{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"siem","name":"Security information & event management","short":"SIEM"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"siem-platforms","name":"SIEM platforms","scope":"Comparable offerings and editions; exclude managed service comparisons."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented-evidence stage of a shipped SIEM operating loop from collection through detection, investigation, and incident or case handling. Anchors describe presence of documented procedures, not observed quality or efficacy. A gap in public docs is unknown (null), not stage 0.","question":"Do current public docs describe a complete ingest-detect-investigate-incident loop as operator procedures, not marketing claims?","anchors":["Public documentation states that the offering does not provide a SIEM ingest-detect-investigate-incident operating loop.","Documentation describes collecting security telemetry and searching stored events.","Documentation describes scheduled or streaming detections that create alerts from queried telemetry.","Documentation describes aggregating alerts into incidents or cases with assignment, status, and review of contributing events.","Documentation describes operator workflows for grouping or enriching incidents, hunting related activity, and documented automation of incident handling under operator-defined conditions.","Documentation describes the stage-4 loop plus SIEM content lifecycle, data-tier or retention operations, and health or audit of collection and detection execution as shipped operator procedures."],"refinements":[{"base":3,"criteria":[{"id":"incident-enrichment","label":"Operator procedure for grouping or enriching incident context beyond initial alert aggregation","weight":3},{"id":"related-activity-hunting","label":"Hunt related activity beyond reviewing the events already attached to a case","weight":3},{"id":"conditional-incident-automation","label":"Automate incident handling under operator-defined conditions","weight":4}]},{"base":4,"criteria":[{"id":"content-lifecycle","label":"Install, update and manage active SIEM content","weight":3},{"id":"retention-operations","label":"Operate shipped data tiers or retention settings","weight":3},{"id":"collection-detection-health","label":"Monitor or audit collection and detection execution","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented-evidence stage of shipped SIEM workflows. Stage 3 is the ordinary current SIEM baseline (normalization, risk or correlation, retention) plus ingest, detect, investigate, and incident or case handling. Stage 4 requires a genuinely different shipped operator workflow beyond that baseline, excluding preview/Pre-GA features, unavailable edition paths, AI branding, and unique-market-first claims. Anchors are not observed quality; undocumented differentiation is unknown (null), not stage 0.","question":"Do current public docs describe a shipped operator workflow that is meaningfully different from ordinary SIEM normalization, risk or correlation, and retention?","anchors":["Public documentation states that the offering does not ship SIEM detection, correlation, investigation, or retention workflows.","Documentation describes collection and search only, without scheduled detections, correlation, or retention controls.","Documentation describes detections that create alerts but does not document the ordinary baseline of normalization, risk or correlation, and retention.","Documentation describes the ordinary current SIEM baseline: ingest with normalization, risk or correlation of alerts, investigation, incident or case handling, and retention.","Documentation describes a genuinely different shipped operator workflow beyond that ordinary baseline, with explicit edition constraints, and without relying on preview, Pre-GA, or edition-unavailable features.","Documentation describes multiple independently shipped beyond-baseline workflows with explicit edition boundaries, excluding preview, Pre-GA, AI branding, and unique-market-first claims."]},{"id":"breadth","name":"Capability breadth","description":"Documented-evidence stage of the SIEM surface — collection, detection classes, hunting, threat intelligence, entity context, and retention options — for the named edition. Anchors are capability presence in docs, not coverage quality or efficacy. Missing catalogs or ungated docs are unknown (null), not stage 0.","question":"Which SIEM capability classes does current documentation describe for the evaluated edition, without treating listings as coverage or efficacy?","anchors":["Public documentation states that the offering does not collect or analyze more than a single excluded or unsupported source class.","Documentation describes collection from a narrow native source set.","Documentation describes search across collected sources in addition to ingest.","Documentation describes detection content plus investigation views covering more than one security domain.","Documentation describes first-party and third-party collection, hunting, threat-intelligence matching, and entity context as part of the SIEM offering.","Documentation describes the stage-4 set plus multiple detection classes, retention or tier options, and packaged content, still as capability presence not efficacy."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented-evidence stage of connectors, parsers, content packs, custom ingest paths, and hooks from the SIEM into adjacent ticketing or automation systems. Anchors are not integration quality. An unfetched catalog is unknown (null), not stage 0.","question":"What first-party, third-party, and custom integration paths do current public docs describe for this SIEM edition?","anchors":["Public documentation states that the offering does not integrate with external telemetry or adjacent systems.","Documentation describes only the vendor's own telemetry sources.","Documentation describes third-party ingest through syslog, CEF, or an ingestion API.","Documentation describes a connector or parser catalog and bundled content that pairs sources with detections.","Documentation describes custom connector or parser development and automation hooks to adjacent ticketing or response systems.","Documentation describes a partner or content hub, custom connector frameworks, and multi-workspace or delegated-tenant operator patterns."]},{"id":"governance","name":"Governance & control","description":"Documented-evidence stage of operational safeguards such as RBAC, automation permission boundaries, data-scope controls, and audit of operator actions. Not observed security performance. Missing audit or data-scope procedures are unknown (null), not stage 0.","question":"Which access-control, approval, and audit safeguards do current public docs describe for this SIEM edition?","anchors":["Public documentation states that the SIEM does not provide role-based or audit controls for operators.","Documentation describes coarse instance or workspace access.","Documentation describes built-in SIEM roles that separate read, incident handling, and content editing.","Documentation describes RBAC for incidents, detections, and automation execution, plus an audit trail of operator actions.","Documentation describes least-privilege role guidance, automation service-account permission boundaries, and table-, scope-, or tier-level data access controls.","Documentation describes data-scope RBAC, automation permission isolation, audit of query or job activity, and explicit multi-tenant or MSSP permission patterns as documented controls, not observed security performance."]},{"id":"operations","name":"Operator enablement","description":"Documented-evidence stage of query language, rule authoring, triage, hunting, content lifecycle, and collection-health procedures. Anchors are not training quality or staffing outcomes. Ungated or unfetched procedures are unknown (null), not stage 0.","question":"What operator procedures for search, detection authoring, triage, hunting, and collection health do current public docs describe?","anchors":["Public documentation states that operators are not given search, triage, or detection-authoring procedures for this offering.","Overview documentation without procedures for search or triage.","Documentation describes a query language and an investigation user interface.","Documentation describes rule authoring, incident or finding triage, and hunting procedures.","Documentation describes content lifecycle (templates, versioning, or export/import), operational dashboards or workbooks, and connector or parser setup or health procedures.","Documentation describes detection-as-code or export, retention or job operations, collection-health monitoring, and operator task checklists as shipped procedures."]}],"assessments":[{"vendor":"microsoft-sentinel","cohort":"siem-platforms","edition":"Microsoft Sentinel cloud SIEM (Microsoft Defender portal; remaining Azure portal support until 31 March 2027). Not Defender XDR as a whole, not Security Copilot, and not Microsoft Sentinel MCP or graph as the scored offering.","asOf":"2026-09-21","status":"research-preview","summary":"Documented cloud SIEM loop of connectors, KQL analytics rules, incidents, hunting, and automation rules. Ordinary baseline includes ASIM normalization and incident correlation. Data-lake tiering is preview and Fusion is unavailable on the evaluated Defender-portal path, so those are not scored as differentiation.","dimensions":{"maturity":{"score":5,"confidence":"medium","rationale":"The incident, hunting and automation loop is supplemented by Content hub lifecycle procedures, shipped Log Analytics retention settings, connector-health monitoring and scheduled/NRT rule execution and change audit. This completes anchor 5 as a documentation stage. Health support has connector-specific limits; preview lake workflows are excluded.","sourceIds":["s4","s5","s8","s9","s11","baseline-retention","baseline-collection-health","baseline-rule-health","baseline-health-setup"]},"innovation":{"score":3,"confidence":"medium","rationale":"Fetched docs establish the ordinary current SIEM baseline: ASIM normalization, analytics-rule correlation of alerts into incidents, investigation, incident handling, and analytics-tier retention. No stage-4 novelty is claimed. Data-lake placement, KQL promotion jobs, and related table management are documented with preview labels and are excluded. Fusion multi-stage correlation is documented as unavailable after Defender-portal onboarding, which is the evaluated path. Copilot, MCP, and agentic-defense branding are not scored.","sourceIds":["s2","s4","s8","s10"]},"breadth":{"score":5,"confidence":"medium","rationale":"First- and third-party collection, hunting, entity context and threat-intelligence workflows are supplemented by scheduled and near-real-time detections, packaged Content hub content and shipped Log Analytics retention settings. These establish anchor 5. Legacy Fusion on the Defender portal and preview lake capabilities remain excluded.","sourceIds":["s4","s6","s9","s11","baseline-retention"]},"ecosystem":{"score":5,"confidence":"medium","rationale":"The connector/content hub, custom ingestion frameworks and ticket/response integrations are supplemented by published service-provider procedures for delegated customer workspaces and Defender portal access. Azure Lighthouse and GDAP have distinct requirements; delegated connector deployment is not assumed from Lighthouse alone. This establishes anchor 5 without changing product scope.","sourceIds":["s2","s6","s8","s11","baseline-mssp","baseline-mssp-defender"]},"governance":{"score":4,"confidence":"medium","rationale":"The non-lake Sentinel roles page documents Reader/Responder/Contributor and playbook roles, least-privilege guidance, explicit service-account permission on playbook resource groups, and resource-context or table-level RBAC for restricting workspace data. Incident activity records support the audit condition. Preview lake and unified-RBAC features are excluded.","sourceIds":["s3","s5","s8"]},"operations":{"score":4,"confidence":"medium","rationale":"Rule authoring/export, incident and hunting workflows, Content hub installation and connector setup establish anchor 4. The new health and retention procedures strengthen operator guidance, but this review does not establish the complete anchor-5 operator task checklist across the evaluated Defender-portal scope and connector set.","sourceIds":["s4","s5","s6","s8","s9","s11","baseline-collection-health","baseline-rule-health","baseline-retention"]}},"constraints":["Evaluated offering is Microsoft Sentinel cloud SIEM, not Microsoft Defender XDR, Security Copilot, or the Sentinel MCP/graph platform extras.","After 31 March 2027 Sentinel is documented as Defender-portal only; Azure portal remains documented until then.","Analytics-tier tables are required for analytics rules, hunting queries, parsers, playbooks, watchlists, and workbooks; lake-only tables do not run those SIEM features.","Fusion and Microsoft-security incident-creation rules are documented as unavailable after Defender-portal onboarding or Defender XDR incident integration.","Data-lake onboarding, graph, and some table-management experiences are documented with preview labels.","Playbooks are Azure Logic Apps with separate roles and resource-group permissions; they are not included merely by enabling Sentinel.","Connector support may be Microsoft, partner, or community; a connector listing is not evidence of complete parsing for every source version.","Connector-health tables cover supported connector types rather than every integration. Azure Lighthouse does not alone grant all customer connector deployment rights; GDAP and tenant-specific permissions may be required."],"sources":[{"id":"s1","title":"What is Microsoft Sentinel?","url":"https://learn.microsoft.com/en-us/azure/sentinel/sentinel-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"What is Microsoft Sentinel SIEM?","url":"https://learn.microsoft.com/en-us/azure/sentinel/overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Roles and permissions in the Microsoft Sentinel platform","url":"https://learn.microsoft.com/en-us/azure/sentinel/roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Threat detection in Microsoft Sentinel","url":"https://learn.microsoft.com/en-us/azure/sentinel/threat-detection","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Investigate Microsoft Sentinel incidents in the Azure portal","url":"https://learn.microsoft.com/en-us/azure/sentinel/investigate-incidents","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Microsoft Sentinel data connectors","url":"https://learn.microsoft.com/en-us/azure/sentinel/connect-data-sources","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Microsoft Sentinel data lake overview","url":"https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Automate threat response in Microsoft Sentinel with automation rules","url":"https://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Hunting capabilities in Microsoft Sentinel","url":"https://learn.microsoft.com/en-us/azure/sentinel/hunting","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s10","title":"Normalization and the Advanced Security Information Model (ASIM)","url":"https://learn.microsoft.com/en-us/azure/sentinel/normalization","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s11","title":"Discover and manage Microsoft Sentinel out-of-the-box content","url":"https://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-deploy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-collection-health","title":"Monitor data connector health","url":"https://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-rule-health","title":"Monitor analytics rule integrity and execution","url":"https://learn.microsoft.com/en-us/azure/sentinel/monitor-analytics-rule-integrity","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-health-setup","title":"Enable Microsoft Sentinel health and audit monitoring","url":"https://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-retention","title":"Configure data retention and archive","url":"https://learn.microsoft.com/en-us/azure/sentinel/configure-data-retention-archive","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-mssp","title":"Manage multiple tenants as a service provider","url":"https://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-mssp-defender","title":"Microsoft Defender portal guidance for managed security providers","url":"https://learn.microsoft.com/en-us/defender-xdr/playbook-managed-security","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Microsoft Sentinel","company":"Microsoft","profileUrl":"/landscape/vendors/microsoft-sentinel/"},{"vendor":"splunk-enterprise-security","cohort":"siem-platforms","edition":"Splunk Enterprise Security 8 Essentials (SIEM/TDIR on Splunk Cloud Platform or Splunk Enterprise). Not Splunk Enterprise Security Premier (native SOAR, UEBA, Attack Analyzer), not Splunk Observability, and not standalone Splunk SOAR.","asOf":"2026-09-21","status":"research-preview","summary":"Captured Essentials feature pages describe detections and investigation capabilities. Full ES 8 operating and permission procedures did not fetch, so affected research stages remain unknown; broader Splunk-platform capabilities are not assumed.