Imply Lumi Integrates SIEM Tools & AI Agents to Expand Security Data Access

www.news4hackers.com-imply-lumi-integrates-siem-tools-ai-agents-to-expand-security-data-access-imply-lumi-integrates-siem-tools-ai-agents-to-expand-security-data-access

Imply has introduced a new approach to integrating security information and event management (SIEM) systems with artificial intelligence (AI) capabilities, enabling broader access to security data.

Evolution of SIEM Architecture

The company’s expanded vision addresses evolving challenges in handling vast data volumes and improving analytical efficiency. Traditional SIEM systems were designed for an earlier technological landscape, where security platforms could process, store, and query all log data within a single environment. As data growth accelerates, this model becomes increasingly costly to scale, compelling security teams to prioritize which data to retain and for how long. The integration of AI further complicates this dynamic, as AI agents do not halt after initial responses. When analyzing alerts, these agents generate follow-up queries that often require accessing additional data sources and historical records beyond the scope of conventional detection rules. This necessitates a more flexible architecture capable of maintaining broader data accessibility and managing unpredictable search demands.

“The SIEM isn’t going away, but the architecture beneath it must evolve,” stated Eric Tschetter, chief architect at Imply. “The goal is not merely to reduce costs but to allow organizations to preserve and access significantly more security data while maintaining their existing tools and workflows.”

Imply Lumi: A Unified Security Data Layer

Similar to data platforms that decoupled low-cost object storage from computing resources, security teams now face an opportunity to retain extensive data in a security data lake while ensuring rapid accessibility for both traditional SIEMs and modern AI agents. Imply Lumi offers a unified security data layer that supports existing SIEM tools and AI agents, enabling organizations to expand data access without requiring data migration into a single system. This solution provides security teams and AI agents with immediate access to data regardless of its location, eliminating the need to consolidate all information into a SIEM first. Users can query both indexed data and unstructured logs stored in object storage using familiar query languages such as SPL and SQL, enhancing the availability of historical security data for investigations without disrupting established workflows. By separating storage, computational resources, and access controls, Lumi allows organizations to retain extended security histories in cost-effective object storage while scaling search capabilities based on demand. This approach ensures that security teams can leverage their existing tools while making more data available for analysis and AI-driven insights.

“With Imply Lumi, we can ingest more data, retain it for longer periods, integrate telemetry from platforms beyond Splunk, and maintain visibility into scaling costs,” said Rafael Hass, security information manager at BTG Pactual.



About Author

en_USEnglish