SIEM Software: AI Market Discovery Index
Tracking how AI platforms recommend siem software. This public AI Market Discovery Index is updated monthly since July 2026.

On this page
- 01Benchmark Summary
- 02Current Benchmark at a Glance
- 03Research Scope and Qualification
- 04Current Brand Standings
- 05How to Read the Standings
- 06Recommendation Coverage Movement
- 07Category Leader: Splunk
- 08Recommendation Placement Snapshot
- 09Buyer-Intent Distribution
- 10Historical Measurement Record
- 11Evidence and Source Layer
- 12Scope Boundaries
Benchmark Summary
Splunk leads the SIEM Software benchmark with valid recommendation coverage of 31.9% in September 2026, down from 35.8% in July 2026. The largest coverage decline belonged to Splunk, moving from 42.0% in August 2026 to 31.9% in September 2026, a move beyond normal variation. Microsoft SharePoint recorded the largest coverage increase, reaching 0.8% in September 2026, up from 0.0% in August 2026, though the absolute counts remain small. Google Chronicle fell to 7.4% in September 2026, down from 12.0% in August 2026, also beyond normal variation.
Over the three comparable months, Splunk moved from 35.8% to 31.9%, Elastic Security held steady from 17.2% to 17.4%, and Rapid7 InsightIDR moved from 13.5% to 12.9% in valid recommendation coverage. Elastic Security, Exabeam, IBM QRadar, Microsoft SharePoint, Rapid7 InsightIDR, Securonix, and Sumo Logic all remained within normal month-to-month variation this month. Note that Microsoft Sentinel appeared in the August 2026 brand set with 35.6% valid recommendation coverage but was not tracked in the September 2026 set.
The benchmark began with 787 prompt-surface observations in July 2026, 800 in August 2026, and 793 in September 2026, producing 355, 424, and 379 qualified observations respectively after qualification.
AI recommendation trend
valid recommendation coverage, Jul 2026 to Sep 2026
- Splunk31.9%
- Elastic Security17.4%
- IBM QRadar14.5%
- Rapid7 InsightIDR12.9%
- Securonix9.0%
- Exabeam7.9%
- Google Chronicle7.4%
- Sumo Logic4.0%
- Microsoft SharePoint0.8%
- Microsoft Sentinel0.0%
Current Benchmark at a Glance
Measure | Jul 2026 | Sep 2026 | Movement |
|---|---|---|---|
Qualified benchmark observations | 355 | 379 | Up 24 |
Tracked brands | 9 | 9 | No change |
Qualified surface breadth | 6 | 6 | No change |
Recommendation-shaped answer share | 25.4% | 18.5% | Down 6.9 points |
Valid recommendation shortlist share | 39.4% | 33.8% | Down 5.6 points |
Leader by valid recommendation coverage | Splunk (35.8%) | Splunk (31.9%) | Down 3.9 points |
In August 2026, qualified benchmark observations rose to 424 before settling at 379 in September 2026. Qualified surface breadth counts the canonical AI/search surface families that produced at least one qualified observation. The six families are ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode.
For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending SIEM Software
Research Scope and Qualification
The public benchmark is narrower than the raw collection universe by design. Brand-level percentages use the qualified observations as the public denominator, not the raw collection.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Research stage | Jul 2026 | Sep 2026 | What it represents |
|---|---|---|---|
Source prompt-surface observations | 787 | 793 | Total prompts collected across AI/search surfaces |
Unique questions | 526 | 603 | Distinct questions asked |
Brand / competitor mentions | 786 | 793 | Prompts mentioning a brand or competitor |
Relevant observations | 507 | 532 | On-topic responses |
Irrelevant observations | 279 | 261 | Off-topic or unusable responses |
Qualified benchmark observations | 355 | 379 | Public benchmark denominator |
For methodology details, see AI Market Discovery Methodology.
Current Brand Standings
The table below is the primary current-month benchmark view, sorted by valid recommendation coverage.
Brand | Presence rate | Valid recommendation coverage | Top-three rate | Rank-one rate | Net sentiment |
|---|---|---|---|---|---|
Splunk | 92.6% | 31.9% | 24.5% | 11.3% | 0.5 |
Elastic Security | 38.8% | 17.4% | 5.0% | 0.3% | 0.7 |
IBM QRadar | 52.0% | 14.5% | 4.8% | 0.0% | 0.5 |
Rapid7 InsightIDR | 18.5% | 12.9% | 2.9% | 0.3% | 0.9 |
Securonix | 15.8% | 9.0% | 1.1% | 0.3% | 0.8 |
Exabeam | 23.2% | 7.9% | 2.9% | 1.1% | 0.5 |
Google Chronicle | 18.5% | 7.4% | 3.7% | 0.3% | 0.7 |
Sumo Logic | 11.1% | 4.0% | 1.3% | 0.0% | 0.6 |
Microsoft SharePoint | 2.4% | 0.8% | 0.5% | 0.3% | 0.4 |
How to Read the Standings
Presence rate is the share of qualified observations in which the brand is mentioned at all. Valid recommendation coverage is the share of qualified observations in which the brand receives a clear, actionable recommendation. Top-three rate is the share of qualified observations in which the brand appears among the top three recommended options. Rank-one rate is the share of qualified observations in which the brand is the single first recommendation. Net sentiment reflects the balance of positive versus negative mentions, from -1 to +1.
For formulas and denominator rules, see AI Market Discovery Metric Definitions.
Recommendation Coverage Movement
The table below tracks each brand's valid recommendation coverage from the July 2026 baseline to the September 2026 current period.
Brand | Jul 2026 | Sep 2026 | Movement since baseline |
|---|---|---|---|
Elastic Security | 17.2% | 17.4% | Up 0.2 points |
Exabeam | 11.3% | 7.9% | Down 3.4 points |
Google Chronicle | 8.2% | 7.4% | Down 0.8 points |
IBM QRadar | 17.5% | 14.5% | Down 3.0 points |
Microsoft Sentinel | 0.0% | 0.0% | No change |
Microsoft SharePoint | 2.0% | 0.8% | Down 1.2 points |
Rapid7 InsightIDR | 13.5% | 12.9% | Down 0.6 points |
Securonix | 9.9% | 9.0% | Down 0.9 points |
Splunk | 35.8% | 31.9% | Down 3.9 points |
Sumo Logic | 6.2% | 4.0% | Down 2.2 points |
In the prior-to-current month comparison, Splunk moved from 42.0% in August 2026 to 31.9% in September 2026, a decline beyond normal variation. Google Chronicle moved from 12.0% in August 2026 to 7.4% in September 2026, also beyond normal variation.
Category Leader: Splunk
Splunk remained the coverage leader in September 2026 at 31.9%, though it declined from 42.0% in August 2026, a move beyond normal variation. Over the full baseline-to-current series, Splunk moved from 35.8% in July 2026 to 31.9% in September 2026, a decline within normal variation. Its presence rate rose to 92.6% in September 2026, up from 90.4% in July 2026. Its top-three rate fell to 24.5% in September 2026 from 30.7% in July 2026, and its rank-one rate fell to 11.3% from 13.5%.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
The month was otherwise quiet for most tracked brands. Elastic Security, Exabeam, IBM QRadar, Microsoft SharePoint, Securonix, and Sumo Logic all stayed within normal month-to-month variation in valid recommendation coverage. Rapid7 InsightIDR declined slightly in each of the two months since July 2026 in valid recommendation coverage, a streak that has not yet reversed.
Recommendation Placement Snapshot
Coverage alone does not show how prominently a brand is recommended. Among the leading brands, placement patterns differed meaningfully in September 2026.
Brand | Sep 2026 top-three rate | Sep 2026 rank-one rate | Jul 2026 top-three rate | Jul 2026 rank-one rate |
|---|---|---|---|---|
Splunk | 24.5% | 11.3% | 30.7% | 13.5% |
Elastic Security | 5.0% | 0.3% | 3.4% | 0.0% |
IBM QRadar | 4.8% | 0.0% | 10.4% | 0.0% |
Close coverage figures can still hide different first-position rates. Splunk held a far higher rank-one rate than the next two brands, even as its top-three rate declined from July 2026 to September 2026.
Buyer-Intent Distribution
All qualified observations in both months fell into the Brand Recommendation class, representing discovery and consideration intent.
Buyer-intent class | Jul 2026 | Sep 2026 |
|---|---|---|
Brand Recommendation | 355 | 379 |
Pricing & Value | 0 | 0 |
Multi-Brand Comparison | 0 | 0 |
Total qualified observations | 355 | 379 |
The current public series measures brand recommendation discovery and does not yet contain qualified observations in the pricing and value or multi-brand comparison classes.
Historical Measurement Record
This is an evergreen benchmark URL. New measurements are added to the same report.
Measurement | Qualified observations | Coverage leader | Leader coverage | Largest coverage movement |
|---|---|---|---|---|
Jul 2026 | 355 | Splunk | 35.8% | N/A (baseline month) |
Aug 2026 | 424 | Splunk | 42.0% | Microsoft Sentinel +35.6 points baseline to current |
Sep 2026 | 379 | Splunk | 31.9% | Splunk Down 10.1 points prior to current |
Evidence and Source Layer
The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.
Scope Boundaries
This public benchmark does not measure market share, attributable sales, every possible AI response, organic-search ranking, social mention volume, or private and sponsored channels. A metric movement alone does not establish causality.
About This Benchmark
The LLM Authority Index AI Market Discovery Index tracks how AI and search surfaces present and recommend brands within a vertical, using standardized prompt collections across canonical AI surfaces each month. All metrics follow documented definitions and research standards.
- AI Market Discovery Methodology
- AI Market Discovery Metric Definitions
- AI Market Discovery Research Standards
- Modeled AI Authority Value
Get a Company-Level Authority Index
The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Keep reading
Related posts
Industry Reports
Procurement Software: AI Market Discovery Index
Read this blog on LLM Authority Index.
ReadIndustry Reports
eSignature Software: AI Market Discovery Index
Read this blog on LLM Authority Index.
ReadIndustry Reports
Customer Service Software: AI Market Discovery Index
Read this blog on LLM Authority Index.
Read