Databricks has completed its acquisition of Panther and is folding the security operations company into its Lakewatch strategy. The transaction adds a mature detection engine, operational workflows and more than 100 integrations to a Databricks product that is being positioned as an agentic security information and event management platform.

The announcement moves the deal from intent to execution, but it is also a product-direction statement. Databricks wants security telemetry to live beside IT and business data in an open lakehouse, with AI agents operating over the combined history rather than relying on a separate, tightly metered SIEM data store.

Panther supplies the operational layer

Lakewatch provides the data foundation: collection, governance and analysis for high-volume security telemetry on the Databricks Data Intelligence Platform. Panther contributes the parts security operations centres use day to day, including detections-as-code, investigation workflows and connectors to cloud, identity, endpoint and software-as-a-service systems.

Databricks says the combination is intended to remove a common trade-off in conventional SIEM deployments. Organisations often limit retention or sample records to control ingestion and storage charges, which can leave incomplete history when an attack crosses several systems over a long period. A lakehouse can retain more of that raw telemetry in open formats and separate storage from the compute used to investigate it.

Panther’s contribution is meant to shorten the distance between stored data and an analyst’s queue. Its existing detection content and integrations can make telemetry actionable, while Lakewatch supplies the governed historical layer beneath it. Databricks says customers get the two elements together from the first day of the completed deal, though the announcement does not define that statement feature by feature.

That architecture is not automatically cheaper or easier. Query design, data quality, retention policies and analyst workflows still determine the operational result. The official announcement does not include comparative pricing, migration effort or independently measured response-time data.

Agents are aimed at repetitive SOC work

Databricks describes autonomous agents that can triage alerts, conduct threat hunts and help refine detection logic. Access to longer histories and joined business context could help an agent distinguish an isolated event from a sequence spread across identities, endpoints and cloud services.

The company also argues that security has become a data and AI problem as attackers use automation and as defenders confront more telemetry than analysts can inspect manually. In that framing, the agent is not a general chatbot layered over alerts. It is an operator working against governed data, coded detections and established response workflows.

Longer retention could also improve retrospective investigations. A newly discovered indicator can be searched against months of unsampled history, and an agent can assemble related events using identity and business context. The benefit depends on consistent schemas and trustworthy joins; retaining more data does not by itself create a correct investigation narrative.

Important controls remain to be clarified. The announcement does not detail which agent actions require approval, how recommendations are evaluated, what evidence is retained for audit, or how customers can constrain automated changes to detection logic. Those questions become more important as a system moves from summarising an alert to taking action in a live environment.

Open data is the centre of the pitch

Databricks says Lakewatch can retain petabyte-scale telemetry for months or years and correlate it with IT and business data. The value proposition is historical depth: an investigation can use the same governed foundation as analytics and AI workloads, rather than exporting a narrow slice of events into another product.

Panther’s integrations are meant to make that foundation operational sooner. A connector catalogue and existing SOC workflows can reduce the engineering work required before an analyst sees useful signals. Detections-as-code also gives teams a versionable way to review and deploy security logic, which is more transparent than rules that exist only inside a vendor console.

Completion is not the end of integration

The deal’s completion confirms ownership, but the announcement leaves the packaging roadmap open. Databricks has not specified whether Panther customers will move to new plans, when every Panther capability will appear in Lakewatch, or which features are immediately available in each cloud and region.

For existing customers, continuity and migration details will matter as much as the strategic vision. For prospective users, the central question is whether the combined product can deliver the promised context and automation without weakening analyst control. Databricks now has the data platform and Panther’s operational tooling under one roof; the next evidence will come from integration milestones, product documentation and measurable security outcomes.