October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Databricks Targets Cybersecurity Tasks With Data Intelligence Platform and Lakewatch

Databricks is building a security lakehouse and agentic SIEM direction—not simply launching a drop-in SIEM. Here is what the products do, what remains unproven and how to evaluate them.
From TheFinanceBase Team8 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Databricks launched Data Intelligence for Cybersecurity on October 1, 2025, applying its lakehouse, analytics, governance and AI tools to security operations. It is not, by itself, a wholly separate replacement for a mature SIEM. The newer Lakewatch, announced on March 27, 2026, is Databricks’ explicitly agentic-SIEM direction and was still listed as being in Private Preview in the announcement reviewed.

The practical proposition is a security data lakehouse: retain more telemetry in open tables, normalize it, query it with data-engineering and machine-learning tools, and use governed agents to help with detection and investigation. Whether it is a good buy depends less on a headline ingestion number than on your data volume, SOC skills, governance requirements and tolerance for building detection operations.

What Databricks actually launched

Databricks’ October 1, 2025 announcement describes Data Intelligence for Cybersecurity as a security-focused solution on the existing Databricks Data Intelligence Platform and Lakehouse architecture. The package brings together security, IT and business data rather than introducing an entirely independent security stack.

Databricks’ premise is that cybersecurity is fundamentally a data problem: defenders need to retain, connect and analyze enormous volumes of events before they can reliably detect and investigate attacks. The launch combines ingestion, analytics, governance, integrations and AI-assisted workflows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

How the named components differ

  • Data Intelligence for Cybersecurity: the overall security solution and architecture built on Databricks.
  • Agent Bricks: tools for building governed, production-oriented AI agents for tasks such as triage, investigation and detection work.
  • Lakebase: an operational data layer Databricks positions for real-time threat intelligence, case management and vulnerability workflows.
  • AI/BI Genie and Databricks One: self-service, natural-language analysis, dashboards and access to governed data.
  • Lakewatch: the later product explicitly positioned as an open, agentic SIEM.

The distinction matters: the 2025 launch was a security platform layer on Databricks; Lakewatch is the subsequent SIEM-branded product.

Which security-operations tasks it targets

The platform is intended to support a broad SOC workflow rather than a single alert console.

  • Centralizing firewall, endpoint, XDR, identity, cloud, SaaS and operational logs.
  • Keeping long-lived, full-fidelity telemetry for retrospective investigations.
  • Searching heterogeneous data for threat hunting and incident reconstruction.
  • Creating, testing and tuning detections.
  • Prioritizing alerts and reducing false positives.
  • Enriching incidents with identity, asset, vulnerability and threat-intelligence context.
  • Supporting vulnerability and case-management processes.
  • Running natural-language queries and real-time or historical analytics.
  • Building agents for repetitive analyst work and connecting results to SIEM, SOAR, XDR or ticketing systems.

How the security lakehouse is supposed to work

Databricks’ security-lakehouse blueprint describes a Bronze/Silver/Gold pattern. A practical flow looks like this:

  1. Ingest: land raw events from cloud, endpoint, network, identity, SaaS and legacy systems.
  2. Store: keep the source data in scalable cloud storage, separating storage from compute.
  3. Normalize: convert vendor-specific records into consistent security schemas, increasingly including OCSF, while preserving useful source detail.
  4. Govern: apply Unity Catalog policies and fine-grained permissions to tables, rows, columns and attributes.
  5. Analyze: use Databricks SQL, streaming pipelines, dashboards, notebooks and machine-learning models for detections and investigations.
  6. Build agents: use Agent Bricks, Genie and related tools to assist with queries, triage and investigation.
  7. Connect actions: send findings or approved actions to existing SIEM, SOAR, XDR, case-management and security-vendor systems.

In this model, Bronze contains raw telemetry, Silver contains normalized and enriched events, and Gold contains detections, aggregates and analyst-facing outputs. The blueprint recommends versioned parser logic, consistent event_time handling and source metadata so data quality can be monitored rather than assumed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is different from a traditional SIEM?