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"Full ES 8 detection-authoring and queue procedures now establish findings, investigation context, ownership and status handling within the Essentials SIEM scope. This closes the initial operating-loop evidence gap at anchor 3. A complete scoped enrichment, related hunting and conditional incident-automation procedure is not established for anchor 4; Premier SOAR is excluded.","sourceIds":["s2","s4","s5"]},"innovation":{"score":null,"confidence":"low","rationale":"Feature pages and help snippets support risk correlation, finding aggregation and investigation as established SIEM workflows. This pass did not fully establish the normalization and retention conditions in the baseline anchor for the selected edition, so the stage remains unknown. No novel workflow is inferred from risk-based alerting or AI branding.","sourceIds":["s1","s2","s4","s6"]},"breadth":{"score":3,"confidence":"low","rationale":"Essentials documentation describes SIEM detections, dashboards (security posture, incident review, risk analysis), MITRE mapping, threat intelligence management, Detection Studio, and adaptive response. Hunting-style asset investigator and security-domain dashboards are listed on the features page. Stage 4 is not claimed for this edition: first-party plus third-party collection is assumed via the Splunk platform rather than an ES-specific connector catalog in the fetched pages, and UEBA is Premier.","sourceIds":["s1","s2"]},"ecosystem":{"score":null,"confidence":"low","rationale":"Stage 3 requires a connector or parser catalog and bundled content that pairs sources with detections. Fetched product and features pages and the docs.splunk.com landing do not provide that catalog; CIM documentation redirected and was not fetched. Third-party syslog/CEF/API ingest is implied by Splunk-platform marketing copy and is not treated as a fully supported stage-2 procedure. The gap is unknown, not stage 0.","sourceIds":["s1","s2","s3"]},"governance":{"score":2,"confidence":"medium","rationale":"The full roles table now establishes distinct read, analyst handling and administrative configuration roles. Queue membership is a workflow view, not a data-access boundary. Operator-audit coverage and scoped automation permissions are not fully established for anchor 3; the roles guide also warns of core-resource access outside ES controls.","sourceIds":["s7","s5"]},"operations":{"score":null,"confidence":"low","rationale":"Full detection-authoring and queue procedures now establish rule creation and triage. A complete current hunting procedure for the Essentials scope was not captured, so all conditions of anchor 3 remain unverified. Product feature lists do not fill that gap.","sourceIds":["s2","s4","s5"]}},"constraints":["Evaluated edition is Enterprise Security 8 Essentials, not Premier and not the full Splunk portfolio.","Product FAQ states Essentials includes SIEM, AI Assistant where available, and Detection Studio; Premier adds native SOAR, UEBA, and Automated Threat Analysis.","ES 8 terminology (findings, analyst queue, detections) replaces notables and incident review; older ES 7 docs on docs.splunk.com redirect to help.splunk.com and specific 7.3.2 topics returned 'does not exist'.","help.splunk.com deep articles did not return full bodies to web_fetch (Heretto portal error); several scores rest on search snippets plus marketing feature pages.","Adaptive Response is documented as a foundation before Splunk SOAR; it is not evidence that Essentials includes SOAR case management.","Cisco ownership does not establish shared entitlement with other Cisco products.","ES roles documentation warns that trusted authenticated users can reach certain core Splunk resources outside ES controls. Analyst queues organize work; they do not enforce data-access separation."],"sources":[{"id":"s1","title":"Splunk Enterprise Security product page","url":"https://www.splunk.com/en_us/products/enterprise-security.html","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"Splunk Enterprise Security Essentials features","url":"https://www.splunk.com/en_us/products/splunk-enterprise-security-essentials-features.html","accessedAt":"2026-09-21","kind":"product"},{"id":"s3","title":"Splunk Enterprise Security documentation landing (docs.splunk.com)","url":"https://docs.splunk.com/Documentation/ES","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Use detections to search for threats in Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/detections/create-event-based-detections-in-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Manage analyst workflows using the analyst queue in Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.6/mission-control/analyst-and-team-based-queues-in-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Using entity risk scores for detections in Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.3/risk-based-alerting/using-entity-risk-scores-for-detections-in-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Users and roles for Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/install/8.7/installation/users-and-roles-for-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Splunk Enterprise Security","company":"Cisco","profileUrl":"/landscape/vendors/splunk-enterprise-security/"},{"vendor":"google-security-operations-siem","cohort":"siem-platforms","edition":"Google Security Operations Standard package, SIEM focus with included base SOAR; Pre-GA enhanced Cases excluded","asOf":"2026-09-21","status":"research-preview","summary":"Standard documents normalized ingestion, detection and search, and includes base SOAR. The legacy case workflow supports analyst assignment and event review; enhanced Pre-GA Cases is excluded. Package-wide permission boundaries remain an evidence gap.","dimensions":{"maturity":{"score":3.7,"confidence":"medium","rationale":"Legacy case ownership, status and alert review establish stage 3. Current UDM hunting procedures add 0.3 and Standard-included conditional playbook handling adds 0.4. Incident enrichment beyond initial grouping is not established in this pass, so the score is 3.7. Enhanced Cases and Enterprise-only capabilities are excluded.","sourceIds":["s3","s5","s11","s4","s12"],"refinement":{"base":3,"evidence":[{"criterion":"related-activity-hunting","rationale":"UDM search procedures let an analyst query additional telemetry, alter the time range and refine results beyond events already attached to an alert. Standard includes SIEM search and investigation.","sourceIds":["s4","s5"]},{"criterion":"conditional-incident-automation","rationale":"The included base SOAR supports playbooks with configured triggers and actions; the current overview explains automatic attachment to matching alerts and activation. This credit uses legacy alert playbooks, not Pre-GA enhanced Cases.","sourceIds":["s5","s12"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"UDM normalization, rules, investigation/search, the included legacy case workflow and Standard retention establish the ordinary current SIEM baseline. This is not a novelty claim. Pre-GA composite detections and enhanced Cases are excluded.","sourceIds":["s2","s3","s4","s5","s11"]},"breadth":{"score":4,"confidence":"medium","rationale":"The Standard scope documents third-party ingestion, normalized UDM events across endpoint/network/identity domains, YARA-L detection, search, investigative entity context and threat-intelligence matching. Curated detections, UEBA and Gemini in higher packages do not support this score.","sourceIds":["s1","s2","s3","s5","s10"]},"ecosystem":{"score":null,"confidence":"low","rationale":"Standard includes base SOAR and an integration catalog, and SIEM ingestion/parsers are documented. The current package table inconsistently lists a subset of curated rules while separately excluding Google Curated Detections for Standard. This review cannot establish the required scoped source-to-detection content pairing at anchor 3; the evidence gap remains unknown.","sourceIds":["s1","s5","s9"]},"governance":{"score":null,"confidence":"low","rationale":"The data-RBAC guide explicitly warns that SIEM scopes do not automatically protect SOAR data and documents additional case/search exceptions. Feature IAM alone does not establish the complete Standard SIEM-plus-base-SOAR governance path; scoped role/audit mapping remains unverified. No cross-workflow control is inferred from SIEM RBAC.","sourceIds":["s6","s8"]},"operations":{"score":3,"confidence":"medium","rationale":"Rules, UDM search and investigation procedures support a documented authoring and analyst workflow. The captured evidence does not establish every lifecycle and dashboard condition for stage 4.","sourceIds":["s3","s4","s9","s10"]}},"constraints":["Standard includes base SOAR; excluded or unverified workflows are evidence gaps, not claims of product absence.","Pre-GA enhanced Cases and composite detections are not evidence of generally available workflow stages.","Verify package entitlements and SIEM/SOAR access boundaries together; data RBAC on SIEM alone does not establish all case visibility rules.","Parser coverage and retention requirements need source-specific validation."],"sources":[{"id":"s1","title":"Google Security Operations SIEM platform overview","url":"https://docs.cloud.google.com/chronicle/docs/overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"UDM overview","url":"https://docs.cloud.google.com/chronicle/docs/event-processing/udm-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Detection rules overview","url":"https://docs.cloud.google.com/chronicle/docs/detection/default-rules","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Understand search","url":"https://docs.cloud.google.com/chronicle/docs/investigation/udm-search","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Google SecOps packages overview","url":"https://docs.cloud.google.com/chronicle/docs/secops/secops-packages","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Data RBAC impact on features overview","url":"https://docs.cloud.google.com/chronicle/docs/administration/datarbac-impact","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Composite detections overview","url":"https://docs.cloud.google.com/chronicle/docs/detection/composite-detections","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Configure feature access","url":"https://docs.cloud.google.com/chronicle/docs/onboard/configure-feature-access","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Check data ingestion health","url":"https://docs.cloud.google.com/chronicle/docs/ingestion/ingestion-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s10","title":"Single and multiple event rules in YARA-L","url":"https://docs.cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s11","title":"Google SecOps legacy investigation and case management","url":"https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s12","title":"Playbook and automation overview","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/whats-on-the-playbooks-screen","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Google Security Operations SIEM","company":"Google / Alphabet","profileUrl":"/landscape/vendors/google-security-operations-siem/"}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small in-house team must operate one SIEM without a dedicated detection-engineering bench. The scenario highlights operator workload and integration upkeep. It does not change research scores or declare any offering eligible.","priorities":["operations","ecosystem"],"questions":["Who will maintain parsers or connectors when a source version changes, and what health signal shows that collection stopped?","Which query language (KQL, SPL, YARA-L) does the team already know well enough to tune detections without a vendor professional-services engagement?","Which incident-automation actions are included in the named edition versus a separate SOAR or Logic Apps entitlement?"]},{"id":"hybrid-telemetry","name":"Hybrid and third-party telemetry","description":"An organization needs detections across cloud-provider logs, identity, and non-vendor firewall or endpoint sources. The scenario asks what to validate in connectors and access control. It does not rewrite scores.","priorities":["breadth","ecosystem","governance"],"questions":["For each planned third-party source, which connector or parser version is documented, and which fields survive normalization (ASIM, CIM, or UDM)?","If analysts should see only some tables or data scopes, is table-level, queue-level, or data-RBAC control documented for the proposed edition?","Does onboarding the SIEM to an adjacent XDR or SOAR portal disable SIEM-native incident-creation rules that the design assumed?"]}],"researchNotes":["Cohort siem-platforms compares SIEM platform offerings and named editions only. Managed detection and response, MSSP operating models, and SOAR-only products are out of cohort scope even when a vendor sells them alongside SIEM.","Anchors are documented-evidence stages, not observed product quality, efficacy, or completeness. Stage 0 is only for affirmative documented absence of the scoped capability. Missing public docs, failed fetches, gated docs, or preview/Pre-GA-only procedures are unknown (null), never zero.","Shipped innovation stage 3 is the ordinary current SIEM baseline: ingest with normalization, risk or correlation, investigation, incident or case handling, and retention. Stage 4 requires a genuinely different shipped operator workflow beyond that baseline. Preview, Pre-GA, edition-unavailable paths, AI branding, and unique-market-first claims are excluded from stage 4+. Undifferentiated ordinary SIEM work is scored 3 with no novelty claim, or null if the full baseline is not documented.","This edition researches Microsoft Sentinel, Splunk Enterprise Security and Google Security Operations. Other field-guide offerings remain unassessed. Coverage is a research sample, not evidence of market leadership.","ibm-qradar remains unassessed as the continuing IBM self-managed QRadar SIEM. Retired QRadar cloud / QRadar SaaS is not treated as a live cloud SIEM pilot. Palo Alto Networks acquisition of QRadar SaaS assets does not make Cortex XSIAM a scored substitute in this file.","Google SecOps Standard includes base SOAR. Reviewed legacy case procedures support the baseline case workflow; package-wide permissions and connector/content pairing remain gaps. Enhanced Cases is Pre-GA and excluded.","Scope limitation: Microsoft publishes both a Sentinel SIEM and a Sentinel 'platform' (data lake, graph, MCP). Conservative interpretation: score cloud SIEM incident/automation procedures; do not score MCP, Security Copilot, agentic defense, preview data-lake management, or Fusion (unavailable after Defender-portal onboarding) as innovation.","Detailed Splunk Enterprise Security 8 procedure pages were inaccessible during review. Product pages and available search excerpts support limited, low-confidence judgments; unsupported control and integration details remain unknown.","Confidence is at most medium because this is public-documentation research, not a lab or customer-tenant assessment. Splunk cells use low confidence because inference from snippets and product pages is material.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."],"history":{"segment":"siem","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"siem","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"siem-platforms","name":"SIEM platforms","scope":"Comparable offerings and editions; exclude managed service comparisons."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented-evidence stage of a shipped SIEM operating loop from collection through detection, investigation, and incident or case handling. Anchors describe presence of documented procedures, not observed quality or efficacy. A gap in public docs is unknown (null), not stage 0.","question":"Do current public docs describe a complete ingest-detect-investigate-incident loop as operator procedures, not marketing claims?","anchors":["Public documentation states that the offering does not provide a SIEM ingest-detect-investigate-incident operating loop.","Documentation describes collecting security telemetry and searching stored events.","Documentation describes scheduled or streaming detections that create alerts from queried telemetry.","Documentation describes aggregating alerts into incidents or cases with assignment, status, and review of contributing events.","Documentation describes operator workflows for grouping or enriching incidents, hunting related activity, and documented automation of incident handling under operator-defined conditions.","Documentation describes the stage-4 loop plus SIEM content lifecycle, data-tier or retention operations, and health or audit of collection and detection execution as shipped operator procedures."],"refinements":[{"base":3,"criteria":[{"id":"incident-enrichment","label":"Operator procedure for grouping or enriching incident context beyond initial alert aggregation","weight":3},{"id":"related-activity-hunting","label":"Hunt related activity beyond reviewing the events already attached to a case","weight":3},{"id":"conditional-incident-automation","label":"Automate incident handling under operator-defined conditions","weight":4}]},{"base":4,"criteria":[{"id":"content-lifecycle","label":"Install, update and manage active SIEM content","weight":3},{"id":"retention-operations","label":"Operate shipped data tiers or retention settings","weight":3},{"id":"collection-detection-health","label":"Monitor or audit collection and detection execution","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented-evidence stage of shipped SIEM workflows. Stage 3 is the ordinary current SIEM baseline (normalization, risk or correlation, retention) plus ingest, detect, investigate, and incident or case handling. Stage 4 requires a genuinely different shipped operator workflow beyond that baseline, excluding preview/Pre-GA features, unavailable edition paths, AI branding, and unique-market-first claims. Anchors are not observed quality; undocumented differentiation is unknown (null), not stage 0.","question":"Do current public docs describe a shipped operator workflow that is meaningfully different from ordinary SIEM normalization, risk or correlation, and retention?","anchors":["Public documentation states that the offering does not ship SIEM detection, correlation, investigation, or retention workflows.","Documentation describes collection and search only, without scheduled detections, correlation, or retention controls.","Documentation describes detections that create alerts but does not document the ordinary baseline of normalization, risk or correlation, and retention.","Documentation describes the ordinary current SIEM baseline: ingest with normalization, risk or correlation of alerts, investigation, incident or case handling, and retention.","Documentation describes a genuinely different shipped operator workflow beyond that ordinary baseline, with explicit edition constraints, and without relying on preview, Pre-GA, or edition-unavailable features.","Documentation describes multiple independently shipped beyond-baseline workflows with explicit edition boundaries, excluding preview, Pre-GA, AI branding, and unique-market-first claims."]},{"id":"breadth","name":"Capability breadth","description":"Documented-evidence stage of the SIEM surface — collection, detection classes, hunting, threat intelligence, entity context, and retention options — for the named edition. Anchors are capability presence in docs, not coverage quality or efficacy. Missing catalogs or ungated docs are unknown (null), not stage 0.","question":"Which SIEM capability classes does current documentation describe for the evaluated edition, without treating listings as coverage or efficacy?","anchors":["Public documentation states that the offering does not collect or analyze more than a single excluded or unsupported source class.","Documentation describes collection from a narrow native source set.","Documentation describes search across collected sources in addition to ingest.","Documentation describes detection content plus investigation views covering more than one security domain.","Documentation describes first-party and third-party collection, hunting, threat-intelligence matching, and entity context as part of the SIEM offering.","Documentation describes the stage-4 set plus multiple detection classes, retention or tier options, and packaged content, still as capability presence not efficacy."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented-evidence stage of connectors, parsers, content packs, custom ingest paths, and hooks from the SIEM into adjacent ticketing or automation systems. Anchors are not integration quality. An unfetched catalog is unknown (null), not stage 0.","question":"What first-party, third-party, and custom integration paths do current public docs describe for this SIEM edition?","anchors":["Public documentation states that the offering does not integrate with external telemetry or adjacent systems.","Documentation describes only the vendor's own telemetry sources.","Documentation describes third-party ingest through syslog, CEF, or an ingestion API.","Documentation describes a connector or parser catalog and bundled content that pairs sources with detections.","Documentation describes custom connector or parser development and automation hooks to adjacent ticketing or response systems.","Documentation describes a partner or content hub, custom connector frameworks, and multi-workspace or delegated-tenant operator patterns."]},{"id":"governance","name":"Governance & control","description":"Documented-evidence stage of operational safeguards such as RBAC, automation permission boundaries, data-scope controls, and audit of operator actions. Not observed security performance. Missing audit or data-scope procedures are unknown (null), not stage 0.","question":"Which access-control, approval, and audit safeguards do current public docs describe for this SIEM edition?","anchors":["Public documentation states that the SIEM does not provide role-based or audit controls for operators.","Documentation describes coarse instance or workspace access.","Documentation describes built-in SIEM roles that separate read, incident handling, and content editing.","Documentation describes RBAC for incidents, detections, and automation execution, plus an audit trail of operator actions.","Documentation describes least-privilege role guidance, automation service-account permission boundaries, and table-, scope-, or tier-level data access controls.","Documentation describes data-scope RBAC, automation permission isolation, audit of query or job activity, and explicit multi-tenant or MSSP permission patterns as documented controls, not observed security performance."]},{"id":"operations","name":"Operator enablement","description":"Documented-evidence stage of query language, rule authoring, triage, hunting, content lifecycle, and collection-health procedures. Anchors are not training quality or staffing outcomes. Ungated or unfetched procedures are unknown (null), not stage 0.","question":"What operator procedures for search, detection authoring, triage, hunting, and collection health do current public docs describe?","anchors":["Public documentation states that operators are not given search, triage, or detection-authoring procedures for this offering.","Overview documentation without procedures for search or triage.","Documentation describes a query language and an investigation user interface.","Documentation describes rule authoring, incident or finding triage, and hunting procedures.","Documentation describes content lifecycle (templates, versioning, or export/import), operational dashboards or workbooks, and connector or parser setup or health procedures.","Documentation describes detection-as-code or export, retention or job operations, collection-health monitoring, and operator task checklists as shipped procedures."]