The planned flag on this category is fourteen months out of date, and the edition it missed shrank the field from fourteen vendors to ten. The Forrester Wave: Security Analytics Platforms, Q2 2025 published in June 2025. What is more interesting than the flag is who disappeared between editions. An entire cohort of 2022 Leaders no longer exists in this category, and one of them left through a sale, which almost never happens to a Leader.
The pasted name matches the published title exactly, so this article reads the June 2025 scorecard directly. The report's own subtitle names the market's fight: the SIEM versus XDR collision. Legacy security information and event management vendors locked in competition with surging extended detection and response providers. The scorecard is the record of the first round.
The scorecard the flag missed: The Forrester Wave: Security Analytics Platforms, Q2 2025
The newest edition evaluates ten vendors across thirty criteria, twenty four on current offering and six on strategy, and carries a definition worth quoting: platforms that "converge data from network, identity, endpoint, application, and other security-relevant sources to generate high-fidelity behavioral alerts and facilitate rapid incident analysis, investigation, and response."
The field: CrowdStrike, Elastic, Exabeam, Google, Microsoft, Palo Alto Networks, Rapid7, Securonix, Splunk, and Sumo Logic.
Three Leaders were named.
Elastic took the highest score in federated search and five-out-of-five marks across fourteen criteria, including artificial intelligence, analyst experience, investigation, and deployment options. Forrester calls Elastic "an engineering-driven company" whose AI innovation sits "at the forefront of the market," naming its Attack Discovery and retrieval-augmented generation capabilities.
Splunk took the top score in current offering with five-out-of-five marks across sixteen criteria: analytics, analyst experience, automation, case management, detection engineering, data pipeline, threat hunting, and more. Forrester's line is about the company's "strategic focus on data, accessing it, applying the right analytics, and accelerating actions across IT and security."
Microsoft was the sole cloud giant among the Leaders and led the strategy axis. Google landed in the Strong Performer band, and AWS was not in the field at all.
The 2022 Leaders who are gone
The Q4 2022 edition evaluated fourteen vendors across twenty eight criteria, and its Leader group included Splunk, Microsoft, IBM, Elastic, Securonix, Sumo Logic, and Exabeam.
Now run the 2025 field against that list. IBM is gone. A Leader exiting a category via asset sale is rarer than a vendor failing to make the field. It happened between these two editions: IBM sold its QRadar SaaS assets to Palo Alto Networks in 2024, and the SIEM portfolio it built for a decade became the entry ticket of an XDR vendor. LogRhythm, another 2022 name, merged into Exabeam in 2024. Micro Focus, a third, became OpenText and was dropped by Forrester for diminished client mindshare.
Forrester's exclusion list is the most honest page in the methodology. Devo and Gurucul were excluded for insufficient market share. Logpoint was excluded as primarily European. Trellix joined OpenText in the mindshare category. AWS built a security lake and was excluded because it is "not yet mature enough." A scorecard's exclusions always reveal more than its tiers. This one shows a category concentrating fast.
The SIEM versus XDR collision
The fight named in the report's subtitle shows up in the tier column itself.
CrowdStrike and Palo Alto Networks entered the field from the XDR side. Both finished below the top tier, with the strategy axis their weak flank. The mechanics are structural. Forrester's own framing: traditional SIEMs offer deep data flexibility but demand manual work, while XDR vendors lead on detection and response with guided workflows, but often lack data-ingest flexibility and compliance features. Flexibility is the SIEM's product. Guidance is the XDR's product. The 2025 edition scores them on one axis, and for now the flexibility camp holds the top.
The platformization trend complicates the fight. Some XDR vendors do not charge for ingesting their own EDR data, which turns the pricing model into a strategic weapon: the endpoint vendor buys its way into the analytics hub with free telemetry. A buyer who standardizes on that endpoint stack has already made half of the SIEM decision without opening a scorecard.
The AI criterion is the next war
Forrester's announcement contains the sentence that matters most: "AI will change the way security operations functions, and betting on the right horse now will enable your team to change with it."
The AI scores were starkly differentiated. The Leaders delivered AI agents, automated parsing, and advanced detection engineering. The rest offered incident summaries, chatbots, and query language translation, which Forrester now treats as table stakes. Elastic's RAG-powered attack discovery and Splunk's analytics depth sit on one side of the line. The gap between AI that writes summaries and AI that runs detections is the next war, and the Q2 2025 criteria drew the line where the market stood in June 2025.
That line will not hold. Security AI moves faster than the two-year cadence between Waves. The Q4 2022 edition could not have scored AI agents at all. The next edition will score what happened after this one, and the report itself says the bet matters now.
What a June 2025 scorecard cannot price
The honest limitation is the calendar plus the concentration.
The scorecard is fourteen months old in the fastest-moving corner of security. Agentic SOC assistants, autonomous detection pipelines, and the AI-vendor churn since June 2025 are not in these scores. Read the tiers as a record of the SIEM-versus-XDR first round, not as a prediction of the second.
The concentration itself is the second limitation. Fourteen names became ten, and the excluded seven, IBM, LogRhythm, Micro Focus, Devo, Gurucul, Logpoint, and Trellix, are no longer available to shortlist in this category at all, while AWS was turned away at the door for an immature security lake. A buyer whose incumbent is on that list is not reading a scorecard anymore. They are planning a migration the scorecard cannot price.
Third, the hyperscaler slot is volatile by definition. AWS was the hyperscaler presence in earlier cycles. In 2025 the slot belongs to Microsoft as the sole cloud giant Leader, with Google as Strong Performer and AWS absent. That slot will keep moving, because the hyperscalers treat this category as an attachment to their clouds rather than a product of its own.
Three questions for the shrinking field
One: are you buying a data platform or a detection workflow? If your team lives in flexible data, the SIEM camp fits. If your team wants guided detections out of the box, the XDR camp fits, at the price of ingest flexibility. The scorecard merges the two camps, your operating model does not.
Two: what is your incumbent's exit risk? A 2022 Leader left through an asset sale and two more disappeared through merger and mindshare loss. Ask every shortlisted vendor who owns them, whether this category is a strategic product or an attachment, and get the answer in writing. A tier today does not guarantee a seat in the next field.
Three: which AI horse are you betting on? Forrester's own line makes the AI bet the hiring decision: your team will change with whichever horse you pick. Demand production AI agents and automated detection engineering, not chatbot demos. The report has already priced the difference.
The detections this category produces still have to be triaged somewhere; see Unified Vulnerability Management Solutions, where the market's value has moved from finding vulnerabilities to fixing them.
Analyst Source
Forrester Research
This article is built on The Forrester Wave: Security Analytics Platforms, Q2 2025, published June 2025, evaluating ten vendors across thirty criteria (twenty four current offering, six strategy). Forrester defines security analytics platforms as platforms that converge data from network, identity, endpoint, application, and other security-relevant sources to generate high-fidelity behavioral alerts and facilitate rapid incident analysis, investigation, and response. Leaders: Elastic, Splunk, and Microsoft. The edition follows The Forrester Wave: Security Analytics Platforms, Q4 2022 (fourteen vendors, twenty eight criteria) and the Q4 2020 edition. Key market dynamics: the SIEM versus XDR collision, platformization with free EDR ingestion, and generative AI differentiation. Excluded from the 2025 field: AWS (Security Lake "not yet mature enough"), Devo and Gurucul (insufficient market share), Logpoint (primarily European), and OpenText (Micro Focus) and Trellix (diminished client mindshare).
Source research
- Announcing The Forrester Wave: Security Analytics Platforms, Q2 2025, The SIEM Vs. XDR Fight Intensifies (Forrester blog)
- The Forrester Wave: Security Analytics Platforms, Q2 2025
- Elastic: named a Leader in The Forrester Wave: Security Analytics Platforms, Q2 2025
- Splunk: named a Leader in The Forrester Wave: Security Analytics Platforms, Q2 2025
- Virtualization Review: Microsoft is sole cloud giant Leader in the Q2 2025 report
- Announcing The Forrester Wave: Security Analytics Platforms, Q4 2022 (Forrester blog)
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.