Databricks emphasizes a data-platform model instead of a proprietary event repository. The claimed differences are:

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
  • Storage-compute separation: inexpensive, scalable storage can hold historical data while compute is used when queries or pipelines run.
  • Longer historical access: buyers can retain more raw telemetry for hunting and investigations instead of restricting analysis to premium hot tiers.
  • Open formats and standards: Lakewatch highlights OCSF, Delta Lake and Apache Iceberg.
  • Cross-domain analysis: security events can be queried alongside application, IT and business data where access policies permit.
  • Data-science tooling: SQL, streaming, notebooks and machine learning operate in the same environment.
  • Unified governance: data, models, dashboards and agents can be governed and audited together.

Open tables can reduce dependence on a proprietary event format, but they do not make the whole operating model portable. Compute, Unity Catalog, Databricks SQL, agents, cloud services and integrations may still be Databricks-specific.

Agent Bricks: assistance, not an autonomous SOC

Databricks presents Agent Bricks as a way to build secure, production-oriented agents grounded in enterprise data. Security uses include alert triage, investigation assistance, threat-hunting queries, detection creation, rule tuning and context gathering.

That positioning is a vendor capability claim, not independent evidence that agents can run a SOC without supervision. A safe deployment should separate read-only investigation from response actions and require:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Human approval before changing rules, isolating systems or taking other consequential actions.
  • Least-privilege data and tool permissions.
  • Complete prompts, tool-use and decision audit logs.
  • Evaluation on replayed, known incidents and representative false positives.
  • Defenses against prompt injection hidden in attacker-controlled logs.
  • Controls for data leakage, hallucinated conclusions and automation bias.

Lakewatch is the key 2026 update

On March 27, 2026, Databricks announced Lakewatch as an open, agentic SIEM. In the official announcement reviewed, Lakewatch was in Private Preview, so its announced capabilities should not be treated as generally available or production-proven.

  • OCSF normalization.
  • Support for Delta Lake and Apache Iceberg.
  • Unified security, IT and business data.
  • Table-, row-, column- and attribute-level access controls.
  • Full auditability.
  • Agentic workflows for ingestion, detection creation, rule tuning and threat investigation.
  • Decoupled storage and compute.

Lakewatch narrows the conceptual gap between Databricks’ security analytics platform and a security-native SIEM, but buyers should verify preview access, service limits, integrations and general-availability status before making a procurement or replacement claim.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

What customer evidence shows—and does not show

CRN reported Databricks naming Arctic Wolf, Palo Alto Networks, SAP, Barracuda Networks, Abnormal AI, Accenture Federal, Deloitte, Panther, Varonis, Securiti AI and Obsidian Security among customers or partners. Databricks executive Omar Khawaja also described deployments ranging from multiple terabytes to hundreds of terabytes per day, with some customers said to collect a petabyte or more daily. Those figures are vendor-reported and are not independent, standardized benchmarks.

Databricks event materials provide further examples:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • SAP Enterprise Cloud Services described a security data-lake operation handling 70 TB per day in a 2025 summit speaker profile.
  • Obsidian Security describes using Databricks for high-volume SaaS security telemetry and investigations.
  • JetBlue describes a security analytics platform using Delta Lake, Auto Loader and Databricks SQL for high-cardinality data and historical investigations.

Read the examples in context: they demonstrate possible scale and architectures, not a guaranteed ingestion cost, detection rate or investigation-time improvement for every buyer.

Deployment, pricing and total-cost reality

Databricks lists pay-as-you-go pricing with per-second billing, committed-use discounts and quote-based purchasing at its pricing page. It does not publish one universal cybersecurity subscription price. A two-week commercial trial with up to $400 in credits is described at the trial page; the Free Edition has limited features and daily usage limits.

Model the complete workload rather than comparing only ingestion rates:

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
  • Raw storage and retention duration.
  • Streaming, batch and SQL compute.
  • Pipeline orchestration and data-quality monitoring.
  • Agent and model inference.
  • Data egress and duplicated datasets.
  • Professional services and detection-engineering labor.
  • Existing SIEM licenses retained during a coexistence period.
  • Analyst time spent maintaining parsers, schemas and detections.

Storage-compute separation may help with large, infrequently queried archives. It may not lower costs when analysts run constant interactive searches, streaming pipelines stay active, agents are heavily used or poorly bounded queries scan years of data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where implementation commonly fails

It is not automatically a turnkey SOC

Organizations may still need detection content, parser maintenance, threat-intelligence feeds, case-management integrations, SOAR playbooks, 24/7 monitoring and incident-response expertise. Databricks’ own blueprint recommends using the lakehouse as a detection and enrichment engine while retaining SIEM/SOAR integrations where appropriate.

Normalization becomes the bottleneck

Vendor-specific fields, parser drift, duplicate events, inconsistent timestamps, missing identity context and incomplete asset inventories can undermine analytics. OCSF mapping can also discard details unless source fields are preserved. Establish versioned parsers, a standard event-time field, source metadata, validation checks and a monitored Bronze-to-Silver process.

AI creates new attack paths

Logs can contain malicious text designed to manipulate an agent. Excessive tool permissions, unapproved rule changes, unverifiable conclusions and natural-language data leakage are operational risks. Default agents to read-only access, isolate tools, require explicit approvals and retain evidence for every decision.

Databricks versus security-native alternatives

Option Primary strength Trade-off or best-fit boundary
Databricks security platform and Lakewatch Large-scale, open-format data foundation; custom analytics; data science; cross-domain queries; governed agents Requires data-platform and detection-engineering capability; Lakewatch availability and maturity must be verified
Microsoft Sentinel / Defender Integrated identity, endpoint and cloud operations for Microsoft-heavy estates Less compelling when the priority is an independent, multi-cloud data foundation
Google Security Operations Security-native analytics, detection and Google threat-intelligence ecosystem Optimized for buyers seeking a packaged security operations platform
Palo Alto Cortex XSIAM Tightly integrated endpoint, network and XDR operations Best suited to organizations prioritizing Palo Alto’s security portfolio
Splunk Enterprise Security Mature SIEM content and broad ecosystem Can entail substantial platform, skills and licensing commitments
Elastic Security Flexible search and analytics Requires teams prepared to operate Elastic infrastructure
CrowdStrike Falcon Endpoint, identity, threat intelligence and security operations Strongest where CrowdStrike’s security ecosystem is strategic
Arctic Wolf Managed detection and response Designed for organizations seeking a service rather than primarily operating a data platform
Panther Cloud-native security data lake and detection engineering More specialized than a broad enterprise data-and-AI platform

How to evaluate it

  1. Profile the data: measure daily ingest, source variety, retention, schema quality, streaming needs and data-residency constraints.
  2. Define the SOC outcome: decide whether the goal is cheaper historical hunting, custom detections, agent-assisted triage or a replacement console.
  3. Run a representative proof of concept: include raw and normalized logs, known incidents, false positives and existing response integrations.
  4. Measure operations: compare detection fidelity, investigation time, query cost, parser maintenance and analyst effort with the incumbent SIEM.
  5. Test governance and AI safety: verify tenant separation, masking, approvals, auditability, prompt-injection resistance and reproducibility.
  6. Price coexistence: include parallel SIEM operation, migration labor, cloud compute, storage, inference and professional services.
  7. Confirm availability: distinguish announced, demonstrated, Private Preview and generally available features before signing a production commitment.

Bottom line for buyers

Databricks is strongest when an organization wants a scalable security-data foundation, long-term telemetry retention, custom detection engineering, machine-learning workflows and security analysis alongside business data. It is a poor fit for a small SOC seeking a turnkey SIEM with packaged detections and minimal engineering.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Data Intelligence for Cybersecurity is best understood as a security-focused lakehouse and AI platform. Lakewatch could bring Databricks closer to a conventional SIEM, but its Private Preview status in the March 2026 announcement means buyers should validate production readiness, integrations and total cost before treating it as a replacement for a mature SIEM, MDR service or XDR platform.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.