{"id":3708,"date":"2024-05-22T10:53:10","date_gmt":"2024-05-22T15:53:10","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-analytics\/snowflake-anvilogic-investment-sign-of-changes-siem"},"modified":"2024-05-22T10:53:10","modified_gmt":"2024-05-22T15:53:10","slug":"snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/22\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market\/","title":{"rendered":"Snowflake&amp;apos;s Anvilogic Investment Signals Changes in SIEM Market"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta1b333f18467fdb5\/664e149a4f8be307d6ace610\/avilogic-snowflake.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Data service provider Snowflake deepened its strategic partnership with cybersecurity-analytics provider Anvilogic this week with a joint offering that could further shake up the security information and event management (SIEM) market.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The two cloud service providers are targeting business customers that already use Snowflake&#8217;s software-as-a-service offering for data storage and analytics and who want to use the stored data and log information for security operations and threat detection. Anvilogic claims to work alongside other SIEM systems, capturing data typically missed by such systems, such as logs produced by cloud services and alerts produced by cloud-security products.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The joint Snowflake and Anvilogic solution would lead to reduced costs \u2014&nbsp;on the order of 50% to 80%, the companies claim \u2014 and will eventually replace legacy SIEM platforms, argues Karthik Kannan, CEO of Anvilogic.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It&#8217;s a bit of a changing of the guard, something that both Snowflake and Anvilogic have been expecting for a long time,&#8221; he says. &#8220;We&#8217;ve been building towards this day, for when our type of approach, which I&#8217;ll explain in a minute, which will take center stage and kind of start to take some of those old legacies out and replace them for the next decade.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The security information and event management (SIEM) market has undergone tremendous changes in the last two years. In August 2022, OpenText <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/opentext-goes-all-in-on-cybersecurity-size-and-scale-with-micro-focus-purchase\" rel=\"noopener\">agreed to purchase Micro Focus<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 the owner of the well-known ArcSight SIEM platform \u2014 for $6 billion. In September, Cisco announced it would move into the SIEM sector by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisco-moves-into-siem-with-28b-deal-to-acquire-splunk\" rel=\"noopener\">purchasing Splunk for $28 billion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a deal that completed in March. Earlier this month, IBM <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/ciso-grapple-with-ibm-unexpected-cybersecurity-software-exit\" rel=\"noopener\">exited the market<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and sold its QRadar division of SaaS cybersecurity products \u2014 which include SIEM capabilities \u2014 to Palo Alto Networks, with the two companies agreeing to work together as partners. Neither company divulged how much Snowflake is investing in Anvilogic. (Anvilogic <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.anvilogic.com\/learn\/series-c\" rel=\"noopener\">closed a $45 million third investment (Series C) round<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in April, bringing its total funding to $85 million.)<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"&quot;Cybersecurity is a Data Problem&quot;\">&#8220;Cybersecurity is a Data Problem&#8221;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The data-focused partnership of Snowflake and Anvilogic makes sense as businesses <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/picking-right-database-tech-cybersecurity-defense\" rel=\"noopener\">find themselves awash in data<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The average company currently uses only about half of the information available through logs, but hopes to track up to 80% in the next few years, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.mckinsey.com\/capabilities\/risk-and-resilience\/our-insights\/cybersecurity\/new-survey-reveals-2-trillion-dollar-market-opportunity-for-cybersecurity-technology-and-service-providers\" rel=\"noopener\">a survey conducted by consultancy McKinsey<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The quest to use all that data effectively makes the pairing of a data-focused service provider with a cybersecurity-service provider make a lot of sense, says John Bland, head of cybersecurity strategy at Snowflake.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We believe firmly that cybersecurity is a data problem,&#8221; he says. &#8220;We&#8217;ve had data volumes explode, and it&#8217;s hard to get visibility into all the data you need \u2014 all your security data and sources you need visibility into \u2014 and then it&#8217;s also hard to retain it and keep it around in a searchable fashion for as long as you need to.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.anvilogic.com\/learn\/snowflake-investment\" rel=\"noopener\">Anvilogic and Snowflake pairing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> will likely make sense for companies that are already committed to the data platform, as pairing with a cybersecurity analytics providers will provide additional benefits, which a standalone SIEM provider might not, says Allie Mellen, principal analyst for security and risk at business-intelligence firm Forrester Research.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is appealing for organizations that are already leveraging the data platform for IT operations, product, or other use cases, as it can help support data consolidation efforts and enable better data governance practices,&#8221; she says. &#8220;However, it is challenging for practitioners to leverage, as it means managing multiple different vendors for different elements of what would traditionally be a single security analytics platform.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Are Monolithic SIEMs Over?\">Are Monolithic SIEMs Over?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Both Anvilogic and Snowflake argue that the era of monolithic SIEM products is coming to a close. Instead, businesses need to effectively manage their data and provide it to specific use cases, whether that is business intelligence or threat intelligence. With the partnership with Anvilogic and its ability to work alongside legacy SIEM systems, Snowflake aims to allow companies to gradually move to a data-centric architecture, Snowflake&#8217;s Bland says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Every customer I&#8217;ve talked to is ready to break up with their legacy SIEM, but they just don&#8217;t know how,&#8221; he says. &#8220;They&#8217;ve built dashboards and detections over the last five years, or it could be that they feel like they have other competing initiatives, and they not sure they want to take the risk of a full &#8216;rip and replace&#8217; right now.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The companies also have the benefit of working native in the cloud, while many traditional SIEM systems have added cloud-based operations after starting as appliances or as applications run inside data centers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With so much of business operations happening in the cloud, non-native cybersecurity platforms are at a disadvantage, says Saryu Nayyar, CEO of rival cybersecurity-analytics firm Gurucul.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Legacy SIEMs are legacy for a reason \u2014 there is far better technology available today,&#8221; he says. &#8220;I think that\u2019s the root cause behind many of these mergers. In an effort to fill the deficiencies in their SIEM platform, vendors are mashing together capabilities that weren\u2019t designed to work in a unified way, and probably won\u2019t any time soon.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet, while the traditional SIEM market is certainly undergoing a challenging evolution, the major players continue to benefit from a focus on tight integration with third parties and other existing relationships, says Forrester&#8217;s Mellen.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Ultimately, it&#8217;s a matter of tradeoffs,&#8221; she says. &#8220;Using a data platform like Snowflake is an opportunity for some enterprises to consolidate business data storage and access. However, it comes with challenges, such as managing the data architecture and leveraging third-party partners for analytics, automation, and data pipeline management.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/snowflake-anvilogic-investment-sign-of-changes-siem\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data service provider Snowflake deepened its strategic partnership with cybersecurity-analytics<\/p>\n","protected":false},"author":12,"featured_media":3709,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=1340%2C530&ssl=1",1340,530,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=300%2C119&ssl=1",300,119,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=640%2C253&ssl=1",640,253,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=640%2C253&ssl=1",640,253,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=1340%2C530&ssl=1",1340,530,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=1340%2C530&ssl=1",1340,530,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=1024%2C405&ssl=1",1024,405,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?resize=825%2C530&ssl=1",825,530,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/snowflakeaposs-anvilogic-investment-signals-changes-in-siem-market.jpg?fit=1340%2C530&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3708"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3708\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3709"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}