Out nowThe Citation EconomyBuy on Amazon →

Subcategory · AI Citation Index

SIEM

SIEM is AI's clearest duopoly. Splunk and Splunk Enterprise Security each surface in 67% of buyer queries across all five engines (ChatGPT, Claude, Gemini, Perplexity, and a fifth in rotation), while Microsoft Defender for Identity matches that shortlist rate with the highest raw mention volume in the category. When buyers ask AI to compare options head-to-head, Splunk and Microsoft Sentinel tie at 54 out of 100 — both win more matchups than they lose, but neither dominates. Elastic Security and Google Security Operations land at 50, trading wins depending on the prompt. SentinelOne is the riser, gaining 28 points in head-to-head scoring over the past quarter while Microsoft Defender for Identity falls 16 points. This is a contested category — no single brand owns AI attention, and the top tier trades citations one-for-one across engines.

172 discovery queries · 261 head-to-heads · refreshed Aug 16, 2026

Discovery stage

The shortlist

Across 172 buyer-style "SIEM" queries

Splunk and Microsoft Defender for Identity each show up in 67% of discovery queries about SIEM software, surfacing across every engine we track. Splunk Enterprise Security matches that rate with nearly identical mention volume. Elastic lands in 65% of queries but is absent on one engine, leaving single-engine fragility. Rapid7 trails at 41%, visible across all five engines but only half as likely to surface as the top tier. Wazuh, the open-source option, appears in 23% of queries — consistent across engines but a distant sixth in share of attention.

16%30%45%59%73%Coverage — share of discovery prompts where the brand surfaces43%54%66%77%89%Engine diversity

Hover or click a logo to see brand details

X = coverage across discovery prompts · Y = engine diversity · Bubble size = total mentions
Tracked acrossChatGPT,Gemini,Claude

Get weekly AI visibility changes for SIEM sent to your inbox.

Score shifts, new entrants, citation gaps — every Monday.

Signal by intent

By topic

Top 5 most-cited brands per intent cluster. Brands with zero citations in a topic are not shown.

1Splunk Enterprise Security
10/10
2Microsoft
10/10
3Elastic Security
10/10
4Elastic
10/10
5Splunk
10/10
1Microsoft
7/7
2Splunk Enterprise Security
7/7
3Splunk
7/7
4Google Security Operations
7/7
5Elastic Security
7/7
1Microsoft
7/7
2Wazuh
7/7
3Splunk
7/7
4Elastic
7/7
5Elastic Security
7/7
1Microsoft
7/7
2Rapid7
7/7
3InsightIDR
7/7
4Elastic Security
7/7
5Splunk Enterprise Security
7/7
1Wazuh
5/5
2Elastic Security
5/5
3Elastic
5/5
4Splunk
5/5
5Microsoft
5/5
1Elastic Security
5/5
2Elastic
5/5
3Panther
5/5
4Sumo Logic
5/5
5Microsoft
5/5
1Microsoft
5/5
2Elastic Security
5/5
3Splunk Enterprise Security
5/5
4Sumo Logic
5/5
5Splunk
5/5
1Microsoft
5/5
2Elastic Security
5/5
3Elastic
5/5
4Splunk Enterprise Security
5/5
5Splunk
5/5
≥50% cited
25–49%
<25%
Topics are discovery-stage prompt clusters · siem

Evaluation stage

Head-to-head

How often AI cites each brand across uniform category evaluation prompts · median 7/100

Splunk and Microsoft Sentinel tie for head-to-head wins, each scoring 54 across 30 comparison queries — both win more matchups than they lose, but neither pulls ahead. Elastic Security and Google Security Operations land at 50, trading wins depending on the prompt pairing. Sumo Logic scores 39, losing more head-to-heads than it wins, while Rapid7 and ServiceNow trail at 34 and 32 — both surface in comparison queries but rarely come out as the picked answer.

0255075100Evaluation citation rate — % of category evaluation prompts citing this brand08152330Evaluation prompts cited inmedian citation ratemedian exposure

Hover or click a logo to see brand details

X = evaluation citation rate · Y = evaluation prompts cited in · Bubble size = citation exposure
Median citation rate 7/100

Each brand's score is the share of category evaluation prompts where AI cited them across all four engines — the same prompt pool for every brand. Brands above the median citation rate have stronger presence in evaluation-stage queries.

Citation sources

Where AI pulls citations from

657 citations captured across SIEM prompt runs.

Vendor pages

319

Product, help, and marketing pages from tracked vendors

Independent sources

248

Reviews, encyclopedias, forums, press — not vendor-owned

Buyer questions

What AI cites for top SIEM questions

Buyers ask AI for SIEM tools by scale and deployment context — phrasings like 'good SIEM software for mid-market firms with multiple locations', 'SIEM for large-scale IT infrastructures'. A second slice digs into workflows and integrations: 'how to manage security logs with SIEM', 'how does SIEM integrate with existing security tools'. A smaller set of queries explores build-versus-buy tradeoffs and incident response features. The questions stay operational — naming team sizes, infrastructure constraints, and feature-level requirements.

Discovery

Buyers exploring the category

Evaluation

Buyers comparing options

Want to know if AI cites your brand for SIEM?

Free audit. ChatGPT, Perplexity, Gemini, Claude.

Run an audit →

See the full SIEM leaderboard →