Databricks launches Lakewatch
Databricks introduced Lakewatch, an open, agentic SIEM designed to unify security, IT, and business data and to detect threats from 'agent attackers' — signaling a push to secure AI/agentic workflows at the platform level. The product highlights growing demand for observability and policy enforcement around autonomous services. (finadium.com)
Databricks launched Lakewatch on March 24, 2026 and opened it in Private Preview, naming Adobe and Dropbox among initial customers. (databricks.com) The company confirmed acquisitions of Antimatter and SiftD.ai as part of the Lakewatch build; Antimatter founder Andrew Krioukov has been tapped to lead the Lakewatch team. (techcrunch.com) SiftD.ai’s co‑founder and CEO Steve Zhang is reported to have created Splunk’s Search Processing Language, and PitchBook estimates Antimatter raised about $12 million led by NEA in 2022. (techcrunch.com) Databricks says Lakewatch runs agent reasoning using Anthropic’s Claude models, leveraging a five‑year Databricks–Anthropic partnership first announced on March 26, 2025. (databricks.com) Technical details released show telemetry normalized to OCSF and stored in Delta Lake or Apache Iceberg, governed via Unity Catalog, ingested through a Lakeflow Connect ETL, and analyzed with Agent Bricks plus a natural‑language “Genie” orchestrator for automated hunting and triage. (blocksandfiles.com) Databricks positions Lakewatch on a compute‑first pricing model that decouples storage from compute and claims up to an 80% reduction in TCO while allowing retention of petabytes of telemetry instead of discarding large shares of logs. (prnewswire.com) The Lakewatch announcement follows Databricks’ roughly $5 billion funding round that closed in February 2026 and is being rolled out into an “Open Security Lakehouse Ecosystem” with partners named by Databricks including Palo Alto Networks, Okta, Arctic Wolf, Akamai and Wiz. (cnbc.com) (blocksandfiles.com)