Imply Lumi connects SIEM tools and AI agents to more security data

Imply has unveiled its expanded vision for the security information and event management (SIEM) market, with Imply Lumi providing the data platform for the agentic SIEM. Imply is bringing modern data architecture to security teams facing growing data volumes, rising costs and new demands from AI-driven investigations, while preserving the SIEM tools and workflows they already depend on.

Why AI is increasing pressure on SIEM architecture

SIEMs were built for a different era, when security platforms could ingest, index, store and query every log within the same system. As data volumes grow, that approach becomes increasingly expensive to scale, forcing security teams to make difficult choices about which data to keep and how long to retain it.

AI is adding to that pressure because agents don’t stop at the first answer. An agent working an alert follows each finding with new questions, often reaching into other data sources and further back in time than a detection rule would, so the underlying architecture has to keep more data accessible and absorb search demand that is much harder to predict.

“The SIEM isn’t going away, but the architecture underneath it has to change,” said Eric Tschetter, chief architect at Imply. “The opportunity isn’t simply to make SIEM cheaper, but to enable organizations to retain and access significantly more security data while preserving the tools and workflows analysts already rely on.”

Data platforms addressed similar challenges by separating low-cost object storage from compute, allowing organizations to retain significantly more data and scale computing resources based on demand. For security teams, the opportunity is not simply to store more data in a security data lake, but to make that data quickly accessible and useful to existing SIEMs and modern AI agents, wherever it lives.

A shared security data layer for existing SIEMs and AI agents

Imply Lumi provides a shared data layer beneath existing SIEM tools and modern AI agents, allowing organizations to expand access to security data while continuing to use their existing security tools and workflows.

Lumi gives security teams and AI agents immediate access to security data wherever it lives, without requiring organizations to move everything into their SIEM first. Teams can search both indexed data and unstructured logs stored in object storage using familiar languages like SPL and SQL, making more of their security history available for investigations without changing existing workflows.

By separating storage, compute and access, Lumi enables organizations to retain more security history in cost-efficient object storage and scale search resources based on demand. Security teams can keep the tools they know while making more of their data available for investigations and AI-driven analysis.

“With Imply Lumi, we can ingest more data, retain it longer, pull in telemetry from platforms beyond Splunk, and still understand what our costs will look like as we scale,” said Rafael Hass, security information manager at BTG Pactual.

Don't miss