CiteWorks Studio

How AI Search Is Recommending SIEM Software: Monthly Trends

Mark HuntleyBy Mark HuntleyFounder and CEO
9 minutes read

Key Takeaways

  • Splunk remained the SIEM software leader in August 2026 with 42.0% valid recommendation coverage, widening its lead to 6.4 points over second place.
  • Microsoft Sentinel entered the benchmark at 35.6% coverage and posted the highest rank-one rate, top-three rate, and strong raw mention presence in its first tracked month.
  • Most other brands moved within normal month-to-month range, with IBM QRadar and Elastic Security staying in the middle tier below the two leading brands.
  • Microsoft SharePoint fell from a small July baseline to zero valid recommendations in August, reflecting a roster change and low-count movement rather than a major incumbent decline.

Executive Summary

Splunk remains the category leader in August 2026, holding 42.0% valid recommendation coverage, up 6.2 points from a 35.8% baseline in July 2026. That gain sits within normal month-to-month range for the brand, so Splunk's leadership is classified as stable rather than a significant move. Splunk holds a 6.4-point gap over the second-place brand.

Microsoft Sentinel entered the tracked benchmark in August 2026 at 35.6% valid recommendation coverage, based on 151 valid recommendations across 424 qualified observations. It is the category's only significant riser this month and immediately places second overall. It also posted the highest rank-one rate in the category at 12.7% (54 placements), the highest top-three rate at 21.2% (90 placements), and raw mention presence of 77.1% (327 mentions). Microsoft SharePoint was the month's only significant decliner, falling from 2.0% coverage in July 2026 (7 valid recommendations) to no valid recommendations in August 2026.

The remaining field moved within normal range. IBM QRadar rose 1.6 points to 19.1%, Google Chronicle rose 3.8 points to 12.0%, and Elastic Security rose 0.7 points to 17.9%. Exabeam, Sumo Logic, and Rapid7 InsightIDR posted modest declines, while Securonix edged up slightly; none of these movements were significant. Because Microsoft Sentinel and Microsoft SharePoint reflect entry into and exit from the tracked brand roster rather than a like-for-like comparison of an existing brand, their movement should be read as a roster change rather than a shift in an incumbent's performance.

This benchmark tracked 800 prompt-surface observations (596 unique questions) in August 2026, up from 787 observations (526 unique questions) in July 2026. Of these, 760 mentioned a tracked brand or competitor in August 2026 (786 in July 2026); 606 were relevant and 154 irrelevant in August 2026 (507 relevant, 279 irrelevant in July 2026). The public benchmark uses the 424 qualified observations in August 2026 (355 in July 2026) that survived both qualification stages.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Aug 2026

  • Splunk+6.2%
    Jul 202635.8%
    Aug 202642.0%
  • Microsoft Sentinel+35.6% · beyond normal variation
    Jul 20260.0%
    Aug 202635.6%
  • IBM QRadar+1.6%
    Jul 202617.5%
    Aug 202619.1%
  • Elastic Security+0.7%
    Jul 202617.2%
    Aug 202617.9%
  • Rapid7 InsightIDR-0.5%
    Jul 202613.5%
    Aug 202613.0%
  • Google Chronicle+3.8%
    Jul 20268.2%
    Aug 202612.0%
  • Securonix+0.2%
    Jul 20269.9%
    Aug 202610.1%
  • Exabeam-3.8%
    Jul 202611.3%
    Aug 20267.5%
  • Sumo Logic-2.7%
    Jul 20266.2%
    Aug 20263.5%
  • Microsoft SharePoint-2.0% · beyond normal variation
    Jul 20262.0%
    Aug 20260.0%

Key Findings

Signal

August 2026 finding

Category leader

Splunk at 42.0% valid recommendation coverage

Significant riser

Microsoft Sentinel at 35.6% coverage, entering the benchmark in its first tracked month

Significant decliner

Microsoft SharePoint down 2.0 points to 0.0% coverage

Rank-one leader

Microsoft Sentinel at 12.7% rank-one rate, with 54 rank-one placements

Highest presence

Splunk at 92.9% raw mention presence, on 394 mentions

Qualified observations

424 observations across 6 AI/search surface families

Benchmark Context

The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.

Research stage

Jul 2026

Aug 2026

What it represents

Source prompt-surface observations collected

787

800

Raw prompt-surface observations gathered

Unique questions

526

596

Distinct questions represented

Brand / competitor mentions

786

760

Prompts mentioning a tracked brand or competitor

Relevant prompts

507

606

Prompts relevant to the vertical

Irrelevant prompts

279

154

Prompts not relevant to the vertical

Qualified benchmark observations

355

424

Public denominator for all metrics

Qualified surface breadth

6

6

AI surface families with at least one qualified observation

Fewer irrelevant prompts and a larger unique-question base produced a bigger qualified benchmark set in August 2026, which is the denominator used for every brand-level metric below.

