SIEM Software: AI Market Discovery Index

Tracking how AI platforms recommend siem software. This public AI Market Discovery Index is updated monthly since July 2026.

Mark Huntley, J.D.
By Mark Huntley, J.D.Growth Strategist & AI Discovery Analyst
6 minutes read

Benchmark Summary

Splunk leads the SIEM Software benchmark with valid recommendation coverage of 31.9% in September 2026, down from 35.8% in July 2026. The largest coverage decline belonged to Splunk, moving from 42.0% in August 2026 to 31.9% in September 2026, a move beyond normal variation. Microsoft SharePoint recorded the largest coverage increase, reaching 0.8% in September 2026, up from 0.0% in August 2026, though the absolute counts remain small. Google Chronicle fell to 7.4% in September 2026, down from 12.0% in August 2026, also beyond normal variation.

Over the three comparable months, Splunk moved from 35.8% to 31.9%, Elastic Security held steady from 17.2% to 17.4%, and Rapid7 InsightIDR moved from 13.5% to 12.9% in valid recommendation coverage. Elastic Security, Exabeam, IBM QRadar, Microsoft SharePoint, Rapid7 InsightIDR, Securonix, and Sumo Logic all remained within normal month-to-month variation this month. Note that Microsoft Sentinel appeared in the August 2026 brand set with 35.6% valid recommendation coverage but was not tracked in the September 2026 set.

The benchmark began with 787 prompt-surface observations in July 2026, 800 in August 2026, and 793 in September 2026, producing 355, 424, and 379 qualified observations respectively after qualification.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Sep 2026

0%15%30%45%60%Jul 2026Aug 2026Sep 2026
  • Splunk31.9%
  • Elastic Security17.4%
  • IBM QRadar14.5%
  • Rapid7 InsightIDR12.9%
  • Securonix9.0%
  • Exabeam7.9%
  • Google Chronicle7.4%
  • Sumo Logic4.0%
  • Microsoft SharePoint0.8%
  • Microsoft Sentinel0.0%

Current Benchmark at a Glance

Measure

Jul 2026

Sep 2026

Movement

Qualified benchmark observations

355

379

Up 24

Tracked brands

9

9

No change

Qualified surface breadth

6

6

No change

Recommendation-shaped answer share

25.4%

18.5%

Down 6.9 points

Valid recommendation shortlist share

39.4%

33.8%

Down 5.6 points

Leader by valid recommendation coverage

Splunk (35.8%)

Splunk (31.9%)

Down 3.9 points

In August 2026, qualified benchmark observations rose to 424 before settling at 379 in September 2026. Qualified surface breadth counts the canonical AI/search surface families that produced at least one qualified observation. The six families are ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode.

For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending SIEM Software

Research Scope and Qualification

The public benchmark is narrower than the raw collection universe by design. Brand-level percentages use the qualified observations as the public denominator, not the raw collection.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Research stage

Jul 2026

Sep 2026

What it represents

Source prompt-surface observations

787

793

Total prompts collected across AI/search surfaces

Unique questions

526

603

Distinct questions asked

Brand / competitor mentions

786

793

Prompts mentioning a brand or competitor

Relevant observations

507

532

On-topic responses

Irrelevant observations

279

261

Off-topic or unusable responses

Qualified benchmark observations

355

379

Public benchmark denominator

For methodology details, see AI Market Discovery Methodology.

Current Brand Standings

The table below is the primary current-month benchmark view, sorted by valid recommendation coverage.

Brand

Presence rate

Valid recommendation coverage

Top-three rate

Rank-one rate

Net sentiment

Splunk

92.6%

31.9%

24.5%

11.3%

0.5

Elastic Security

38.8%

17.4%

5.0%

0.3%

0.7

IBM QRadar

52.0%

14.5%

4.8%

0.0%

0.5

Rapid7 InsightIDR

18.5%

12.9%

2.9%

0.3%

0.9

Securonix

15.8%

9.0%

1.1%

0.3%

0.8

Exabeam

23.2%

7.9%

2.9%

1.1%

0.5

Google Chronicle

18.5%

7.4%

3.7%

0.3%

0.7

Sumo Logic

11.1%

4.0%

1.3%

0.0%

0.6

Microsoft SharePoint

2.4%

0.8%

0.5%

0.3%

0.4

How to Read the Standings

Presence rate is the share of qualified observations in which the brand is mentioned at all. Valid recommendation coverage is the share of qualified observations in which the brand receives a clear, actionable recommendation. Top-three rate is the share of qualified observations in which the brand appears among the top three recommended options. Rank-one rate is the share of qualified observations in which the brand is the single first recommendation. Net sentiment reflects the balance of positive versus negative mentions, from -1 to +1.

For formulas and denominator rules, see AI Market Discovery Metric Definitions.

Recommendation Coverage Movement

The table below tracks each brand's valid recommendation coverage from the July 2026 baseline to the September 2026 current period.

Brand

Jul 2026

Sep 2026

Movement since baseline

Elastic Security

17.2%

17.4%

Up 0.2 points

Exabeam

11.3%

7.9%

Down 3.4 points

Google Chronicle

8.2%

7.4%

Down 0.8 points

IBM QRadar

17.5%

14.5%

Down 3.0 points

Microsoft Sentinel

0.0%

0.0%

No change

Microsoft SharePoint

2.0%

0.8%

Down 1.2 points

Rapid7 InsightIDR

13.5%

12.9%

Down 0.6 points

Securonix

9.9%

9.0%

Down 0.9 points

Splunk

35.8%

31.9%

Down 3.9 points

Sumo Logic

6.2%

4.0%

Down 2.2 points

In the prior-to-current month comparison, Splunk moved from 42.0% in August 2026 to 31.9% in September 2026, a decline beyond normal variation. Google Chronicle moved from 12.0% in August 2026 to 7.4% in September 2026, also beyond normal variation.

Category Leader: Splunk

Splunk remained the coverage leader in September 2026 at 31.9%, though it declined from 42.0% in August 2026, a move beyond normal variation. Over the full baseline-to-current series, Splunk moved from 35.8% in July 2026 to 31.9% in September 2026, a decline within normal variation. Its presence rate rose to 92.6% in September 2026, up from 90.4% in July 2026. Its top-three rate fell to 24.5% in September 2026 from 30.7% in July 2026, and its rank-one rate fell to 11.3% from 13.5%.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

The month was otherwise quiet for most tracked brands. Elastic Security, Exabeam, IBM QRadar, Microsoft SharePoint, Securonix, and Sumo Logic all stayed within normal month-to-month variation in valid recommendation coverage. Rapid7 InsightIDR declined slightly in each of the two months since July 2026 in valid recommendation coverage, a streak that has not yet reversed.

Recommendation Placement Snapshot

Coverage alone does not show how prominently a brand is recommended. Among the leading brands, placement patterns differed meaningfully in September 2026.

Brand

Sep 2026 top-three rate

Sep 2026 rank-one rate

Jul 2026 top-three rate

Jul 2026 rank-one rate

Splunk

24.5%

11.3%

30.7%

13.5%

Elastic Security

5.0%

0.3%

3.4%

0.0%

IBM QRadar

4.8%

0.0%

10.4%

0.0%

Close coverage figures can still hide different first-position rates. Splunk held a far higher rank-one rate than the next two brands, even as its top-three rate declined from July 2026 to September 2026.

Buyer-Intent Distribution

All qualified observations in both months fell into the Brand Recommendation class, representing discovery and consideration intent.

Buyer-intent class

Jul 2026

Sep 2026

Brand Recommendation

355

379

Pricing & Value

0

0

Multi-Brand Comparison

0

0

Total qualified observations

355

379

The current public series measures brand recommendation discovery and does not yet contain qualified observations in the pricing and value or multi-brand comparison classes.

Historical Measurement Record

This is an evergreen benchmark URL. New measurements are added to the same report.

Measurement

Qualified observations

Coverage leader

Leader coverage

Largest coverage movement

Jul 2026

355

Splunk

35.8%

N/A (baseline month)

Aug 2026

424

Splunk

42.0%

Microsoft Sentinel +35.6 points baseline to current

Sep 2026

379

Splunk

31.9%

Splunk Down 10.1 points prior to current

Evidence and Source Layer

The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.

Scope Boundaries

This public benchmark does not measure market share, attributable sales, every possible AI response, organic-search ranking, social mention volume, or private and sponsored channels. A metric movement alone does not establish causality.

About This Benchmark

The LLM Authority Index AI Market Discovery Index tracks how AI and search surfaces present and recommend brands within a vertical, using standardized prompt collections across canonical AI surfaces each month. All metrics follow documented definitions and research standards.

Get a Company-Level Authority Index

The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper.

Get my free AI Company Index

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.