The short version
- SIEM contracts are large: Vendr’s purchase data (opens in a new tab) put the median Splunk buyer at $94,200 a year across 222 purchases, and the median Exabeam (opens in a new tab) buyer at $210,252.
- The vendor map has been redrawn. Cisco bought Splunk for about $28 billion (opens in a new tab) in 2024, and Exabeam and LogRhythm merged (opens in a new tab) the same year. Changes like these send customers looking at alternatives.
- SOC teams are under strain: in Splunk’s State of Security 2025 (opens in a new tab), 59% reported too many alerts and 78% said their security tools are disconnected and dispersed.
- Enterprise buyers mix AI and people: in a Gartner survey (opens in a new tab) of 645 B2B buyers, 45% used generative AI in a recent purchase and 69% prefer to check AI-generated insights with sales reps.
- In our study of AI search, ChatGPT ran a search for a named publication, ranking or award in 43.8% of its answers, one of them for a Gartner Magic Quadrant. Analyst coverage is part of what assistants look for.
Who signs off on a SIEM, and how much is one contract worth?
A security committee led by the CISO and SOC leadership buys it, on multi-year contracts priced mostly by data volume.
The core group is the CISO, the head of security operations, security architects and detection engineers. Finance and IT join because cost scales with data. Splunk’s pricing, Vendr notes, is “primarily consumption-based,” scaling with data ingested rather than user seats; list prices run from $1,800 to $2,700 per GB of daily ingest a year for self-hosted Splunk Enterprise. Microsoft Sentinel (opens in a new tab) is also priced on the data customers ingest, store and consume.
That makes each customer large and sticky. Vendr’s medians, which are samples of purchases on one procurement platform rather than market averages:
| Vendor | Median annual spend | Purchases in sample |
|---|---|---|
| Splunk | $94,200 | 222 |
| Sumo Logic | $85,135 | 181 |
| Securonix | $67,750 | not stated |
| Exabeam | $210,252 | not stated |
The category is large and growing. Splunk, citing a market forecast, puts SIEM growth at a 14.5% annual rate, reaching $11.3 billion by 2026 from $4.8 billion in 2021. Treat a vendor-cited forecast with care.
What starts a SIEM evaluation today?
Usually a trigger: an ownership change, a cost shock, a consolidation program, a failing SOC or a new reporting rule.
Ownership changes. Cisco agreed to pay $157 per share (opens in a new tab), about $28 billion, for Splunk. Exabeam and LogRhythm completed their merger on July 17, 2024. When a product’s owner or roadmap changes, we infer that some customers re-evaluate at renewal, and challengers court them.
Consolidation. A Gartner survey of 418 organizations (opens in a new tab) found 75% pursuing security vendor consolidation in 2022, up from 29% in 2020. The data are older, but the pressure behind platform bundles is not.
Strained SOCs. In Splunk’s survey, 46% said they spend more time maintaining tools than defending the organization, 55% deal with too many false positives, and 57% lose investigation time to gaps in their data management. Splunk is itself a SIEM vendor, so read these as one input.
Detection speed and money. A breach took 241 days on average to identify and contain, according to IBM’s 2025 breach report (opens in a new tab), which is the window a SIEM is bought to shorten. When the organization’s own team caught the breach, rather than hearing of it from the attacker, the saving was $900,000. Heavy use of AI and automation in security operations went with $1.9 million lower breach costs.
Reporting rules. Under Article 23 of the EU’s NIS2 Directive (opens in a new tab), covered companies must send an early warning within 24 hours of becoming aware of a significant incident and a fuller notification within 72 hours. Rules like these raise the cost of slow detection, we infer.
Where do AI assistants enter the SIEM buying journey?
At the long list and in background research, with people and analysts used to check what the assistant said.
The best evidence on enterprise buyers comes from Gartner’s 2026 survey of 645 B2B buyers. They used an average of seven information sources during a recent purchase. 45% used generative AI, mainly to gather information on vendors and products. 69% prefer to validate AI-generated insights with sales reps, and just over half said they are more likely to meet misleading information from generative AI.