Benchmark-Level Metrics

Metric

Jul 2026

Aug 2026

Change

Qualified observations

355

424

Up 69

Companies tracked

9

9

No change

Recommendation-shaped answer share

25.4%

18.4%

Down 7.0 points

Valid recommendation shortlist share

39.4%

34.2%

Down 5.2 points

Category leader by coverage

Splunk

Splunk

No change

The July 2026 run produced 90 recommendation-shaped answers (25.4% share) and 140 valid recommendation shortlists (39.4% share) from 355 qualified observations. The August 2026 run produced 78 recommendation-shaped answers (18.4% share) and 145 valid recommendation shortlists (34.2% share) from 424 qualified observations. July's response mix included 75 recommendation shortlists, 51 comparison analyses, 40 ranked lists, and 7 pricing analyses, versus 65 recommendation shortlists, 41 comparison analyses, 63 ranked lists, and 3 pricing analyses in August.

AI Recommendation Trend

Splunk and Microsoft Sentinel form a two-brand leadership structure at the top of the category, 6.4 points apart. The remaining field sits below 20% coverage, with IBM QRadar and Elastic Security forming a middle cluster.

Valid Recommendation Coverage by Brand

Brand

Jul 2026

Aug 2026

Movement

Aug 2026 rank

Splunk

35.8%

42.0%

Up 6.2 points

1st

Microsoft Sentinel

0.0%

35.6%

Up 35.6 points

2nd

IBM QRadar

17.5%

19.1%

Up 1.6 points

3rd

Elastic Security

17.2%

17.9%

Up 0.7 points

4th

Rapid7 InsightIDR

13.5%

13.0%

Down 0.5 points

5th

Google Chronicle

8.2%

12.0%

Up 3.8 points

6th

Securonix

9.9%

10.1%

Up 0.2 points

7th

Exabeam

11.3%

7.5%

Down 3.8 points

8th

Sumo Logic

6.2%

3.5%

Down 2.7 points

9th

Microsoft SharePoint

2.0%

0.0%

Down 2.0 points

10th

The category's movement this month reflects one significant new entrant, Microsoft Sentinel, and one significant exit, Microsoft SharePoint; every other brand's movement fell within normal month-to-month range.

What Changed This Month

Microsoft Sentinel Entered the Benchmark at Scale

Microsoft Sentinel was not tracked in the July 2026 benchmark and entered in August 2026 with 35.6% valid recommendation coverage, based on 151 valid recommendations from 424 qualified observations. This is the largest single-month movement in the series and is classified as a significant riser.

The brand recorded a 12.7% rank-one rate with 54 rank-one placements, a 21.2% top-three rate with 90 placements, and a 26.2% top-ten rate with 111 placements. Its raw mention presence was 77.1%, on 327 mentions across 424 observations. Net sentiment was 0.5.

The distinction to notice is that Microsoft Sentinel's presence and recommendation performance arrived together. It was surfaced widely and recommended frequently, not merely mentioned in passing. Both signals are strong in the first month of measurement.

Highest-priority diagnostic: Which prompt types and surfaces are driving Microsoft Sentinel's 151 valid recommendations, and which brands lose the recommendation when it appears?

Microsoft SharePoint Fell Out of Measurable Coverage

Microsoft SharePoint moved from 2.0% valid recommendation coverage in July 2026 (7 valid recommendations from 355 qualified observations) to 0.0% in August 2026 (no valid recommendations from 424 qualified observations). The drop of 2.0 points is classified as a significant decliner.

In July 2026, Microsoft SharePoint recorded a 1.1% top-three rate with 4 placements, a 0.9% rank-one rate with 3 placements, and 4.2% raw mention presence on 15 mentions. In August 2026, the brand no longer appears in the qualified benchmark metrics, with no current-month values for presence, top-three, or rank-one rates.

The distinction to notice is that this is a small-count movement. The July baseline itself was thin, at 7 valid recommendations, so the move to zero reflects a brand that was already marginal in the category rather than a decline from a strong position.

Highest-priority diagnostic: Which surface or prompt pattern produced Microsoft SharePoint's 7 July valid recommendations, and has the underlying query intent shifted to other tools?

Exabeam and Sumo Logic Showed the Sharpest Downward Movement

Exabeam moved from 11.3% valid recommendation coverage in July 2026 (40 valid recommendations) to 7.5% in August 2026 (32 valid recommendations), down 3.8 points, which falls within normal month-to-month range for this brand. Its top-three rate fell from 4.8% to 1.4%, and its rank-one rate fell from 2.8% (10 placements) to 0.9% (4 placements).

Sumo Logic moved from 6.2% coverage in July 2026 (22 valid recommendations) to 3.5% in August 2026 (15 valid recommendations), down 2.7 points. Its top-three rate fell from 3.1% to 0.9%, and its raw mention presence fell from 13.0% to 10.1%.

The distinction to notice is that both brands lost recommendation share at a similar or faster rate than their presence fell. Exabeam's presence fell from 21.7% to 19.3% while coverage fell 3.8 points; Sumo Logic's presence fell from 13.0% to 10.1% while coverage fell 2.7 points. The data describes brands that are being mentioned somewhat less often and recommended less often when mentioned; it does not establish why.

Highest-priority diagnostic: For Exabeam, which surface family accounts for the loss of top-three placements, and for Sumo Logic, which competing brand now takes the recommendation it previously captured?

Splunk Extended Its Lead While Remaining Stable

Splunk rose from 35.8% valid recommendation coverage in July 2026 (127 valid recommendations) to 42.0% in August 2026 (178 valid recommendations), up 6.2 points. This movement falls within normal month-to-month range, keeping Splunk classified as stable despite the gain.

Splunk's top-three rate fell from 30.7% to 25.5%, and its rank-one rate fell from 13.5% to 9.9%. Raw mention presence rose from 90.4% to 92.9%, on 394 mentions. Net sentiment was 0.5, down from 0.6.

The distinction to notice is that Splunk's coverage gain came alongside a lower top-three and rank-one rate. It is being recommended in more responses, while its share of the most prominent placements narrowed over the same period.

Highest-priority diagnostic: Which response types and surfaces account for Splunk's 51 additional valid recommendations, and where did its displaced top-three and rank-one placements go?

Buyer-Intent Interpretation

Buyer-intent cluster

What it captures

Strategic question

Brand Recommendation

Direct asks for the best or a recommended SIEM solution

Which brand does the AI name first, and in what context?

Pricing & Value

Queries about cost, pricing models, or value for money

What does the AI say about cost, and whose pricing is surfaced?

Multi-Brand Comparison

Head-to-head comparisons between named options

Which brand wins the comparison, and on which criteria?

All 424 qualified observations in August 2026 and all 355 in July 2026 fell into the Brand Recommendation cluster. There were no qualified observations in the Pricing & Value or Multi-Brand Comparison clusters in either month. The public benchmark can therefore answer which brands AI systems recommend for SIEM software, but it cannot yet answer how AI systems compare options head-to-head or how they frame pricing and value. Those commercial questions remain outside the current benchmark's reach.

Brand Opportunity Summary

Brand

Aug 2026 coverage

Current signal

Highest-priority diagnostic

Splunk

42.0%

Coverage leader, stable; top-three and rank-one rates fell

Which surfaces and prompts drove the 51 new valid recommendations, and where did top-three placements go?

Microsoft Sentinel

35.6%

Significant riser, category entrant at scale

Which prompt and surface patterns produced 151 valid recommendations in the first tracked month?

IBM QRadar

19.1%

Stable; presence up 5.8 points but top-three rate down

Why did raw presence rise 5.8 points while the top-three rate fell 3.8 points?

Elastic Security

17.9%

Stable; slight coverage gain

Which prompt types converted into the 15 additional valid recommendations?

Rapid7 InsightIDR

13.0%

Stable; rank-one placements lost

What accounted for the loss of all 4 rank-one placements from July?

Google Chronicle

12.0%

Stable; coverage up 3.8 points

Which surfaces contributed the 22 additional valid recommendations, and why did sentiment decline?

Securonix

10.1%

Stable; coverage flat

Which prompts sustain the 43 valid recommendations despite a falling top-three rate?

Exabeam

7.5%

Stable; top-three rate fell

Which surface family lost the 11 top-three placements between July and August?

Sumo Logic

3.5%

Stable; top-three rate fell

Which competitors now capture the recommendations Sumo Logic lost?

Microsoft SharePoint

0.0%

Significant decliner, no valid recommendations

What underlying query or surface change removed the brand from measurable coverage?

The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why.

Evidence Behind the Benchmark

The aggregate metrics are built from prompt-level observations (query, surface, recommendation outcome, rank, sentiment, and citations where exposed). Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.

Interpretation Notes

  • This two-month series relies on small observation counts for several brands. Microsoft SharePoint's July baseline rests on 7 valid recommendations, and Sumo Logic's August result rests on 15; movement in these figures should be read with that context in mind.
  • All percentages are calculated against the qualified benchmark denominator (355 observations in July 2026, 424 in August 2026), not the larger raw collection universe.
  • Month-over-month movement identifies changes worth investigating; it does not by itself establish the cause of those changes.
  • Microsoft Sentinel and Microsoft SharePoint changes reflect the brands' entry into and exit from the tracked benchmark, not a like-for-like comparison across both months for either brand.

Next Step

The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.

The aggregate percentages leave the most commercially important questions unanswered: which high-intent prompts does a brand win, which competitor takes the recommendation when a brand loses, what attributes does the AI associate with each option, and which external sources shape those answers? These patterns sit beneath the coverage rate and determine whether a brand's position is durable or vulnerable.

A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy. It converts the benchmark's category-level signals into actionable intelligence for a single brand.

Request an AI visibility audit

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT