Exabeam Integrated Generative AI Into Security Operations
New platform updates allow autonomous threat triage and local AI querying to accelerate security investigations.
Updated on Oct. 1, 2026 in Artificial Intelligence

Live Poll
Do you trust artificial intelligence agents to conduct secure investigations within your company's internal data?
Exabeam has released new capabilities for its security operations platform and LogRhythm SIEM, including autonomous AI tools and agentic plugins. These features allow security teams to automate threat investigations across both cloud and on-premises environments.
Why it matters
Security teams struggle to keep pace with manual investigation workflows, creating a need for automated triage tools that maintain data control. These updates aim to reconcile the speed of generative AI with the privacy requirements of sensitive on-premises data.
Nova AI reduces triage time to approximately 10 minutes, a 30-fold increase in efficiency compared to manual analyst workflows. The platform utilizes an MCP (Model Context Protocol) server to enable local generative AI models to query security data without off-premises transfer.
The players
Exabeam
A provider of security operations platforms and SIEM technology focused on log management and AI-assisted threat detection.
LogRhythm
An SIEM platform provider acquired by Exabeam that specializes in threat monitoring and data collection for enterprise environments.
The details
Nova AI operates by autonomously gathering context, executing secondary searches, and retrieving entity profiles across the security platform. The migration of the LogRhythm SIEM (Security Information and Event Management, a system for analyzing security logs) from Elasticsearch to OpenSearch enables new generative AI collectors for services like ChatGPT and Gemini. Additionally, the Agentic SOC Plugin allows analysts to use natural-language commands via OpenAI Codex and Anthropic Claude Code.
Timeline
October 1, 2026: Exabeam introduced its new Agentic SOC and LogRhythm capabilities.
The Tech Race
This release follows the trend of adopting open standards like the Model Context Protocol to bridge local generative AI models with proprietary security infrastructure. It marks a shift from cloud-only AI security tools toward local-first data processing.
Security analysts can now use natural-language prompts to execute complex queries and triage cases significantly faster. These tools are designed to function within existing on-premises data environments, allowing teams to leverage AI without moving sensitive logs to the cloud.
The takeaway
The industry is moving toward agentic workflows that allow autonomous AI to perform high-level security analysis. Watch for the forthcoming release of skills on the Exabeam Agent Skills Marketplace to see how these automated capabilities scale across different enterprise security stacks.
What happens next
Exabeam is expected to release a series of specific skills through the Exabeam Agent Skills Marketplace.
Further reading
For more on how organizations are integrating autonomous systems into their security posture, visit Artificial Intelligence.
Live Poll
Do you trust artificial intelligence agents to conduct secure investigations within your company's internal data?








