How AI Search Is Recommending SIEM Software: Monthly Trends
This analysis is based on the source benchmark: SIEM Software: 2026 AI Market Discovery Index
Key Takeaways
- Splunk remained the SIEM software leader in August 2026 with 42.0% valid recommendation coverage, widening its lead to 6.4 points over second place.
- Microsoft Sentinel entered the benchmark at 35.6% coverage and posted the highest rank-one rate, top-three rate, and strong raw mention presence in its first tracked month.
- Most other brands moved within normal month-to-month range, with IBM QRadar and Elastic Security staying in the middle tier below the two leading brands.
- Microsoft SharePoint fell from a small July baseline to zero valid recommendations in August, reflecting a roster change and low-count movement rather than a major incumbent decline.
Executive Summary
Splunk remains the category leader in August 2026, holding 42.0% valid recommendation coverage, up 6.2 points from a 35.8% baseline in July 2026. That gain sits within normal month-to-month range for the brand, so Splunk's leadership is classified as stable rather than a significant move. Splunk holds a 6.4-point gap over the second-place brand.
Microsoft Sentinel entered the tracked benchmark in August 2026 at 35.6% valid recommendation coverage, based on 151 valid recommendations across 424 qualified observations. It is the category's only significant riser this month and immediately places second overall. It also posted the highest rank-one rate in the category at 12.7% (54 placements), the highest top-three rate at 21.2% (90 placements), and raw mention presence of 77.1% (327 mentions). Microsoft SharePoint was the month's only significant decliner, falling from 2.0% coverage in July 2026 (7 valid recommendations) to no valid recommendations in August 2026.
The remaining field moved within normal range. IBM QRadar rose 1.6 points to 19.1%, Google Chronicle rose 3.8 points to 12.0%, and Elastic Security rose 0.7 points to 17.9%. Exabeam, Sumo Logic, and Rapid7 InsightIDR posted modest declines, while Securonix edged up slightly; none of these movements were significant. Because Microsoft Sentinel and Microsoft SharePoint reflect entry into and exit from the tracked brand roster rather than a like-for-like comparison of an existing brand, their movement should be read as a roster change rather than a shift in an incumbent's performance.
This benchmark tracked 800 prompt-surface observations (596 unique questions) in August 2026, up from 787 observations (526 unique questions) in July 2026. Of these, 760 mentioned a tracked brand or competitor in August 2026 (786 in July 2026); 606 were relevant and 154 irrelevant in August 2026 (507 relevant, 279 irrelevant in July 2026). The public benchmark uses the 424 qualified observations in August 2026 (355 in July 2026) that survived both qualification stages.
AI recommendation trend
valid recommendation coverage, Jul 2026 to Aug 2026
- Splunk+6.2%Jul 202635.8%Aug 202642.0%
- Microsoft Sentinel+35.6% · beyond normal variationJul 20260.0%Aug 202635.6%
- IBM QRadar+1.6%Jul 202617.5%Aug 202619.1%
- Elastic Security+0.7%Jul 202617.2%Aug 202617.9%
- Rapid7 InsightIDR-0.5%Jul 202613.5%Aug 202613.0%
- Google Chronicle+3.8%Jul 20268.2%Aug 202612.0%
- Securonix+0.2%Jul 20269.9%Aug 202610.1%
- Exabeam-3.8%Jul 202611.3%Aug 20267.5%
- Sumo Logic-2.7%Jul 20266.2%Aug 20263.5%
- Microsoft SharePoint-2.0% · beyond normal variationJul 20262.0%Aug 20260.0%
Key Findings
Signal | August 2026 finding |
|---|---|
Category leader | Splunk at 42.0% valid recommendation coverage |
Significant riser | Microsoft Sentinel at 35.6% coverage, entering the benchmark in its first tracked month |
Significant decliner | Microsoft SharePoint down 2.0 points to 0.0% coverage |
Rank-one leader | Microsoft Sentinel at 12.7% rank-one rate, with 54 rank-one placements |
Highest presence | Splunk at 92.9% raw mention presence, on 394 mentions |
Qualified observations | 424 observations across 6 AI/search surface families |
Benchmark Context
The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.
Research stage | Jul 2026 | Aug 2026 | What it represents |
|---|---|---|---|
Source prompt-surface observations collected | 787 | 800 | Raw prompt-surface observations gathered |
Unique questions | 526 | 596 | Distinct questions represented |
Brand / competitor mentions | 786 | 760 | Prompts mentioning a tracked brand or competitor |
Relevant prompts | 507 | 606 | Prompts relevant to the vertical |
Irrelevant prompts | 279 | 154 | Prompts not relevant to the vertical |
Qualified benchmark observations | 355 | 424 | Public denominator for all metrics |
Qualified surface breadth | 6 | 6 | AI surface families with at least one qualified observation |
Fewer irrelevant prompts and a larger unique-question base produced a bigger qualified benchmark set in August 2026, which is the denominator used for every brand-level metric below.
Benchmark-Level Metrics
Metric | Jul 2026 | Aug 2026 | Change |
|---|---|---|---|
Qualified observations | 355 | 424 | Up 69 |
Companies tracked | 9 | 9 | No change |
Recommendation-shaped answer share | 25.4% | 18.4% | Down 7.0 points |
Valid recommendation shortlist share | 39.4% | 34.2% | Down 5.2 points |
Category leader by coverage | Splunk | Splunk | No change |
The July 2026 run produced 90 recommendation-shaped answers (25.4% share) and 140 valid recommendation shortlists (39.4% share) from 355 qualified observations. The August 2026 run produced 78 recommendation-shaped answers (18.4% share) and 145 valid recommendation shortlists (34.2% share) from 424 qualified observations. July's response mix included 75 recommendation shortlists, 51 comparison analyses, 40 ranked lists, and 7 pricing analyses, versus 65 recommendation shortlists, 41 comparison analyses, 63 ranked lists, and 3 pricing analyses in August.
AI Recommendation Trend
Splunk and Microsoft Sentinel form a two-brand leadership structure at the top of the category, 6.4 points apart. The remaining field sits below 20% coverage, with IBM QRadar and Elastic Security forming a middle cluster.
Valid Recommendation Coverage by Brand
Brand | Jul 2026 | Aug 2026 | Movement | Aug 2026 rank |
|---|---|---|---|---|
Splunk | 35.8% | 42.0% | Up 6.2 points | 1st |
Microsoft Sentinel | 0.0% | 35.6% | Up 35.6 points | 2nd |
IBM QRadar | 17.5% | 19.1% | Up 1.6 points | 3rd |
Elastic Security | 17.2% | 17.9% | Up 0.7 points | 4th |
Rapid7 InsightIDR | 13.5% | 13.0% | Down 0.5 points | 5th |
Google Chronicle | 8.2% | 12.0% | Up 3.8 points | 6th |
Securonix | 9.9% | 10.1% | Up 0.2 points | 7th |
Exabeam | 11.3% | 7.5% | Down 3.8 points | 8th |
Sumo Logic | 6.2% | 3.5% | Down 2.7 points | 9th |
Microsoft SharePoint | 2.0% | 0.0% | Down 2.0 points | 10th |
The category's movement this month reflects one significant new entrant, Microsoft Sentinel, and one significant exit, Microsoft SharePoint; every other brand's movement fell within normal month-to-month range.
What Changed This Month
Microsoft Sentinel Entered the Benchmark at Scale
Microsoft Sentinel was not tracked in the July 2026 benchmark and entered in August 2026 with 35.6% valid recommendation coverage, based on 151 valid recommendations from 424 qualified observations. This is the largest single-month movement in the series and is classified as a significant riser.
The brand recorded a 12.7% rank-one rate with 54 rank-one placements, a 21.2% top-three rate with 90 placements, and a 26.2% top-ten rate with 111 placements. Its raw mention presence was 77.1%, on 327 mentions across 424 observations. Net sentiment was 0.5.
