"Excellent Alert Context and Clear Development Pipeline"
Context for alerts, easy log source integration, and a clear development pipeline. Raw log view without a basic summary of each alert unless AI triage is run. The alert context is very useful for false positive detection, noise reduction, and rule tuning.
"Easy-to-Use SIEM with Strong Integrations"
I appreciate Panther for precisely meeting our needs and offering great value. Setting up Panther was smooth and easy, and the onboarding mentoring was super helpful. The Terraform interface is very nice for its supported features. Panther closed a critical gap by centralizing security event logs from various systems, simplifying incident investigation and correlation. PantherAI has been a significant help, taking the guesswork out of security incidents and enabling quicker issue identification. The UI is easy to use and navigate, and the alert investigation tools are intuitive. I would like to see greater Terraform support and the ability to manage rules as code outside of the Panther Analysis repository mechanism. Panther closes critical gaps by centralizing security logs from various systems, enabling easier incident investigation and correlation, and enhancing our ability to identify true positives.
"Panther AI Quickens Log Analysis and Dashboard Queries"
The most useful feature is Panther AI, which helps quickly skim through logs, create search queries, and also queries for building dashboards. At times, I encounter UI issues with Panther AI when fetching results, and I think that part of the experience could be improved. It provides visibility and monitoring across all possible areas in our organization.
"Purpose-Built SIEM for Scaling SecOps with Excellent Search and Top-Tier AI SOC"
Built for what matters in SecOps: detection and response at scale. Panther doesn't waste time on useless features; everything has purpose and meaning. The search function has 3 modes, with PantherFlow being much like KQL and a joy to use. The DAC concepts are top-notch, and their AI SOC functions actually work—Panther AI may be one of the best on the market right now. I'd prefer if it also supported self-hosting in Azure, in addition to AWS. That said, AWS works perfectly fine for me; it's really just a personal preference. Complex analysis of Cyber, Fraud, and Product Security events, with AI analysis and assistance to support investigations. Detections as code helps standardize and maintain detection logic in a clear, repeatable way.
"Great Detection as Code That Accelerates Investigations"
Detection as code is awesome. The MCP also lets me work through investigations super quickly. Not all services are supported, which is typical for a new product. It speeds up detection and response as a whole. And with AI getting smarter, DaaC makes a lot of sense.
S
Security Operations Manager
"Panther Excels with Detection as Code and AI Triage"
Detection as code is great for version control and managing an alert lifecycle (dev/staging/prod). Panther AI Triage is a game-changer! Add Panther MCP and GitHub Co-Pilot, and we're close to automating a large part of our work! The alert pipeline includes some unnecessary checks (via yaml and test cases) that feel perfunctory and don't really test the logic of the rule. It's more unit testing, which suits software development more than security. Panther solves the noisy alert and alert fatigue problem with Panther AI Triage. We use its insights to fine-tune our alerts and narrow down the behaviors we want to protect and alert on. Also, we can offload analysis for signals we trust are lower severity while keeping a human-in-the-loop for complex and higher severity alerts. This lets our team scale in ways we hadn't imagined (essentially doing more with fewer people).
"Dependable SIEM with Excellent Support and AI-Powered Efficiency"
The support team is responsive and gives detailed guidance whenever we need assistance.
The platform is simple to set up and run, even with a small team. Its intuitive interface and AI capabilities let a small security team operate like a much larger one.
Predictable costs are a major plus. Panther's pricing lets us forecast our security budget accurately, which is vital for planning.
The MCP integration allows us to create custom detection rules that merge Panther's data with our local data sources for tailored threat detection. MCP and PantherAI also help non-native English speakers grasp complex security concepts quickly, reducing language hurdles across our team. I have no significant concerns or areas where Panther needs improvement. As a small team implementing our first SIEM, we required a platform we could deploy and manage without heavy resources. During our POC, we compared Panther with two other solutions, and Panther proved the easiest to implement and operate, solving this challenge smoothly.
The predictable cost structure was also key to getting executive approval, making the approval process straightforward.
"Compact and Powerful SIEM with Rapidly Evolving AI Analytics"
Panther is a compact, powerful SIEM with AI Analytics that are improving every day. Each category is easy to navigate, there are many integrations you can request, the pricing is very competitive, and the custom rule builder is well thought out. The tool is still young, but as it matures and catches up with larger, more advanced SIEMs on features, it will be world-class. An AI-driven ruleset builder plus detection triage helper could really help small teams close the skills gap in a SOC. A well-designed AI assistant inside a SIEM like this, with added OSINT and context, could get an entire operation running in weeks without needing to hire more people.
"Panther Streamlines and Accelerates Security Operations"
What stands out most about Panther is how quickly we go from alert to action. It's powerful and highly automated, with native integrations that made rollout and adoption simple across teams. Features like enrichment and AI-assisted analysis make SOC investigations much faster and less complex, and the support team is always quick to respond. Right now, I have no major complaints. Our experience from onboarding through daily operations has been smooth. Panther tackles the biggest SIEM challenge: turning huge volumes of security data into fast, actionable investigation workflows. It brings together signals from multiple tools via native integrations, enriches alerts with context, and uses AI-assisted analysis to cut manual triage time.
The result is a faster, more efficient SOC. Our team responds more quickly, onboarding is easier, and we spend less time on repetitive analysis and more on reducing real risk.
"Panther Integrates SIEM with AI to Accelerate Triage and Hunting"
Panther's evolution into AI-powered security has transformed what our team can do. The AI Auto Triage speeds up our workflow, and the built-in AI integration lets us automate threat hunting automatically. Having threat intelligence fed into the MCPs is a big plus.
The pricing feels justified by what you get, and I haven't seen another SIEM that goes this deep with SIEM plus AI integration. The out-of-the-box integrations cover the usual security stack, but shipping logs to S3 and normalizing them in Panther is straightforward enough.
With Snowflake as the data lake, queries are efficient and it's one of the smoothest ways I've used to search through log sources at scale. We also have monthly sessions with Panther's team to keep our instances updated, learn about new features, and fine-tune the platform.
The UI/UX is clean and intuitive. Many SIEMs are clunky, with buttons scattered all over. Panther is a real SIEM: if you know what you're looking for or want to build a detection, it's easy because the backend is SQL and everything is detection as code. The biggest challenge is keeping your detections as code well-managed; it's easy for your setup to drift out of sync with the upstream repo. Before you start writing rules, think about potential upstream conflicts when you customize. If you plan your detection-as-code infrastructure with that in mind, you'll avoid major headaches. Panther is really pushing its AI features. The Auto Triage has cut down our alerts from hundreds to just the important ones. While other vendors bolt on AI triage, Panther has it natively, and it performs flawlessly.
They're also working on AI that can generate new detections inside the platform. It helps pinpoint areas with high false positives so we can minimize noise for our analysts, including suggesting adjustments to rules that reduce unnecessary alerts.