A SIEM is the system most companies use to collect security logs and raise alerts. SIEM stands for security information and event management. Firewalls, laptops, cloud accounts, and identity tools all produce records. The SIEM stores a copy and runs rules against that copy.
Storing the copy is how the vendor usually charges. High-volume sources, such as verbose cloud logs or every action an internal software agent takes, get expensive fast. Teams then leave those sources out. The hunt later cannot see them.
Object storage is the cheap file store the cloud already gives you, names like Amazon S3 or Azure Blob. The files are there. The SIEM never indexed them.
Vega announced Vega II on September 29, 2026. Shay Sandler and Eli Rozen founded the company in 2024. They raised about $185 million. The product sits on what Vega calls a Security Analytics Mesh. In plain terms, Vega sends the question to each store instead of assembling one giant new database first (Vega, 2026).
Vega says a search can cover a billion logs in under 60 seconds, that investigations finish about 90 percent faster, and that the bill can fall by as much as 82 percent versus a legacy SIEM. Those figures come from Vega.
The model, the memory, and the leftover sources
The defense model is a smaller model Vega trained for this job: read an alert, pull related records, and write up what happened. It runs beside general models such as those from OpenAI or Google. Vega’s claim is a faster first read and a notebook a person can replay.
Memory is the file of what the team already learned. A closed case often contains facts the next analyst needs: this server is supposed to talk to that partner, this alert is a known backup job. Without memory, each new alert starts from zero. With it, the next pass can start from the last approved answer. Ask who can see that file, change it, and erase it.
The gateway is the on-ramp for sources that never got a paid SIEM feed. Vega can take a stream such as OpenTelemetry, which is a common way applications emit traces and logs, or a simple webhook, and land it in object storage. From there the same search can reach it.
Vega does not ask you to switch off Splunk, Microsoft Sentinel, or IBM QRadar on day one. Those tools can stay for the logs you already pay to keep hot. Vega is aimed at the rest.
Time the hunt and read both invoices
Search that stays in object storage avoids a SIEM ingest fee. It still uses the cloud. Each read has a price. If the files sit in another region, moving the results out has a price too. Ask Vega to estimate those lines on your Amazon Web Services, Microsoft Azure, or Google Cloud invoice for the volume you actually have.
A hot SIEM index is built for quick answers. A cold bucket is built for cheap holding. During an incident you need to know how long a real hunt takes against last month’s files. Time it.
Logs from different products do not use the same field names. A detection that looks for “user” will miss a source that calls the same thing “account.” Ask what happens when a vendor changes a field, and who updates the map.
Detection Skills is Vega’s published format for writing down how your team works an alert. If your staff can export that write-up and use it elsewhere, the effort travels. If it only runs inside Vega, treat it as part of the product.
I have not sat with Vega on this release. The useful test is small. Name three sources you currently leave out. Ask Vega to run one hunt it says should complete. Read the SIEM invoice and the cloud invoice for that week side by side.
CrowdStrike is the other security operations story I wrote this month, on Falcon Guardian listing agents on laptops that already run the Falcon sensor (September 1). That product starts on the endpoint. Vega starts on the logs the SIEM never held.
Works cited
Vega. "Vega Arms Defenders with the First Purpose-Built Model Trained for Agentic Cyber Defense." 29 Sept. 2026, vega.io.
Vega. Product pages on the Security Analytics Mesh, Vega II, Vega Memory, and Vega Gateway. 2026, vega.io.
Globes. "9 Vega: SIEM-less cybersecurity." 17 June 2026, en.globes.co.il/en/article-9-vega-siem-less-cybersecurity-1001545891.
Novinson, Michael. "Vega Raises $120M Series B for AI-Native Security Operations." BankInfoSecurity, 11 Feb. 2026.
Bellamkonda, Shashi. "CrowdStrike Ships Falcon Guardian to Inventory and Block Agents on Laptops." shashi.co, 1 Sept. 2026, www.shashi.co/2026/09/crowdstrike-ships-falcon-guardian-to.html.
