Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security data lakes and SIEM cost pressure: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Gartner’s 2026 Security and Risk Management Summit elevated security data lakes as a new category while removing standalone security data pipelines from the Hype Cycle, reflecting a shift from routing data as infrastructure to treating the data layer as the foundation for detections, according to Axoflow. The market is moving toward architectures where collection-time detection, normalization, and downstream analytics are separated deliberately, and that changes how SOC teams evaluate cost, portability, and control.

NHIMG editorial — based on content published by Axoflow: Security Data Lakes and the Hype Cycle shift in security operations

Questions worth separating out

Q: How should security teams evaluate security data lakes alongside SIEM investments?

A: Teams should evaluate them by control outcomes, not by storage cost alone.

Q: When does a security data pipeline become a commodity feature?

A: It becomes a commodity when it only transports logs from source to destination without improving detection quality, schema consistency, or evidence retention.

Q: What signals show that telemetry quality is affecting SOC outcomes?

A: Common signals include inconsistent fields across sources, poor parsing rates, dropped events, and repeated analyst work to reformat data before investigation.

Practitioner guidance

  • Define the security data layer as a control domain Assign ownership for schema normalization, enrichment, and retention decisions so the data layer is governed like a security control rather than an engineering utility.
  • Separate routing from detection decisions Document which detections should run at collection time and which should remain downstream, then use that split to reduce volume without losing investigative fidelity.
  • Measure telemetry quality before cost savings Track field completeness, event consistency, and parsing accuracy alongside ingest cost so leaders can see whether savings came from better control or data loss.

What's in the full article

Axoflow's full article covers the operational detail this post intentionally leaves for the source:

  • How the collection layer can execute detection logic before telemetry moves downstream
  • Why object storage can replace expensive SIEM-tier retention for raw events
  • What Security Data Lakes change in the vendor and platform landscape
  • How pipeline functions are being packaged into broader security platforms

👉 Read Axoflow's analysis of security data lakes and the SOC architecture shift →

Security data lakes and SIEM cost pressure: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Security data architecture is now a governance problem, not a plumbing problem. Once the market starts valuing the data layer itself, teams must treat normalization, schema consistency, and retention as controls that shape detection outcomes. That matters for SOC leadership because the same telemetry now underpins threat hunting, compliance evidence, and identity correlation across NHIs and human users. The practical conclusion is that data-layer design has become a security decision, not an IT convenience.

A question worth separating out:

Q: Should teams retain raw telemetry or only normalized events?

A: Most teams need both, but for different purposes. Normalized events support routine detection and low-cost analytics, while raw telemetry provides forensic depth when investigations require reconstruction. The key is to decide explicitly which data stays in expensive systems and which can be moved to lower-cost storage without reducing response capability.

👉 Read our full editorial: Security data lakes are changing security operations architecture



   
ReplyQuote
Share: