Subcategory · AI Citation Index

SIEM

SIEM is a contested category with no consensus pick. Rapid7 captures the widest discovery footprint — showing up in 41% of buyer queries across ChatGPT, Claude, Gemini, Perplexity, and Meta AI — but Elastic and SentinelOne win more head-to-head comparisons when buyers ask AI to choose between options. Splunk and Microsoft Sentinel surface in half the discovery prompts but split head-to-head wins evenly with Elastic Security and Google Security Operations. The interesting tension is CyberArk: it wins more head-to-heads than it loses but almost never surfaces in AI discovery prompts — an absent giant. SentinelOne is the riser, gaining 28 points in recent months, while Microsoft Defender for Identity is the faller, dropping 16 points. The category is fragmented — five brands split discovery share within ten points of each other, and no single brand owns the evaluation stage.

172 discovery queries · 261 head-to-heads · refreshed Jul 27, 2026

Discovery stage

The shortlist

Across 172 buyer-style "SIEM" queries

Rapid7 shows up in 41% of SIEM discovery prompts across all five AI engines we track (ChatGPT, Claude, Gemini, Perplexity, Meta AI). Splunk and Microsoft Defender for Identity each surface in 50% of buyer queries but appear on only four of the five engines, leaving single-engine gaps. Elastic surfaces in 48% of discovery prompts across four engines, while LogRhythm SIEM trails at 23% with visibility on all five. The shortlist is fragmented — no brand breaks 50% discovery share across all engines.

4%13%22%31%41%Coverage — share of discovery prompts where the brand surfaces43%54%65%76%87%Engine diversity

Hover or click a logo to see brand details

X = coverage across discovery prompts · Y = engine diversity · Bubble size = total mentions
Tracked acrossChatGPT,Gemini,Claude

Get weekly AI visibility changes for SIEM sent to your inbox.

Score shifts, new entrants, citation gaps — every Monday.

Signal by intent

By topic

Top 5 most-cited brands per intent cluster. Brands with zero citations in a topic are not shown.

1Rapid7
7/10
2InsightIDR
7/10
3Google Security Operations
7/10
4Sumo
6/10
5Splunk Enterprise Security
6/10
1Google Security Operations
7/7
2LogRhythm SIEM
4/7
3Microsoft
3/7
4Splunk Enterprise Security
3/7
5Splunk
3/7
1Rapid7
6/7
2InsightIDR
5/7
3LogRhythm SIEM
5/7
4Sumo
5/7
5Graylog
4/7
1Microsoft
7/7
2Rapid7
7/7
3InsightIDR
7/7
4Elastic Security
7/7
5Splunk Enterprise Security
7/7
1Elastic Security
5/5
2Elastic
5/5
3Splunk
5/5
4Microsoft
5/5
5Splunk Enterprise Security
5/5
1Sumo
5/5
2Google Security Operations
5/5
3Expel
3/5
4Elastic Stack
3/5
5Red Canary
2/5
1Sumo
5/5
2Rapid7
5/5
3InsightIDR
5/5
4LogRhythm SIEM
4/5
5Google Security Operations
4/5
1Microsoft
5/5
2Elastic Security
5/5
3Elastic
5/5
4Splunk Enterprise Security
5/5
5Splunk
5/5
≥50% cited
25–49%
<25%
Topics are discovery-stage prompt clusters · siem

Evaluation stage

Head-to-head

How often AI cites each brand across uniform category evaluation prompts · median 7/100

When buyers ask AI to compare SIEM options head-to-head, Elastic Security and Google Security Operations each win half their matchups across 28 comparison queries. Splunk, Microsoft Sentinel, and Splunk Enterprise Security tie at 54 out of 100 across 30 head-to-heads — winning slightly more than they lose. Rapid7 loses more head-to-heads than it wins despite its wide discovery footprint, scoring 34 across 19 comparisons. ServiceNow scores 32 across 18 matchups, losing most fights.

0255075100Evaluation citation rate — % of category evaluation prompts citing this brand08152330Evaluation prompts cited inmedian citation ratemedian exposure

Hover or click a logo to see brand details

X = evaluation citation rate · Y = evaluation prompts cited in · Bubble size = citation exposure
Median citation rate 7/100

Each brand's score is the share of category evaluation prompts where AI cited them across all four engines — the same prompt pool for every brand. Brands above the median citation rate have stronger presence in evaluation-stage queries.

Citation sources

Where AI pulls citations from

657 citations captured across SIEM prompt runs.

Vendor pages

319

Product, help, and marketing pages from tracked vendors

Independent sources

248

Reviews, encyclopedias, forums, press — not vendor-owned

Buyer questions

What AI cites for top SIEM questions

Buyers ask AI for the best SIEM tools by deployment scale, vertical, and infrastructure type — phrasings like 'good SIEM software for mid-market firms with multiple locations', 'good SIEM software for large-scale IT infrastructures', 'how to manage security logs with SIEM'. A smaller slice digs into integration workflows and incident-response feature comparisons — 'how does SIEM integrate with existing security tools', 'how to evaluate the incident response features of SIEM solutions'. One prompt asks build-versus-buy directly.

Discovery

Buyers exploring the category

Evaluation

Buyers comparing options

Want to know if AI cites your brand for SIEM?

Free audit. ChatGPT, Perplexity, Gemini, Claude.

Run an audit →

See the full SIEM leaderboard →