That pattern suits SIEM, we infer. An architect asks an assistant to summarize options and compare pricing models, then checks the claims in analyst reports, peer reviews and a proof of concept. The assistant shapes which vendors are worth a call. The call decides the deal. Data platform buyers follow a similar path, as our guide to analytics and BI software shows.
A security architect who types a SIEM question into Google will usually meet an AI answer first. Of the eight industries in our study of 1,248 US searches, B2B software and technology had the highest AI Overview rate: Google’s AI summary topped the results on 96.0% of those searches.
Which questions do SIEM buyers ask AI assistants?
Questions about alternatives, migration, pricing models, consolidation and fit with existing tools. We drafted the SIEM prompts below as examples of each trigger; none comes from observed buyer logs.
| Trigger | Illustrative prompt |
|---|---|
| Renewal or ownership change | “What are the main Splunk alternatives for a 20,000-employee bank, and how hard is migration?” |
| Merger | “What happens to LogRhythm SIEM customers after the Exabeam merger?” |
| Cost | “Which SIEMs price by ingest, and which by users or endpoints? How do I estimate cost at 2 TB a day?” |
| Consolidation | “Should we use Microsoft Sentinel if we already run Defender, or keep a separate SIEM?” |
| Architecture | “Can a SIEM search logs kept in our own data lake without moving them?” |
| Compliance | “Which SIEMs help meet NIS2 incident reporting deadlines?” |
| Proof | “Which vendors are Leaders in the latest Gartner Magic Quadrant for SIEM?” |
The proof questions matter because assistants search for rankings. In our hidden-searches study, ChatGPT ran a search aimed at a named publication, ranking or award in 43.8% of its answers, and most past-year searches looked for the latest edition of an annual ranking. One observed search was “Gartner Magic Quadrant 2024 managed detection and response.” Managed detection providers face the same ranking checks, covered in how MDR providers win qualified leads.
How does a mention in an AI answer become a SIEM proof of concept?
Through the evaluation invite list: the AI answer shapes who gets a call, a proof of concept and a contract.
- Trigger. A renewal, a merger, a cost review or an incident opens the question.
- Long list. The team asks assistants for alternatives and comparisons, alongside analyst reports and peers.
- Validation. Architects check claims with vendors’ sales engineers, references and documentation.
- Proof of concept. Two or three vendors ingest real data for weeks.
- Contract. A multi-year agreement priced by data volume, which grows as the customer sends more data.
The value sits in steps 2 and 3. A vendor missing from the long list never reaches the proof of concept. A vendor named with a wrong pricing model or an outdated product name starts the sales call correcting the assistant. Pricing is a known weak spot: when our pricing study checked four assistants on 45 software products, just 61.9% of the plan prices they quoted matched the vendor’s own pricing page in full. We expect ingest-based SIEM pricing to be harder still to quote than a per-seat price.
An architect who shortlists you after reading an AI answer often arrives through a sales call, not a tracked click; what lost clicks mean for pipeline covers how to account for that.
Why does an assistant put one SIEM on the long list and leave another off?
The platforms do not say; studies point to independent and recent sources, and SIEM buyers lean on analyst reports.
Documented by the platforms. According to Google, AI Overviews and AI Mode may use a “query fan-out” technique (opens in a new tab), so a single SIEM question can trigger related searches on pricing, migration and integrations. None of the platforms explains how it settles on the security vendors it names.
Observed in studies. On US software questions, earned, independent sites supplied 72.7% of the sources AI search used, compared with 45.4% for Google, in work by Chen and colleagues (opens in a new tab). In our four-assistant study, recommendations overlapped most for B2B software, at 0.543 on a scale from 0 to 1, so assistants agree more here than in most industries, though far from fully. In our freshness study, assistants cited pages first published about half as long ago as Google’s top 10 for the same questions. In our Reddit study, more than a third of Google’s AI Overviews for B2B software cited Reddit, and r/cybersecurity was among the most-cited communities.
What SIEM buyers rely on. Analyst evaluations carry weight in this category. Gartner published its latest Magic Quadrant for SIEM on 8 October 2025. Splunk (opens in a new tab) says it has been named a Leader 11 times in a row; Microsoft cites the same report plus an IDC MarketScape. Splunk’s own SIEM guide (opens in a new tab) lists Gartner, Forrester and IDC reports as the common references.
Our inference. A reasonable expectation is that vendors with current analyst coverage, specific public documentation and active practitioner discussion give assistants more to cite. That expectation has not been tested on security analytics vendors.
What does a SIEM vendor lose when assistants skip it?
Evaluations it never hears about, each one worth a multi-year contract. No study puts a figure on the total.
- Rare windows. SIEM replacements are disruptive, so evaluations open mainly at renewal or after a trigger. Missing one may mean waiting for the next contract cycle, we infer.
- Large stakes per miss. With median contracts in the tens or hundreds of thousands of dollars a year, a single lost evaluation is material for most vendors.
- A place on the list is not stable. We asked ChatGPT each question five times in our consistency study, and only 25.2% of the brands it named came back in every run, so a SIEM vendor can be on one architect’s long list and off the next.
- Wrong facts travel. After mergers and rebrands, we expect assistants to describe retired SIEM product names or old pricing; our guide to correcting wrong brand information in AI answers covers the repair.
What does GEO look like for a SIEM or security analytics vendor?
It puts your detection, pricing and migration evidence where assistants and architects can find and check it. Nobody can promise a SIEM a spot on any long list.
- State what you are, precisely. SIEM, security analytics platform, data lake add-on or part of a broader operations platform. Use the same words everywhere, especially after a merger or rename.
- Publish pricing logic in plain pages. Explain the unit (ingest, users, endpoints, queries), what counts toward it and a worked example. Ingest pricing is where confusion costs deals.
- Document migration paths. Public guides for moving from the main incumbents, with detection rule conversion and timelines, answer the questions buyers ask at renewal.
- Earn analyst and peer coverage. Analyst evaluations, peer review platforms and practitioner communities are where SIEM claims get checked; building brand authority for AI search explains how that coverage is earned.
- Publish integration and detection detail. Data connector lists, detection content mapped to common frameworks and architecture notes give assistants specifics to cite.
- Write honest comparison pages. See whether comparison pages help B2B citations and why ranked lists matter.
- Measure across assistants. Track trigger-specific questions in ChatGPT, Google AI Overviews and AI Mode, Gemini, Perplexity, Copilot and Claude, several runs each.
What is still unknown about AI search in SIEM evaluations?
No published study measures SOC teams’ use of assistants, or whether being named wins SIEM evaluations.
- Nothing specific to security operations buyers. Gartner surveyed B2B buyers across categories, not CISOs or SOC leaders choosing a SIEM.
- Vendor and sample data. Splunk’s survey comes from a SIEM vendor; Vendr’s medians come from one platform’s purchases; the market forecast is vendor-cited.
- The link to revenue is the least proven part. Across the 45 studies of AI search optimization in Martinez’s review (opens in a new tab), traffic and conversions had the weakest evidence.
- Answers move. Results change between runs, wordings and assistants.
How can a SIEM vendor find out whether AI answers are costing it enterprise evaluations?
Ask the assistants your prospects’ renewal and migration questions, and see which SIEMs make their long lists.
List 20 to 30 prompts across alternatives, migration, pricing model, consolidation, compliance and proof. Because answers shift, put every prompt to ChatGPT, Gemini, Perplexity, Copilot, Claude and Google’s AI features more than once. Note which vendors appear, which analyst reports and communities are cited, and whether your ingest pricing and current product names come through correctly. SIEM is one part of a wider security market, covered in how cybersecurity software firms earn revenue from AI search. For firewall and zero trust buyers, see how network security vendors win buyers.