}],"assessments":[{"vendor":"microsoft-sentinel","cohort":"siem-platforms","edition":"Microsoft Sentinel cloud SIEM (Microsoft Defender portal; remaining Azure portal support until 31 March 2027). Not Defender XDR as a whole, not Security Copilot, and not Microsoft Sentinel MCP or graph as the scored offering.","asOf":"2026-09-21","status":"research-preview","summary":"Documented cloud SIEM loop of connectors, KQL analytics rules, incidents, hunting, and automation rules. Ordinary baseline includes ASIM normalization and incident correlation. Data-lake tiering is preview and Fusion is unavailable on the evaluated Defender-portal path, so those are not scored as differentiation.","dimensions":{"maturity":{"score":5,"confidence":"medium","rationale":"The incident, hunting and automation loop is supplemented by Content hub lifecycle procedures, shipped Log Analytics retention settings, connector-health monitoring and scheduled/NRT rule execution and change audit. This completes anchor 5 as a documentation stage. Health support has connector-specific limits; preview lake workflows are excluded.","sourceIds":["s4","s5","s8","s9","s11","baseline-retention","baseline-collection-health","baseline-rule-health","baseline-health-setup"]},"innovation":{"score":3,"confidence":"medium","rationale":"Fetched docs establish the ordinary current SIEM baseline: ASIM normalization, analytics-rule correlation of alerts into incidents, investigation, incident handling, and analytics-tier retention. No stage-4 novelty is claimed. Data-lake placement, KQL promotion jobs, and related table management are documented with preview labels and are excluded. Fusion multi-stage correlation is documented as unavailable after Defender-portal onboarding, which is the evaluated path. Copilot, MCP, and agentic-defense branding are not scored.","sourceIds":["s2","s4","s8","s10"]},"breadth":{"score":5,"confidence":"medium","rationale":"First- and third-party collection, hunting, entity context and threat-intelligence workflows are supplemented by scheduled and near-real-time detections, packaged Content hub content and shipped Log Analytics retention settings. These establish anchor 5. Legacy Fusion on the Defender portal and preview lake capabilities remain excluded.","sourceIds":["s4","s6","s9","s11","baseline-retention"]},"ecosystem":{"score":5,"confidence":"medium","rationale":"The connector/content hub, custom ingestion frameworks and ticket/response integrations are supplemented by published service-provider procedures for delegated customer workspaces and Defender portal access. Azure Lighthouse and GDAP have distinct requirements; delegated connector deployment is not assumed from Lighthouse alone. This establishes anchor 5 without changing product scope.","sourceIds":["s2","s6","s8","s11","baseline-mssp","baseline-mssp-defender"]},"governance":{"score":4,"confidence":"medium","rationale":"The non-lake Sentinel roles page documents Reader/Responder/Contributor and playbook roles, least-privilege guidance, explicit service-account permission on playbook resource groups, and resource-context or table-level RBAC for restricting workspace data. Incident activity records support the audit condition. Preview lake and unified-RBAC features are excluded.","sourceIds":["s3","s5","s8"]},"operations":{"score":4,"confidence":"medium","rationale":"Rule authoring/export, incident and hunting workflows, Content hub installation and connector setup establish anchor 4. The new health and retention procedures strengthen operator guidance, but this review does not establish the complete anchor-5 operator task checklist across the evaluated Defender-portal scope and connector set.","sourceIds":["s4","s5","s6","s8","s9","s11","baseline-collection-health","baseline-rule-health","baseline-retention"]}},"constraints":["Evaluated offering is Microsoft Sentinel cloud SIEM, not Microsoft Defender XDR, Security Copilot, or the Sentinel MCP/graph platform extras.","After 31 March 2027 Sentinel is documented as Defender-portal only; Azure portal remains documented until then.","Analytics-tier tables are required for analytics rules, hunting queries, parsers, playbooks, watchlists, and workbooks; lake-only tables do not run those SIEM features.","Fusion and Microsoft-security incident-creation rules are documented as unavailable after Defender-portal onboarding or Defender XDR incident integration.","Data-lake onboarding, graph, and some table-management experiences are documented with preview labels.","Playbooks are Azure Logic Apps with separate roles and resource-group permissions; they are not included merely by enabling Sentinel.","Connector support may be Microsoft, partner, or community; a connector listing is not evidence of complete parsing for every source version.","Connector-health tables cover supported connector types rather than every integration. Azure Lighthouse does not alone grant all customer connector deployment rights; GDAP and tenant-specific permissions may be required."],"sources":[{"id":"s1","title":"What is Microsoft Sentinel?","url":"https://learn.microsoft.com/en-us/azure/sentinel/sentinel-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"What is Microsoft Sentinel SIEM?","url":"https://learn.microsoft.com/en-us/azure/sentinel/overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Roles and permissions in the Microsoft Sentinel platform","url":"https://learn.microsoft.com/en-us/azure/sentinel/roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Threat detection in Microsoft Sentinel","url":"https://learn.microsoft.com/en-us/azure/sentinel/threat-detection","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Investigate Microsoft Sentinel incidents in the Azure portal","url":"https://learn.microsoft.com/en-us/azure/sentinel/investigate-incidents","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Microsoft Sentinel data connectors","url":"https://learn.microsoft.com/en-us/azure/sentinel/connect-data-sources","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Microsoft Sentinel data lake overview","url":"https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Automate threat response in Microsoft Sentinel with automation rules","url":"https://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Hunting capabilities in Microsoft Sentinel","url":"https://learn.microsoft.com/en-us/azure/sentinel/hunting","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s10","title":"Normalization and the Advanced Security Information Model (ASIM)","url":"https://learn.microsoft.com/en-us/azure/sentinel/normalization","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s11","title":"Discover and manage Microsoft Sentinel out-of-the-box content","url":"https://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-deploy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-collection-health","title":"Monitor data connector health","url":"https://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-rule-health","title":"Monitor analytics rule integrity and execution","url":"https://learn.microsoft.com/en-us/azure/sentinel/monitor-analytics-rule-integrity","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-health-setup","title":"Enable Microsoft Sentinel health and audit monitoring","url":"https://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-retention","title":"Configure data retention and archive","url":"https://learn.microsoft.com/en-us/azure/sentinel/configure-data-retention-archive","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-mssp","title":"Manage multiple tenants as a service provider","url":"https://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-mssp-defender","title":"Microsoft Defender portal guidance for managed security providers","url":"https://learn.microsoft.com/en-us/defender-xdr/playbook-managed-security","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"splunk-enterprise-security","cohort":"siem-platforms","edition":"Splunk Enterprise Security 8 Essentials (SIEM/TDIR on Splunk Cloud Platform or Splunk Enterprise). Not Splunk Enterprise Security Premier (native SOAR, UEBA, Attack Analyzer), not Splunk Observability, and not standalone Splunk SOAR.","asOf":"2026-09-21","status":"research-preview","summary":"Captured Essentials feature pages describe detections and investigation capabilities. Full ES 8 operating and permission procedures did not fetch, so affected research stages remain unknown; broader Splunk-platform capabilities are not assumed.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"Full ES 8 detection-authoring and queue procedures now establish findings, investigation context, ownership and status handling within the Essentials SIEM scope. This closes the initial operating-loop evidence gap at anchor 3. A complete scoped enrichment, related hunting and conditional incident-automation procedure is not established for anchor 4; Premier SOAR is excluded.","sourceIds":["s2","s4","s5"]},"innovation":{"score":null,"confidence":"low","rationale":"Feature pages and help snippets support risk correlation, finding aggregation and investigation as established SIEM workflows. This pass did not fully establish the normalization and retention conditions in the baseline anchor for the selected edition, so the stage remains unknown. No novel workflow is inferred from risk-based alerting or AI branding.","sourceIds":["s1","s2","s4","s6"]},"breadth":{"score":3,"confidence":"low","rationale":"Essentials documentation describes SIEM detections, dashboards (security posture, incident review, risk analysis), MITRE mapping, threat intelligence management, Detection Studio, and adaptive response. Hunting-style asset investigator and security-domain dashboards are listed on the features page. Stage 4 is not claimed for this edition: first-party plus third-party collection is assumed via the Splunk platform rather than an ES-specific connector catalog in the fetched pages, and UEBA is Premier.","sourceIds":["s1","s2"]},"ecosystem":{"score":null,"confidence":"low","rationale":"Stage 3 requires a connector or parser catalog and bundled content that pairs sources with detections. Fetched product and features pages and the docs.splunk.com landing do not provide that catalog; CIM documentation redirected and was not fetched. Third-party syslog/CEF/API ingest is implied by Splunk-platform marketing copy and is not treated as a fully supported stage-2 procedure. The gap is unknown, not stage 0.","sourceIds":["s1","s2","s3"]},"governance":{"score":2,"confidence":"medium","rationale":"The full roles table now establishes distinct read, analyst handling and administrative configuration roles. Queue membership is a workflow view, not a data-access boundary. Operator-audit coverage and scoped automation permissions are not fully established for anchor 3; the roles guide also warns of core-resource access outside ES controls.","sourceIds":["s7","s5"]},"operations":{"score":null,"confidence":"low","rationale":"Full detection-authoring and queue procedures now establish rule creation and triage. A complete current hunting procedure for the Essentials scope was not captured, so all conditions of anchor 3 remain unverified. Product feature lists do not fill that gap.","sourceIds":["s2","s4","s5"]}},"constraints":["Evaluated edition is Enterprise Security 8 Essentials, not Premier and not the full Splunk portfolio.","Product FAQ states Essentials includes SIEM, AI Assistant where available, and Detection Studio; Premier adds native SOAR, UEBA, and Automated Threat Analysis.","ES 8 terminology (findings, analyst queue, detections) replaces notables and incident review; older ES 7 docs on docs.splunk.com redirect to help.splunk.com and specific 7.3.2 topics returned 'does not exist'.","help.splunk.com deep articles did not return full bodies to web_fetch (Heretto portal error); several scores rest on search snippets plus marketing feature pages.","Adaptive Response is documented as a foundation before Splunk SOAR; it is not evidence that Essentials includes SOAR case management.","Cisco ownership does not establish shared entitlement with other Cisco products.","ES roles documentation warns that trusted authenticated users can reach certain core Splunk resources outside ES controls. Analyst queues organize work; they do not enforce data-access separation."],"sources":[{"id":"s1","title":"Splunk Enterprise Security product page","url":"https://www.splunk.com/en_us/products/enterprise-security.html","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"Splunk Enterprise Security Essentials features","url":"https://www.splunk.com/en_us/products/splunk-enterprise-security-essentials-features.html","accessedAt":"2026-09-21","kind":"product"},{"id":"s3","title":"Splunk Enterprise Security documentation landing (docs.splunk.com)","url":"https://docs.splunk.com/Documentation/ES","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Use detections to search for threats in Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/detections/create-event-based-detections-in-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Manage analyst workflows using the analyst queue in Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.6/mission-control/analyst-and-team-based-queues-in-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Using entity risk scores for detections in Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.3/risk-based-alerting/using-entity-risk-scores-for-detections-in-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Users and roles for Splunk Enterprise Security","url":"https://help.splunk.com/en/splunk-enterprise-security-8/install/8.7/installation/users-and-roles-for-splunk-enterprise-security","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"google-security-operations-siem","cohort":"siem-platforms","edition":"Google Security Operations Standard package, SIEM focus with included base SOAR; Pre-GA enhanced Cases excluded","asOf":"2026-09-21","status":"research-preview","summary":"Standard documents normalized ingestion, detection and search, and includes base SOAR. The legacy case workflow supports analyst assignment and event review; enhanced Pre-GA Cases is excluded. Package-wide permission boundaries remain an evidence gap.","dimensions":{"maturity":{"score":3.7,"confidence":"medium","rationale":"Legacy case ownership, status and alert review establish stage 3. Current UDM hunting procedures add 0.3 and Standard-included conditional playbook handling adds 0.4. Incident enrichment beyond initial grouping is not established in this pass, so the score is 3.7. Enhanced Cases and Enterprise-only capabilities are excluded.","sourceIds":["s3","s5","s11","s4","s12"],"refinement":{"base":3,"evidence":[{"criterion":"related-activity-hunting","rationale":"UDM search procedures let an analyst query additional telemetry, alter the time range and refine results beyond events already attached to an alert. Standard includes SIEM search and investigation.","sourceIds":["s4","s5"]},{"criterion":"conditional-incident-automation","rationale":"The included base SOAR supports playbooks with configured triggers and actions; the current overview explains automatic attachment to matching alerts and activation. This credit uses legacy alert playbooks, not Pre-GA enhanced Cases.","sourceIds":["s5","s12"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"UDM normalization, rules, investigation/search, the included legacy case workflow and Standard retention establish the ordinary current SIEM baseline. This is not a novelty claim. Pre-GA composite detections and enhanced Cases are excluded.","sourceIds":["s2","s3","s4","s5","s11"]},"breadth":{"score":4,"confidence":"medium","rationale":"The Standard scope documents third-party ingestion, normalized UDM events across endpoint/network/identity domains, YARA-L detection, search, investigative entity context and threat-intelligence matching. Curated detections, UEBA and Gemini in higher packages do not support this score.","sourceIds":["s1","s2","s3","s5","s10"]},"ecosystem":{"score":null,"confidence":"low","rationale":"Standard includes base SOAR and an integration catalog, and SIEM ingestion/parsers are documented. The current package table inconsistently lists a subset of curated rules while separately excluding Google Curated Detections for Standard. This review cannot establish the required scoped source-to-detection content pairing at anchor 3; the evidence gap remains unknown.","sourceIds":["s1","s5","s9"]},"governance":{"score":null,"confidence":"low","rationale":"The data-RBAC guide explicitly warns that SIEM scopes do not automatically protect SOAR data and documents additional case/search exceptions. Feature IAM alone does not establish the complete Standard SIEM-plus-base-SOAR governance path; scoped role/audit mapping remains unverified. No cross-workflow control is inferred from SIEM RBAC.","sourceIds":["s6","s8"]},"operations":{"score":3,"confidence":"medium","rationale":"Rules, UDM search and investigation procedures support a documented authoring and analyst workflow. The captured evidence does not establish every lifecycle and dashboard condition for stage 4.","sourceIds":["s3","s4","s9","s10"]}},"constraints":["Standard includes base SOAR; excluded or unverified workflows are evidence gaps, not claims of product absence.","Pre-GA enhanced Cases and composite detections are not evidence of generally available workflow stages.","Verify package entitlements and SIEM/SOAR access boundaries together; data RBAC on SIEM alone does not establish all case visibility rules.","Parser coverage and retention requirements need source-specific validation."],"sources":[{"id":"s1","title":"Google Security Operations SIEM platform overview","url":"https://docs.cloud.google.com/chronicle/docs/overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"UDM overview","url":"https://docs.cloud.google.com/chronicle/docs/event-processing/udm-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Detection rules overview","url":"https://docs.cloud.google.com/chronicle/docs/detection/default-rules","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Understand search","url":"https://docs.cloud.google.com/chronicle/docs/investigation/udm-search","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Google SecOps packages overview","url":"https://docs.cloud.google.com/chronicle/docs/secops/secops-packages","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Data RBAC impact on features overview","url":"https://docs.cloud.google.com/chronicle/docs/administration/datarbac-impact","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Composite detections overview","url":"https://docs.cloud.google.com/chronicle/docs/detection/composite-detections","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Configure feature access","url":"https://docs.cloud.google.com/chronicle/docs/onboard/configure-feature-access","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Check data ingestion health","url":"https://docs.cloud.google.com/chronicle/docs/ingestion/ingestion-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s10","title":"Single and multiple event rules in YARA-L","url":"https://docs.cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s11","title":"Google SecOps legacy investigation and case management","url":"https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s12","title":"Playbook and automation overview","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/whats-on-the-playbooks-screen","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small in-house team must operate one SIEM without a dedicated detection-engineering bench. The scenario highlights operator workload and integration upkeep. It does not change research scores or declare any offering eligible.","priorities":["operations","ecosystem"],"questions":["Who will maintain parsers or connectors when a source version changes, and what health signal shows that collection stopped?","Which query language (KQL, SPL, YARA-L) does the team already know well enough to tune detections without a vendor professional-services engagement?","Which incident-automation actions are included in the named edition versus a separate SOAR or Logic Apps entitlement?"]},{"id":"hybrid-telemetry","name":"Hybrid and third-party telemetry","description":"An organization needs detections across cloud-provider logs, identity, and non-vendor firewall or endpoint sources. The scenario asks what to validate in connectors and access control. It does not rewrite scores.","priorities":["breadth","ecosystem","governance"],"questions":["For each planned third-party source, which connector or parser version is documented, and which fields survive normalization (ASIM, CIM, or UDM)?","If analysts should see only some tables or data scopes, is table-level, queue-level, or data-RBAC control documented for the proposed edition?","Does onboarding the SIEM to an adjacent XDR or SOAR portal disable SIEM-native incident-creation rules that the design assumed?"]}],"researchNotes":["Cohort siem-platforms compares SIEM platform offerings and named editions only. Managed detection and response, MSSP operating models, and SOAR-only products are out of cohort scope even when a vendor sells them alongside SIEM.","Anchors are documented-evidence stages, not observed product quality, efficacy, or completeness. Stage 0 is only for affirmative documented absence of the scoped capability. Missing public docs, failed fetches, gated docs, or preview/Pre-GA-only procedures are unknown (null), never zero.","Shipped innovation stage 3 is the ordinary current SIEM baseline: ingest with normalization, risk or correlation, investigation, incident or case handling, and retention. Stage 4 requires a genuinely different shipped operator workflow beyond that baseline. Preview, Pre-GA, edition-unavailable paths, AI branding, and unique-market-first claims are excluded from stage 4+. Undifferentiated ordinary SIEM work is scored 3 with no novelty claim, or null if the full baseline is not documented.","This edition researches Microsoft Sentinel, Splunk Enterprise Security and Google Security Operations. Other field-guide offerings remain unassessed. Coverage is a research sample, not evidence of market leadership.","ibm-qradar remains unassessed as the continuing IBM self-managed QRadar SIEM. Retired QRadar cloud / QRadar SaaS is not treated as a live cloud SIEM pilot. Palo Alto Networks acquisition of QRadar SaaS assets does not make Cortex XSIAM a scored substitute in this file.","Google SecOps Standard includes base SOAR. Reviewed legacy case procedures support the baseline case workflow; package-wide permissions and connector/content pairing remain gaps. Enhanced Cases is Pre-GA and excluded.","Scope limitation: Microsoft publishes both a Sentinel SIEM and a Sentinel 'platform' (data lake, graph, MCP). Conservative interpretation: score cloud SIEM incident/automation procedures; do not score MCP, Security Copilot, agentic defense, preview data-lake management, or Fusion (unavailable after Defender-portal onboarding) as innovation.","Detailed Splunk Enterprise Security 8 procedure pages were inaccessible during review. Product pages and available search excerpts support limited, low-confidence judgments; unsupported control and integration details remain unknown.","Confidence is at most medium because this is public-documentation research, not a lab or customer-tenant assessment. Splunk cells use low confidence because inference from snippets and product pages is material.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."]},"changes":[]}]},"unassessed":[{"slug":"elastic-security-siem","name":"Elastic Security","company":"Elastic","profileUrl":"/landscape/vendors/elastic-security-siem/"},{"slug":"crowdstrike-falcon-next-gen-siem","name":"Falcon Next-Gen SIEM","company":"CrowdStrike","profileUrl":"/landscape/vendors/crowdstrike-falcon-next-gen-siem/"},{"slug":"palo-alto-cortex-xsiam","name":"Cortex XSIAM","company":"Palo Alto Networks","profileUrl":"/landscape/vendors/palo-alto-cortex-xsiam/"},{"slug":"exabeam-logrhythm-siem","name":"Exabeam New-Scale / LogRhythm SIEM","company":"Exabeam","profileUrl":"/landscape/vendors/exabeam-logrhythm-siem/"},{"slug":"securonix-unified-defense-siem","name":"Unified Defense SIEM","company":"Securonix","profileUrl":"/landscape/vendors/securonix-unified-defense-siem/"},{"slug":"ibm-qradar","name":"IBM QRadar SIEM","company":"IBM","profileUrl":"/landscape/vendors/ibm-qradar/"},{"slug":"opentext-arcsight","name":"OpenText Enterprise Security Manager","company":"OpenText","profileUrl":"/landscape/vendors/opentext-arcsight/"},{"slug":"fortinet-fortisiem","name":"FortiSIEM","company":"Fortinet","profileUrl":"/landscape/vendors/fortinet-fortisiem/"},{"slug":"rapid7-insightidr","name":"SIEM (InsightIDR)","company":"Rapid7","profileUrl":"/landscape/vendors/rapid7-insightidr/"},{"slug":"logpoint-siem","name":"Logpoint SIEM","company":"Logpoint","profileUrl":"/landscape/vendors/logpoint-siem/"},{"slug":"graylog-security","name":"Graylog Security","company":"Graylog","profileUrl":"/landscape/vendors/graylog-security/"},{"slug":"wazuh","name":"Wazuh","company":"Wazuh Inc.","profileUrl":"/landscape/vendors/wazuh/"}]}