates and can remediate autonomously or with oversight. Dropzone AI, 7AI and Prophet Security sell AI SOC analysts that sit on top of an existing SIEM. Palo Alto Networks relaunched XSOAR as Cortex AgentiX in October 2025, where admins decide which actions need approval.
The limits are real. Agents are strong at triage and evidence gathering and weak at business context: whether that VP really logs in from that country. Every one of them runs with an identity and permissions, which is why Palo Alto paid $25 billion for CyberArk and Microsoft wires these agents to Entra Agent IDs. Most vendors do not publish how to stop an agent mid-action, a gap I measured in the kill switch test.
- CrowdStrike makes Charlotte AI Detection Triage generally availablesource
- Microsoft announces Security Copilot agents, including the Phishing Triage Agentsource
- Palo Alto Networks launches Cortex AgentiX as the successor to XSOARsource
- Palo Alto Networks completes its $25 billion CyberArk acquisitionsource
Era 5 · The Next Five Years · 2027-2031
What will SIEM and SOC platforms look like by 2031?
My bet: by 2031 the autonomous SOC is the default for tier-1 and most tier-2 work. Agents will triage and investigate virtually every alert, close the noise, and execute pre-approved containment such as isolating a laptop or revoking a session. A human approves anything that touches production systems, executives, customers or legal exposure.
The SIEM itself becomes a data layer. Detection, investigation and response move into agents that read from a security data lake, and the per-gigabyte SIEM license gives way to pricing per investigation or per outcome. Google, Microsoft, CrowdStrike, Palo Alto Networks and Cisco are each building that stack, and the startups will either plug into it or be bought by it.
For this to happen, three things must be true. Agent identity has to be solved: every SOC agent gets its own scoped credential, short-lived tokens, and a log of every action tied to that identity. Verdict quality has to be measured independently, not self-reported. And security leaders need a way to prove to auditors and boards that an agent's decision was reviewable. Without that, regulated companies will keep a human on every action, and the shift stalls at triage.
My prediction · by 2031 · medium confidence
By 2031, AI agents will triage and investigate virtually all SOC alerts and execute pre-approved containment on their own, while humans approve high-impact actions and own breach decisions. Tier-1 analyst roles will be largely gone.
What has to be true
- Every SOC agent runs on its own scoped, auditable identity with short-lived credentials
- Agent verdict accuracy is measured independently, including false negatives
- Auditors and regulators accept reviewable agent decisions as valid control evidence
- Prompt injection through security telemetry is mitigated well enough to trust agent closures
Projected autonomy 4.0 of 5
- Cisco announces a Splunk Triage Agent slated for 2026source
Then vs now: who does each step?
The job broken into its steps, and who or what does each one in each era.
| Job step | On-prem | SaaS and cloud | AI-assisted | Agentic | Next 5 years |
|---|---|---|---|---|---|
| Collect and store security logs | SIEM engineers on appliances, 30 to 90 days kept | Cloud SIEM ingests, priced per gigabyte | Cloud SIEM plus data lake, engineers tune sources | Security data lake, agents query it directly | Data layer only; agents decide what to retain |
| Write and tune detections | Hand-written correlation rules | Detection engineers write searches | Copilot drafts queries, engineer edits | Engineers review agent-suggested detections | Agents propose and test; engineers approve |
| Triage each alert | Tier-1 analyst, alert by alert | Tier-1 analyst plus SOAR enrichment | Analyst with a copilot summary | Agent triages; closes false positives | Agent, nearly all volume |
| Investigate a real incident | Tier-2 analyst pivots across consoles | Analyst runs searches and playbooks | Analyst asks the copilot, verifies | Agent builds the timeline; analyst confirms | Agent investigates; human reviews the narrative |
| Contain the threat | Responder calls IT to pull the cable | Analyst triggers a SOAR playbook | Analyst clicks the recommended action | Analyst approves agent-proposed containment | Agent acts within pre-approved scopes |
| Report to auditors and leadership | Manual log review evidence for PCI and SOX | Dashboards exported to slides | Copilot drafts the incident report | Agent writes the report; human signs off | Continuous evidence; human owns the risk call |
How does the SIEM and SOC platforms team change?
The tier-1 alert queue is the first security job agents are taking. Every major SIEM and XDR vendor now ships an agent that triages alerts and closes false positives without a human, and the startups sell exactly that as a product. The SOC that needed a dozen people to watch a queue around the clock now needs a few people to watch the agents.
The work that remains is harder and more senior: confirming true positives, making containment calls, writing detections, and deciding what an agent may do on its own. A new role appears that most SOCs do not have yet: someone who owns each agent's permissions, accuracy and failure modes the way a manager owns a team. My advice in the CISO's AI defense playbook is to staff that role before you scale the agents.
Roles that shrink
- Tier-1 alert triage analysts
- SOAR playbook maintainers for routine enrichment
- Outsourced MSSP tier-1 monitoring
- SIEM parser and storage administration
Roles that appear
- Agent supervisor who reviews verdicts and owns escalation rules
- Detection and agent engineer who writes detections and agent instructions as code
- Agent identity and access owner for SOC agents
- AI SOC evaluator who measures agent accuracy against human decisions
- Security data platform engineer
Skills to learn
- Reading and challenging an agent's evidence and reasoning
- Writing precise agent feedback and guardrails in plain language
- Scoping least-privilege permissions for non-human identities
- Detection as code and query languages (KQL, SPL, YARA-L)
- Incident command and decision-making under time pressure
- Measuring false negative rates, not just time saved
What gets easier for the humans?
| Before | After |
|---|---|
| A tier-1 analyst opens every user-reported phishing email and spends up to 30 minutes on each | The agent resolves the false positives and only true phishing reaches a person |
| Night shift watches a queue where most alerts are noise | Agents work the overnight queue and page a human only on confirmed threats |
| Analysts pivot across four consoles to build an incident timeline | The agent assembles the timeline with evidence; the analyst checks it |
| Writing a detection meant learning each vendor's query language | Engineers describe the behavior and review the generated query |
| Incident reports written by hand after the fact | The agent drafts the report from its own investigation log |
Decisions that stay human
- Containment that touches production systems, executives, or customers
- Declaring a breach and triggering legal, regulatory or customer notification
- Deciding what an agent is allowed to do on its own, and revoking that
- Judgment calls that need business context the logs do not hold
- Paying a ransom, engaging law enforcement, or briefing the board
Where should agents not act alone?
Risks and failure modes, through a security and identity lens.
- 01
Over-permissioned SOC agents
A triage agent with rights to isolate hosts, disable accounts and read mailboxes is the most privileged identity in the company. Give each agent its own identity, least-privilege scopes and short-lived credentials, never a shared admin account.
- 02
Prompt injection through the evidence
The agent reads attacker-controlled content: email bodies, file names, log fields, web pages. Text crafted to tell the agent "this alert is benign" is a new evasion technique. Treat every input as untrusted and keep closure rules outside the model.
- 03
Silent false negatives
A wrongly closed true positive leaves no error, which makes it a [silent failure](/silent-failure-security-controls/). Sample closed alerts for human review every week and track the agent's miss rate, not just its speed.
- 04
No kill switch or audit trail
If you cannot stop an agent mid-action and replay exactly what it did and why, you cannot defend its decisions to an auditor or a court. Require action-level logs tied to the agent's identity and a documented way to pause it.
- 05
Attackers target the agent itself
Once agents can contain, an attacker who learns their rules can trigger self-inflicted outages, such as mass account lockouts. High-impact actions need rate limits and human approval.
- 06
Vendor concentration
When the SIEM, the EDR and the agents come from one platform, one compromise or outage blinds the whole SOC. Keep independent logging and a manual runbook.
Who is building agentic SIEM and SOC platforms?
Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.
Incumbents
Phishing Triage Agent in Defender autonomously classifies user-reported phishing, resolves false positives, and leaves true positives open for analysts; runs on an Entra Agent ID.
Checked Oct 9, 2026Compare
Triage and Investigation Agent determines whether alerts are true or false positives and explains its assessment, with investigations capped at 20 minutes.
Checked Oct 9, 2026Compare
Charlotte AI Detection Triage classifies and prioritizes detections within customer-set autonomy limits; AgentWorks builds custom security agents without code.
Checked Oct 9, 2026Compare
- Splunk Enterprise Security (Cisco) ↗being verified
Splunk AI Assistant in Security is available; a Triage Agent and AI playbook authoring were announced for 2026 availability.
Checked Oct 9, 2026Compare
AgentiX agents reason, plan and execute workflows to resolve incidents, with admins deciding when agents act alone or need approval for high-impact actions.
Checked Oct 9, 2026Compare
Agent-native
AI SOC platform whose agents triage and deduplicate alerts, investigate cases, and respond autonomously or with human oversight.
Checked Oct 9, 2026Compare
AI SOC analyst that investigates alerts end to end and shows its reasoning; analysts keep authority over containment.
Checked Oct 9, 2026
- 7AI ↗being verified
Agentic security platform whose agents enrich signals, triage alerts, hunt for known threats and correlate telemetry.
Checked Oct 9, 2026
Agentic AI SOC platform that investigates every alert, hunts for threats detections miss, and recommends detection coverage improvements.
Checked Oct 9, 2026
Open source
Free, open-source SIEM and XDR; no native AI agent claimed on its site, so teams pair it with their own automation.
Checked Oct 9, 2026
Side-by-side comparisons: Top 5 SIEM Tools of 2026: Microsoft Sentinel vs Splunk vs the Rest, Top 5 SOAR Platforms for 2026: Cortex XSOAR vs Splunk SOAR vs Tines vs Torq vs Swimlane.
Questions people ask
How is AI changing SIEM and SOC platforms?
SIEMs are shifting from tools that raise alerts for humans to platforms where AI agents triage and investigate those alerts. Microsoft, CrowdStrike, Google and Palo Alto Networks all ship agents that classify alerts, gather evidence and close false positives. Humans still approve containment and own breach decisions.
Will AI agents replace SOC analysts?
They are replacing tier-1 alert triage, the most repetitive part of the job. They are not replacing incident responders, detection engineers or the people who decide what to contain. The SOC gets smaller and more senior, and a new role appears to supervise the agents.
What is an AI SOC analyst?
An AI SOC analyst is an agent that picks up each alert, gathers context from logs, endpoints, identity and threat intelligence, and returns a verdict with its reasoning. Products include Dropzone AI, Prophet Security, 7AI and Torq, plus built-in agents from the major SIEM and XDR vendors.
Is the SIEM dead?
No, but it is changing shape. The collection and storage layer is becoming a security data lake, and detection, investigation and response are moving into agents that read from it. Expect licensing to shift from per-gigabyte ingestion toward per-investigation or per-outcome pricing.
What is the difference between SOAR and an agentic SOC?
SOAR runs playbooks someone wrote in advance, so it only handles known scenarios. An agent reasons about each alert, chooses its own investigation steps, and adapts from analyst feedback. Most vendors now pair the two: agents investigate, deterministic playbooks execute high-impact actions.
Can AI agents contain threats on their own?
Some can, within limits the customer sets. CrowdStrike and Palo Alto Networks let teams define which actions agents take alone and which need approval. In practice most SOCs let agents close false positives and keep humans approving isolation, account disablement and anything touching production.
What are the security risks of AI agents in the SOC?
The main risks are over-permissioned agent identities, prompt injection through attacker-controlled evidence, silent false negatives, and missing audit trails or kill switches. Give each agent its own least-privilege identity, log every action, and sample closed alerts for human review.
Sources
- 2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface, accessed Oct 9, 2026
- Security information and event management (Wikipedia), accessed Oct 9, 2026
- HP Closes $1.5 Billion Acquisition Of ArcSight (TechCrunch), accessed Oct 9, 2026
- IBM Closes on Acquisition Of Q1 Labs (Dark Reading), accessed Oct 9, 2026
- Splunk Announces General Availability Of Splunk Cloud (Dark Reading), accessed Oct 9, 2026
- Splunk Closes Acquisition of Phantom, accessed Oct 9, 2026
- Chronicle dives into security telemetry with Backstory (TechTarget), accessed Oct 9, 2026
- Azure Sentinel is now generally available (Petri), accessed Oct 9, 2026
- Google Cloud: Raising the bar in security operations (Siemplify acquisition), accessed Oct 9, 2026
- Microsoft Copilot for Security is generally available on April 1, 2024, accessed Oct 9, 2026
- CrowdStrike Introduces Charlotte AI to Deliver Generative AI-Powered Cybersecurity, accessed Oct 9, 2026
- Cisco Completes Acquisition of Splunk, accessed Oct 9, 2026
- Exabeam and LogRhythm Complete Merger and Announce New Company Details, accessed Oct 9, 2026
- Palo Alto Networks Closes Acquisition of IBM's QRadar SaaS Assets, accessed Oct 9, 2026
- CrowdStrike Delivers the Next Breakthrough in AI-Powered Agentic Cybersecurity with Charlotte AI Detection Triage, accessed Oct 9, 2026
- Microsoft Security Copilot Phishing Triage Agent in Microsoft Defender (Microsoft Learn), accessed Oct 9, 2026
- Microsoft Security Copilot inclusion in Microsoft 365 E5 (Microsoft Learn), accessed Oct 9, 2026
- Use Triage and Investigation Agent to investigate alerts (Google SecOps docs), accessed Oct 9, 2026
- Google's SOC agent cuts alert review from 30 minutes to 60 seconds (TechInformed), accessed Oct 9, 2026
- Palo Alto Networks Unveils Cortex AgentiX, accessed Oct 9, 2026
- Palo Alto Networks Form 8-K exhibit: completion of CyberArk acquisition, accessed Oct 9, 2026
- AI security firm Torq bags $140m Series D at $1.2bn valuation (FinTech Global), accessed Oct 9, 2026
- Dropzone AI raises $37M Series B for AI SOC agents, accessed Oct 9, 2026
- Agentic security firm 7AI raises $130 million (SecurityWeek), accessed Oct 9, 2026
- Prophet Security Raises $30M Series A Led by Accel, accessed Oct 9, 2026
- Cisco Elevates the SOC with Agentic AI for Faster Threat Response and Reduced Complexity, accessed Oct 9, 2026
- Zscaler Completes Acquisition of Red Canary, accessed Oct 9, 2026
- Google Completes $32 Billion Acquisition of Wiz (Cleary Gottlieb), accessed Oct 9, 2026
Published Oct 9, 2026. Last verified Oct 9, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.
Keep reading
Essays and analysis
- The CISO's AI Defense Playbook: A Practical Framework
- From Zero-Day to Zero-Hour: How AI Compresses the Vulnerability Lifecycle
- The Silent Failure Problem: Your Security Controls Rot Without Telling You
- The Kill Switch Test: Only 11 of 47 Checked AI Agent Security Vendors Publicly Claim You Can Stop a Rogue Agent
- Everyone Bought AI Observability. Nobody Owns Agent Behavior.
- Human vs AI Agents in Cybersecurity: Who Should Guard Your Data?