To have that test run for you, talk to us about a SIEM visibility audit. We will show where assistants place you on the long lists that turn into proofs of concept, and which gaps in your public detection, pricing and migration evidence are most likely keeping you out of renewal-cycle evaluations. Closing those gaps, through pricing logic pages, migration guides and analyst and peer coverage, is the work our generative engine optimization service page covers.
Frequently asked questions
Do enterprise security teams trust AI answers about SIEMs?
Partly. In Gartner’s survey, 45% of B2B buyers used generative AI, but 69% prefer to validate AI-generated insights with sales reps.
Will being a Leader in the SIEM Magic Quadrant get us named by assistants?
Plausibly. In 43.8% of the answers in our study, ChatGPT went looking for a named ranking, and one of those searches was for a Magic Quadrant. Nobody has measured the effect for SIEM.
Should we publish our SIEM pricing?
Publish the pricing logic at least. Ingest-based pricing is hard to quote, and only 61.9% of AI-quoted software prices were fully faithful in our study.
Do Reddit and practitioner forums matter for SIEM?
They can. More than a third of Google’s AI Overviews for B2B software cited Reddit in our study, and r/cybersecurity was among the most-cited communities.
When would better AI visibility appear as SIEM proofs of concept?
Expect quarters, not weeks. Evaluations open mainly at renewals and after triggers, and the average breach lifecycle alone is 241 days.
Sources
- Vendr (2026), Splunk software pricing and plans (opens in a new tab)
- Vendr (2026), Exabeam software pricing and plans (opens in a new tab)
- Vendr (2026), Sumo Logic software pricing and plans (opens in a new tab)
- Vendr (2026), Securonix software pricing and plans (opens in a new tab)
- Cisco (2024-03-18), Cisco completes acquisition of Splunk (opens in a new tab)
- Cisco (2023-09-21), Cisco to acquire Splunk (opens in a new tab)
- Exabeam (2024-07-17), Exabeam and LogRhythm complete merger and announce new company details (opens in a new tab)
- Splunk (2025), State of Security 2025 (opens in a new tab)
- Splunk (2025-10), 2025 Gartner Magic Quadrant for SIEM (opens in a new tab)
- Splunk (n.d.), What is SIEM? (opens in a new tab)
- Microsoft (2026), Microsoft Sentinel (opens in a new tab)
- Gartner (2026-05-20), Gartner survey finds 69% of B2B buyers turn to sales reps to validate AI-generated insights (opens in a new tab)
- Gartner (2022-09-13), Gartner survey shows 75% of organizations are pursuing security vendor consolidation in 2022 (opens in a new tab)
- IBM (2025-07-30), IBM report: 13% of organizations reported breaches of AI models or applications (opens in a new tab)
- European Union, via Springlex (2022-12-27), NIS2 Directive, Article 23 (opens in a new tab)
- Google Search Central (2025), AI features and your website (opens in a new tab)
- Chen, Wang, Chen and Koudas (2025), Generative Engine Optimization: How to Dominate AI Search (opens in a new tab), arXiv:2509.08919.
- Martinez (2026), Optimizing Visibility in Generative Engines: A Critical Survey of Generative Engine Optimization (2023-2026) (opens in a new tab), arXiv:2607.14035.
- Underneath (2026), When does Google show an AI Overview? 1,248 US searches
- Underneath (2026), The hidden searches AI assistants run before they answer
- Underneath (2026), How faithfully do AI assistants quote software prices?
- Underneath (2026), Do ChatGPT, Gemini, Perplexity and Claude agree on brands?
- Underneath (2026), How fresh are the pages AI engines cite?
- Underneath (2026), When does a Reddit thread become evidence in Google’s AI?
- Underneath (2026), Ask an AI the same question 5 times: do the brands change?