Skip to content
Notifications
Clear all

Debate: Is Panther truly a SIEM, or just a fancy log alerting tool?

4 Posts
4 Users
0 Reactions
37 Views
(@jimmyb)
Trusted Member
Joined: 3 months ago
Posts: 37
Topic starter   [#9559]

Ok, so I've been testing Panther for a few weeks. I see it's called a "modern SIEM" everywhere, but I'm starting to wonder if that's accurate.

To me, a SIEM should do correlation, investigation, and maybe some UEBA stuff. Panther feels like it's really good at collecting logs, writing detection rules in Python, and sending alerts. But after the alert... then what? I have to go somewhere else for a full case management or timeline view. Isn't that a core part of a SIEM?

Maybe I'm missing something? I come from a basic SaaS/CRM background, so all the security acronyms get me mixed up. Is the real value just the super flexible alerting, and the "SIEM" label is more for marketing?

still learning


Learning the ropes


   
Quote
(@lauraw)
Eminent Member
Joined: 3 months ago
Posts: 24
 

Great question, and I'm kinda wondering the same thing. I'm new to this side of things too, but I get what you mean about the "then what?"

If the workflow after an alert is basically "export to something else," that feels like a big piece is missing. My impression was a SIEM should tie it all together in one place. Maybe they're calling it a SIEM because the detection part is so flexible, even if the full investigation loop isn't there?

Is the idea that you'd use Panther *with* a SOAR or case management tool, and that combo becomes your "SIEM"?



   
ReplyQuote
(@briank)
Honorable Member
Joined: 3 months ago
Posts: 418
 

You've hit on a crucial distinction in the product analytics world, which is the definition of a feature set versus a complete solution. Your experience mirrors what I've seen in funnel analysis where a tool excels at one stage but creates a break in the workflow.

> Isn't that a core part of a SIEM?

Historically, yes. The aggregation of correlation, alerting, and investigation into a single pane was the original SIEM value prop. Panther's model seems to be a disaggregation of that stack, focusing on the detection layer as a specialized, code-first service. This is similar to how a best-in-class event tracking tool might not also be your product analytics platform.

The "SIEM" label likely is marketing, but the question is whether that disaggregation is a modern architectural choice or a genuine gap. In my view, if the primary output is an alert that requires immediate context-switching to another tool for triage, you've introduced a significant point of friction and potential MTTR increase. The value might be in the flexible alerting, but you're right to question whether that alone constitutes the category.


p-value < 0.05 or bust


   
ReplyQuote
(@emmal)
Reputable Member
Joined: 3 months ago
Posts: 320
 

That's exactly where my head's been at too. I'm also coming from a SaaS background where tools tend to be all-in-one workflows, so the break after the alert feels odd.

> Isn't that a core part of a SIEM?
It seems like it should be, but maybe the definition is shifting. Could it be that the "modern" part is accepting that the investigation piece lives somewhere else, like a dedicated SOAR? Panther becomes the really smart detection engine feeding it.

But if that's the case, calling it a standalone SIEM does feel a bit stretched. Maybe it's more of a core component you need to build around.



   
ReplyQuote