Databricks completes acquisition of Panther
Databricks has completed its acquisition of Panther, merging the AI SOC platform with its Lakewatch agentic SIEM to accelerate the transition to open, petabyte-scale security lakehouses.

Databricks has finalized its acquisition of Panther, merging the security operations center (SOC) platform with Lakewatch, Databricks' agentic SIEM. This merger addresses a common industry pain point where legacy security information and event management (SIEM) systems force organizations to choose between escalating storage fees and restricted historical data retention. By combining Panther's software-driven detection engine with the open security lakehouse architecture of Lakewatch, the unified platform allows enterprises to store and analyze massive volumes of telemetry without facing proprietary vendor lock-in.
For security practitioners, this integration introduces several technical capabilities designed to modernize threat detection. The platform supports open standards including OCSF, Spark, Unity Catalog, Delta, Parquet, and SQL, ensuring that security data remains fully accessible across an enterprise's AI tooling. Security teams can leverage more than 100 out-of-the-box integrations and connectors spanning major cloud providers like AWS, Microsoft Azure, and Google Cloud, alongside identity systems like Okta and Entra ID. This setup enables the seamless ingestion and normalization of petabyte-scale telemetry directly into the lakehouse.
The combined offering transforms daily operations by shifting workflows toward software engineering practices. Instead of managing rigid, manual rules, engineers can implement detections-as-code, authoring and deploying threat detections through automated CI/CD pipelines. Furthermore, the platform deploys autonomous AI agents that run natively on the Databricks Data + AI platform. These agents actively triage alerts, conduct threat hunts, and correlate security events with business context like HR records and asset inventories, reducing analyst burnout by delivering highly enriched incident summaries instead of raw alert floods.
This is our own summary of reporting by Databricks AI