The distinction to notice is that Microsoft Sentinel's presence and recommendation performance arrived together. It was surfaced widely and recommended frequently, not merely mentioned in passing. Both signals are strong in the first month of measurement.
Highest-priority diagnostic: Which prompt types and surfaces are driving Microsoft Sentinel's 151 valid recommendations, and which brands lose the recommendation when it appears?
Microsoft SharePoint Fell Out of Measurable Coverage
Microsoft SharePoint moved from 2.0% valid recommendation coverage in July 2026 (7 valid recommendations from 355 qualified observations) to 0.0% in August 2026 (no valid recommendations from 424 qualified observations). The drop of 2.0 points is classified as a significant decliner.
In July 2026, Microsoft SharePoint recorded a 1.1% top-three rate with 4 placements, a 0.9% rank-one rate with 3 placements, and 4.2% raw mention presence on 15 mentions. In August 2026, the brand no longer appears in the qualified benchmark metrics, with no current-month values for presence, top-three, or rank-one rates.
The distinction to notice is that this is a small-count movement. The July baseline itself was thin, at 7 valid recommendations, so the move to zero reflects a brand that was already marginal in the category rather than a decline from a strong position.
Highest-priority diagnostic: Which surface or prompt pattern produced Microsoft SharePoint's 7 July valid recommendations, and has the underlying query intent shifted to other tools?
Exabeam and Sumo Logic Showed the Sharpest Downward Movement
Exabeam moved from 11.3% valid recommendation coverage in July 2026 (40 valid recommendations) to 7.5% in August 2026 (32 valid recommendations), down 3.8 points, which falls within normal month-to-month range for this brand. Its top-three rate fell from 4.8% to 1.4%, and its rank-one rate fell from 2.8% (10 placements) to 0.9% (4 placements).
Sumo Logic moved from 6.2% coverage in July 2026 (22 valid recommendations) to 3.5% in August 2026 (15 valid recommendations), down 2.7 points. Its top-three rate fell from 3.1% to 0.9%, and its raw mention presence fell from 13.0% to 10.1%.
The distinction to notice is that both brands lost recommendation share at a similar or faster rate than their presence fell. Exabeam's presence fell from 21.7% to 19.3% while coverage fell 3.8 points; Sumo Logic's presence fell from 13.0% to 10.1% while coverage fell 2.7 points. The data describes brands that are being mentioned somewhat less often and recommended less often when mentioned; it does not establish why.
Highest-priority diagnostic: For Exabeam, which surface family accounts for the loss of top-three placements, and for Sumo Logic, which competing brand now takes the recommendation it previously captured?
Splunk Extended Its Lead While Remaining Stable
Splunk rose from 35.8% valid recommendation coverage in July 2026 (127 valid recommendations) to 42.0% in August 2026 (178 valid recommendations), up 6.2 points. This movement falls within normal month-to-month range, keeping Splunk classified as stable despite the gain.
Splunk's top-three rate fell from 30.7% to 25.5%, and its rank-one rate fell from 13.5% to 9.9%. Raw mention presence rose from 90.4% to 92.9%, on 394 mentions. Net sentiment was 0.5, down from 0.6.
The distinction to notice is that Splunk's coverage gain came alongside a lower top-three and rank-one rate. It is being recommended in more responses, while its share of the most prominent placements narrowed over the same period.
Highest-priority diagnostic: Which response types and surfaces account for Splunk's 51 additional valid recommendations, and where did its displaced top-three and rank-one placements go?
Buyer-Intent Interpretation
Buyer-intent cluster | What it captures | Strategic question |
|---|---|---|
Brand Recommendation | Direct asks for the best or a recommended SIEM solution | Which brand does the AI name first, and in what context? |
Pricing & Value | Queries about cost, pricing models, or value for money | What does the AI say about cost, and whose pricing is surfaced? |
Multi-Brand Comparison | Head-to-head comparisons between named options | Which brand wins the comparison, and on which criteria? |
All 424 qualified observations in August 2026 and all 355 in July 2026 fell into the Brand Recommendation cluster. There were no qualified observations in the Pricing & Value or Multi-Brand Comparison clusters in either month. The public benchmark can therefore answer which brands AI systems recommend for SIEM software, but it cannot yet answer how AI systems compare options head-to-head or how they frame pricing and value. Those commercial questions remain outside the current benchmark's reach.
Brand Opportunity Summary
Brand | Aug 2026 coverage | Current signal | Highest-priority diagnostic |
|---|---|---|---|
Splunk | 42.0% | Coverage leader, stable; top-three and rank-one rates fell | Which surfaces and prompts drove the 51 new valid recommendations, and where did top-three placements go? |
Microsoft Sentinel | 35.6% | Significant riser, category entrant at scale | Which prompt and surface patterns produced 151 valid recommendations in the first tracked month? |
IBM QRadar | 19.1% | Stable; presence up 5.8 points but top-three rate down | Why did raw presence rise 5.8 points while the top-three rate fell 3.8 points? |
Elastic Security | 17.9% | Stable; slight coverage gain | Which prompt types converted into the 15 additional valid recommendations? |
Rapid7 InsightIDR | 13.0% | Stable; rank-one placements lost | What accounted for the loss of all 4 rank-one placements from July? |
Google Chronicle | 12.0% | Stable; coverage up 3.8 points | Which surfaces contributed the 22 additional valid recommendations, and why did sentiment decline? |
Securonix | 10.1% | Stable; coverage flat | Which prompts sustain the 43 valid recommendations despite a falling top-three rate? |
Exabeam | 7.5% | Stable; top-three rate fell | Which surface family lost the 11 top-three placements between July and August? |
Sumo Logic | 3.5% | Stable; top-three rate fell | Which competitors now capture the recommendations Sumo Logic lost? |
Microsoft SharePoint | 0.0% | Significant decliner, no valid recommendations | What underlying query or surface change removed the brand from measurable coverage? |
The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why.
Evidence Behind the Benchmark
The aggregate metrics are built from prompt-level observations (query, surface, recommendation outcome, rank, sentiment, and citations where exposed). Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.
- AI Industry Market Discovery
- AI Industry Market Discovery Methodology
- AI Industry Market Discovery Metrics
- AI Industry Market Discovery Standards
Interpretation Notes
- This two-month series relies on small observation counts for several brands. Microsoft SharePoint's July baseline rests on 7 valid recommendations, and Sumo Logic's August result rests on 15; movement in these figures should be read with that context in mind.
- All percentages are calculated against the qualified benchmark denominator (355 observations in July 2026, 424 in August 2026), not the larger raw collection universe.
- Month-over-month movement identifies changes worth investigating; it does not by itself establish the cause of those changes.
- Microsoft Sentinel and Microsoft SharePoint changes reflect the brands' entry into and exit from the tracked benchmark, not a like-for-like comparison across both months for either brand.
Next Step
The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.
The aggregate percentages leave the most commercially important questions unanswered: which high-intent prompts does a brand win, which competitor takes the recommendation when a brand loses, what attributes does the AI associate with each option, and which external sources shape those answers? These patterns sit beneath the coverage rate and determine whether a brand's position is durable or vulnerable.
A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy. It converts the benchmark's category-level signals into actionable intelligence for a single brand.
/ Take the next step
Want to Understand Your AI Citation Footprint?
We start every engagement with a full audit of how AI systems reference your brand today.
Measurable, Repeatable Programme
Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge
Citation Architecture Review
Identify which high-authority community sources are and aren't working in your favour across AI platforms.
AI Visibility Audit
Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.
/ Learn More
Understanding AI search visibility.
AI search experiences create answers by pulling information from many places online and summarizing it into a single response.


