Cybersecurity

Next-gen SIEM trends following the July outage and migration surges

CrowdStrike's Next-Gen SIEM reached $600 million in annual recurring revenues as IBM migrates QRadar clients to Falcon. The platform utilizes Charlotte AI to reduce manual investigation steps by up to 85 percent through an agentic SOC model.

Next-gen SIEM trends following the July outage and migration surges

CrowdStrike Next-Gen SIEM reached $600 million in ending annual recurring revenues in the first quarter of fiscal 2027. This growth makes it one of the largest businesses for the company outside endpoint security. The combined SIEM, Cloud, and Identity businesses now generate more than $2 billion in ending annual recurring revenues. This momentum follows a period of recovery after the July 2024 sensor update incident. IBM began sunsetting its QRadar SaaS business and designated Falcon Next-Gen SIEM as the preferred migration path for its global enterprise clients. A major fuel retailer also selected CrowdStrike to replace a legacy SIEM platform with a next-generation endpoint detection and response solution and software from a network security vendor in an 8-figure win. Organizations consolidate products onto a single platform to stop the management friction of disparate tools. Palo Alto Networks saw its Next-Gen Security annual recurring revenues increase 60% year over year. SentinelOne reported 23% growth in its annual recurring revenues. The Zacks Consensus Estimate for fiscal 2027 and 2028 revenues indicates a year-over-year increase of around 23.5% and 21.6%, respectively.

The 2026 Global Threat Report states the average adversary breakout time is 29 minutes, with the fastest recorded at 27 seconds. Adversaries move at machine speed, which requires AI-driven security operations to investigate and respond in real time. CrowdStrike delivers the next evolution of the agentic SOC where specialized agents and analysts work as one system. This production operating model allows experts and agents to stop breaches as one system. The platform uses Charlotte AI to coordinate fleets of battle-tested agents. These agents handle tasks including cross-domain investigations and proactive reconnaissance. CrowdStrike is building a platform where specialized agents, such as the RTR Remediation Agent and the Intel Reports Agent, coordinate under an orchestrator to automate investigations and reduce manual workload for security teams. Charlotte AI reduces manual investigation steps by up to 85 percent. This evolution includes a unified agentic SOAR workspace where Charlotte AI AgentWorks, SOAR orchestration, and Falcon Foundry converge into one place to build and govern rule-based and agentic automation alike. Teams also use certified data pipelines starting with Zscaler and Palo Alto Networks to ensure data arrives detection-ready. Microsoft also provides agents for Defender and Entra, but CrowdStrike relies on an orchestrator agent to coordinate specialized tasks. You might find the steep learning curve of the console frustrating if your team lacks experience. Does the move toward autonomous agents increase the risk of unmanaged automation?

Falcon LogScale handles petabyte-scale data using an index-free architecture. This approach eliminates the traditional indexing overhead required by systems like Splunk or Elasticsearch. The platform compresses log data at a 6x to 80x reduction ratio. This allows teams to search unstructured log data in real time without the storage costs of index-heavy systems. LogScale can ingest up to 1 petabyte of data per day and provides sub-second query latency. The platform supports cold storage tiering, where older data moves to object storage like AWS S3 or Azure Blob, and data remains searchable without rehydration. CrowdStream, which uses Cribl technology, enables data enrichment, normalization, and filtering before logs hit storage. This process reduces noise and storage costs by dropping irrelevant events at the edge. The integration with SailPoint SecOps Identity Intelligence brings identity governance and access data for human, machine, and AI identities into Falcon workflows. This allows analysts to correlate SailPoint insights with endpoint, cloud, and threat intelligence telemetry. Users can deploy LogScale in fully managed cloud, self-hosted, or hybrid models.

Feature Detail
Next-Gen SIEM ARR Over $600 million
LogScale Compression 6x to 80x reduction
Charlotte AI Benefit 85% reduction in manual steps
Fastest Breakout Time 27 seconds