Skip to content
Breaking:

Databricks Acquires SiftD.ai for Its Lakewatch Security Platform

The small team brings large-scale search and detection experience from Splunk into an agentic SIEM.

By The Company Wire Staff4 min read
Share
Databricks — Databricks Acquires SiftD.ai for Its Lakewatch Security Platform
Databricks — Databricks Acquires SiftD.ai for Its Lakewatch Security Platform. Photo via original source.

The center of gravity in the cybersecurity market shifted significantly this week as Databricks moved to dismantle the traditional silos separating enterprise data storage from high-stakes threat detection. The San Francisco-based data intelligence giant has officially acquired SiftD.ai, a specialized security startup composed of engineers who were instrumental in building the foundational search technology at Splunk. The deal, which closed on March 23, was formally announced the following day as the cornerstone of a much broader strategic pivot. With this acquisition, Databricks is launching Lakewatch, an agentic security information and event management platform designed to challenge the dominance of legacy incumbents by integrating security directly into the data lakehouse.

While financial terms of the deal were not disclosed, the strategic value of SiftD.ai lies in its pedigree. The young company brings a depth of experience in large-scale search, detection engineering, and threat analytics that is rare even in a crowded Silicon Valley talent pool. In the modern security operations center, the primary challenge is no longer just collecting data, but finding the proverbial needle in a haystack of petabyte-scale noise. Security teams are currently drowning in enormous streams of logs, and the ability to identify a small number of genuinely dangerous events requires the kind of sophisticated indexing and query optimization that the SiftD.ai team spearheaded during their tenure at Splunk.

Databricks is betting that by combining SiftD.ai’s search expertise with its own lakehouse architecture and emerging generative AI capabilities, it can create a more efficient defensive posture for its customers. Lakewatch is being positioned as an agentic platform, meaning it utilizes AI agents to autonomously investigate alerts rather than simply flagging them for human review. This shift toward autonomy is intended to address the chronic talent shortage in cybersecurity, where human analysts are often overwhelmed by the volume of telemetry generated by modern cloud infrastructure.

The acquisition of SiftD.ai did not happen in a vacuum. It was announced alongside Databricks' earlier purchase of Antimatter, revealing a calculated, multi-pronged assembly of a security stack. The two teams are tasked with addressing different, yet complementary, layers of the security problem. While Antimatter contributes specialized research into identity and authorization specifically for AI systems—ensuring that large language models do not leak sensitive permissions—SiftD.ai provides the heavy-duty plumbing for search and detection. By pursuing these dual acquisitions, Databricks is signaling that it lacks the patience for exclusively organic growth. The company is using targeted M&A to assemble a competitive security platform significantly faster than it could by building every layer internally from scratch.

This aggressive expansion represents a frontal assault on a market long led by established vendors including Microsoft, CrowdStrike, and Cisco’s Splunk. For years, the industry standard has been to move security data into a specialized SIEM, creating a secondary repository of information that often results in redundant costs and fragmented visibility. Databricks is now presenting a counter-argument that is gaining traction among budget-conscious Chief Information Officers: enterprise customers should analyze security information where their broader enterprise data already resides. By eliminating the need to move data between platforms, Databricks claims it can reduce duplication and lower the total cost of ownership for security operations.

However, the transition from a general-purpose data platform to a specialized security system of record is fraught with technical hurdles. To be successful, Lakewatch must provide more than just storage; it requires dependable ingestion of diverse log sources, lightning-fast queries for real-time incident response, and rigorous controls that strictly separate sensitive security records from ordinary business analytics work. Security data is inherently more sensitive than marketing or sales metrics, and the stakes for a breach within the monitoring platform itself are catastrophic.

Industry analysts note that the ultimate success of this venture will hinge on the successful integration of the SiftD.ai team. Because SiftD.ai was a small team, the acquisition’s long-term value will depend heavily on Databricks’ ability to retain these specialized engineers and grant them significant influence over the product roadmap. The challenge for Databricks is to take the highly specialized knowledge of these search experts and convert it into user-friendly tools that security teams can operate effectively without requiring extensive external consulting or professional services.

For Lakewatch to become a credible system of record in the eyes of Chief Information Security Officers, it must prove it can handle the rigors of a modern breach investigation. This means providing clear, actionable detection content, robust audit trails for compliance, and predictable performance even during periods of extreme data spikes. If Databricks can successfully fuse the SiftD.ai team's search pedigree with its own AI-driven lakehouse, it may well disrupt the fundamental economics of the SIEM market, forcing legacy vendors to justify why security data should remain isolated from the rest of the enterprise’s intelligence.

As the deal closes and the integration begins, the industry will be watching to see if Lakewatch can deliver on the promise of an agentic future. The marriage of Splunk-grade search technology with a modern data lakehouse marks a significant milestone in the evolution of the Silicon Valley data wars, making it clear that Databricks no longer views itself as just a data processing company, but as a central pillar of the enterprise defense strategy. The next few months will determine if this small team of search specialists can truly scale their vision within the vast machinery of the Databricks ecosystem.

Sources

  1. Databricks: Lakewatch Launch and SiftD.ai Acquisition
  2. TechCrunch: Databricks Bought Two Startups for Lakewatch

Company: Databricks

Written by

The Company Wire Staff

Newsroom · Silicon Valley

Reporting from The Company Wire newsroom. Staff bylines cover funding rounds, product launches and company news verified against primary sources.