Composable SIEM Manifesto | Abstract

Abstract Manifesto

SIEM IS A STATE OF MIND

The future of security operations is composable.

Where is Hotel California?

Some say it’s a boutique hotel in Todos Santos. Not according to Don Henley. Hotel California is a state of mind! An allegory. A metaphor.

When I say SIEM is a state of mind, I mean it is less about a single product or vendor and more about an organizational philosophy. This is the difference between SIEM and Security Operations. The word operations assumes processes, customization, people (training, specialization, tasks) and business support. A state of mind is a mindset: an orientation toward how you design, deploy, and evolve security data systems. Just like Hotel California never meant a physical hotel, SIEM in the modern era isn’t confined to one appliance or monolith. It is the shared approach that guides how data is collected, normalized, stored, and leveraged for detection and response. In this sense, describing SIEM as a state of mind implies that it is not a destination but a perspective, a way of thinking that emphasizes adaptability, modularity, and choice.

"SIEM IS DEAD"

For years now, I’ve heard the same tired drab: “SIEM is dead.” That track has been on repeat for over a decade. But SIEM is like Machiavelli: faking its own death. Reinventing itself, changing costumes, waiting for the next act. What is dead is the legacy approach that got us into the log lemming, data swamp, and vendor-locked state we are in. But oh yeah, no problem, let’s platformitize and get all of our security from a single vendor. Nothing can go wrong with this plan! I am having flashbacks to the days of McAfee and Symantec.

The current debate centers on federated/decoupled architectures vs. monolithic platforms vs AI-SOC. But if you step back, what SIEM has become is not a product, not even a platform in the old sense. SIEM is a state of mind. A metaphor for how organizations approach detection, response, and security data strategy. A system, yes, but a system of systems.

from monoliths to modular platforms

In the early days, SIEMs were monolithic systems. They tried to do everything in one tightly bound box: collect, store, correlate, detect, alert, respond. We used to love our appliances! Branded faceplates with blinking diodes, rack ’em and stack ’em. But no single system could evolve at the pace of security.

The future is modular and decoupled: a flexible, composable platform where each function can be swapped, scaled, or integrated. The value is not in the one-box solution, but in the architecture of choice. A system of systems.

Key layers of a modern SIEM architecture include

Data strategy and collection

Flexible ingestion from any source

Pipelines

Shaping, enriching, and routing data efficiently

Data lake

Affordable long-term storage that meets regulatory and retention requirements

AI Enabled Workbench

A unified workbench for case management, hunting, response, and investigations leveraging the power of AI

AI Enabled Triage

Blending automated scoring with human-in-the-loop workflows

Automated response

Closed-loop playbooks, orchestration, and workflow integration

AI-SOC Is a Capability

AI-SOC is not a new category. It is not a replacement for SIEM. And It is not a destination architecture. AI-enabled security operations, the natural evolution of how humans interact with detection, investigation, and response workflows.

AI-SOC will follow the same path.

Standalone AI-SOC vendors will feel pressure to build more and more SIEM-like functionality: data access, normalization, context, storage, correlation, and detection logic. At the same time, SIEM platforms will continue to embed AI deeper into investigations, triage, response, and analyst workflows. Over time, the distinction collapses not because of marketing, but because security operations demand it.

AI does not replace SIEM. It augments it.

Composable SIEM for the AI Generation AI-GEN

Deconstructing SIEM Into Its Fundamental Building Blocks

Collection: The Security Data Fabric

Collection is no longer just log ingestion. In a composable SIEM, it becomes a security data fabric, the control point where data is shaped before it becomes expensive, rigid, or locked into a single system.

This layer includes:

Detection Fabric: Signal at Speed

Detection is about immediacy, the ability to identify threats while they are still unfolding, when response still matters and context has not yet gone cold.

Detection needs data, and it needs reliable, consistent data, but it does not require that all data be centralized, indexed, or treated equally. Modern security operations rely on multiple detection models, each optimized for a different purpose and time horizon:

Retention: Context at Scale

Most organizations are paying a tremendous tariff on security data storage. The reality is that the majority of security data that gets collected is never used for detection, investigation, or response. Instead, it accumulates in what has effectively become a data swamp, expensive to maintain, difficult to manage, and rarely delivering proportional value.

This is not a tooling failure. It is a data strategy failure.

AI-Enabled Security Operations (AI-SecOps)

Security operations is where SIEM becomes real, and where AI must be deeply embedded, not bolted on. In a composable SIEM world, SOC workflows operate with AI as an enabler across the entire architecture, independent of where data lives or which engine produced the alert.

At its core, AI-SecOps is about enabling analysts, not replacing them.

THe Future of SIEM ARCHITECTURE

Composable does not mean fragmented. Composable does not mean complex.

Composable means intentional assembly.

What "composable" actually means

A composable SIEM is a security architecture where collection, detection, retention, and AI-enabled security operations are independent, interoperable building blocks that can be assembled, evolved, and scaled by design, not constrained by a single vendor platform.

When you deconstruct SIEM into its fundamental building blocks, something becomes clear: SIEM was never meant to be a single product. It was always a system of systems. Composable SIEM acknowledges that reality, but Abstract defined it.

Abstract is the first and only platform built from the ground up as a truly composable SIEM. Not a monolith broken apart after the fact. Not a legacy SIEM with modular language layered on top. A system intentionally designed so collection, detection, retention, and AI-enabled security operations can evolve independently and be assembled by choice.