---
title: Panther Reviews
meta_title: 'Panther Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 49 reviews by the users' company size, role or industry to
  find out how Panther works for a business like yours.
aggregate_rating:
  rating_value: 4.7
  review_count: 49
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---


# Panther Reviews
**Vendor:** Panther Labs  
**Category:** [Security Information and Event Management (SIEM) Software](https://www.g2.com/categories/security-information-and-event-management-siem)  
**Average Rating:** 4.7/5.0  
**Total Reviews:** 49
## About Panther
Panther is the AI SOC Platform that scales security expertise by embedding AI agents across your security operations with native access to your data lake, detection logic, and organizational knowledge. Unlike bolt-on tools, Panther&#39;s closed-loop architecture turns every alert into compounding intelligence that makes the system smarter over time. Request a demo today at: https://panther.com/product/request-a-demo/



## Panther Pros & Cons
**What users like:**

- Users commend Panther&#39;s **outstanding customer support** , highlighting its responsiveness and commitment to resolving issues efficiently. (13 reviews)
- Users commend Panther for its **exceptional detection efficiency** , enabling effective and purposeful responses in security operations. (12 reviews)
- Users find Panther&#39;s **intuitive interface** and comprehensive documentation make it easy to navigate and use effectively. (12 reviews)
- Users praise the **easy integrations** with various log sources, simplifying security management and boosting team efficiency. (11 reviews)
- Users praise Panther for its **purposeful features and continuous improvements** , enhancing usability and aligning with market needs. (11 reviews)
- Integrations (10 reviews)
- Alerting System (9 reviews)
- Implementation Ease (9 reviews)
- Users value Panther&#39;s **seamless onboarding and robust detection capabilities** , showcasing its commitment to innovation and support. (9 reviews)
- Alerting (7 reviews)

**What users dislike:**

- Users find Panther has **missing features** like version control and underdeveloped response workflows, complicating overall use. (5 reviews)
- Users find Panther&#39;s **complexity challenging** , particularly for non-technical teams and in managing version controls. (4 reviews)
- Users find the **Alert Management limited** due to lack of customization and configuration challenges affecting efficiency. (3 reviews)
- Users find the **complex configuration** of Panther burdensome, complicating integration with deployment pipelines and automation systems. (3 reviews)
- Users find the **dashboard issues** in Panther limit comprehensive security leadership insights and advanced customization options. (3 reviews)
- Users find the **immaturity of the dashboard feature** limits their ability for complex analysis and charting. (3 reviews)
- Users find the **limited access** to external enrichment providers and UI customization frustrating and restrictive. (3 reviews)
- Users find the **limited visualization** capabilities of Panther&#39;s dashboard to be a significant drawback when performing complex analyses. (3 reviews)
- Users note a **difficult learning curve** for those unfamiliar with coding, affecting the initial user experience. (2 reviews)
- Inefficient Alert System (2 reviews)

## Panther Reviews
  ### 1. Detection as Code and AI Triage Make Panther a Standout

**Rating:** 4.0/5.0 stars

**Reviewed by:** Mark H. | Security Operations Manager, Enterprise (> 1000 emp.)

**Reviewed Date:** January 12, 2026

**What do you like best about Panther?**

Detection as code is handy for version control and creating an alert lifecycle (dev/staging/prod) Panther AI Triage is a game changer! Add in Panther MCP and GitHub Co-Pilot and we are on the cusp of fully automating a lot of our work!

**What do you dislike about Panther?**

Alert pipeline includes unnecessary checks (via yaml and the test cases) that are really perfunctory and don't actually test the logic of the rule in question. Also fits unit testing approach which aligns more with software development than security.

**What problems is Panther solving and how is that benefiting you?**

Panther is solving the noisy alert/alert fatigue challenge via Panther AI Triage. We can leverage it's insights to then tune our alerts better and narrow down the behaviors we want to protect and alert against. Not to mention we can off load analysis for signals we trust are lower in severity while still allowing a human-in-the-loop to review complex and higher severity alerts. This in turn is allowing our team to scale in ways not previously imagined (essentially being able to do more with less headcount).

  ### 2. Purpose-Built SIEM for SecOps at Scale with a Delightful Search and Top-Tier AI SOC

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Health, Wellness and Fitness | Enterprise (> 1000 emp.)

**Reviewed Date:** January 27, 2026

**What do you like best about Panther?**

Built for what matters in SecOps, detection and response at scale. Panther does not waste time on useless features as everything has purpose and meaning. Their search function has 3 modes, with PantherFlow being very much like KQL and a delight to use. The DAC concepts are top notch and .. their AI SOC functions actually work, Panther AI may be one of the best on the market right now.

**What do you dislike about Panther?**

I’d prefer if it also supported self-hosting in Azure, in addition to AWS. That said, AWS works perfectly fine for me—it’s really just a matter of personal preference.

**What problems is Panther solving and how is that benefiting you?**

Complex analysis of Cyber, Fraud, and Product Security events, with AI analysis and assistance to support investigations. Detections as code helps standardize and maintain detection logic in a clear, repeatable way.

  ### 3. A giant in the SIEM space

**Rating:** 5.0/5.0 stars

**Reviewed by:** Zhel P. | Sr. Detection &amp; Response Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 29, 2025

**What do you like best about Panther?**

I have been utilizing Panther extensively over the past 18 months, and it has consistently proven to be an exceptionally reliable and robust solution. Its flexibility allows users to seamlessly operate via the console or integrate directly with existing CI/CD pipelines. The user interface is notably intuitive and offers multiple sophisticated options for querying data, complemented by customizable dashboards that significantly enhance analytical capabilities.

Panther includes numerous pre-built detections that are effortlessly adaptable, making it straightforward to align them with specific environmental requirements. Additionally, authoring detections as code in Python is streamlined and efficient. The platform stands out with valuable features such as comprehensive metadata fields including MITRE ATT&CK mapping, summaries, runbooks, and tagging capabilities.

Equally impressive is Panther's outstanding customer support team, whose responsiveness and expertise ensure issues are typically resolved within just a few hours. Their proactive engagement and consistent receptiveness to feedback, reflected clearly in periodic review meetings, continually demonstrate their commitment to customer success.

Overall, my experience with Panther has been exceptional, and I strongly recommend it to organizations seeking a versatile, powerful, and user-friendly security solution.

**What do you dislike about Panther?**

There is nothing that i dislike about the product.

**What problems is Panther solving and how is that benefiting you?**

We are currently ingesting logs from all corporate and cloud infrastructure into this solution, enabling comprehensive visibility and centralized management of our log data. The implementation process is straightforward and intuitive, requiring minimal effort, and the ongoing management of the platform has proven to be exceptionally simple and efficient.

This solution has become our primary tool for detection engineering and forensic log analysis, thanks to its powerful querying capabilities, versatile functionality, and reliability. It seamlessly supports our operational workflows and significantly enhances our capability to quickly detect and respond to security incidents, ultimately strengthening our organization's overall security posture.

  ### 4. Amazing SIEM for this AND the next generation of defenders!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Aaron T. | Senior Security Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 28, 2025

**What do you like best about Panther?**

Detection-as-code is the next frontier! This platform gives you everything you could want from your old SIEM platform and amplifies it to 11! The support behind the product is as amazing as the product itself, which is a rare trait these days.

**What do you dislike about Panther?**

Not really a downside but more of a fyi: To make the most of the platform, you want to understand and manage it via CI/CD practices and tooling. Pretty much everything can be done through the UI, but if you really want to get into the weeds and maintain a tight control over detections and alerting, you'll want to have some familiarity with proper CI/CD practices.

**What problems is Panther solving and how is that benefiting you?**

From having built in packs and schemas for all of our current use cases to supporting our most needed alerting destinations, Panther covers pretty much all of our current needs. The unified search and simple query language for more advanced searches should satisfy all analyst, young to old, green to experienced!
Detection-as-code provides us with a huge amount of flexibility for how we would like to create, manage, and deprecate our detection mechanisms.

  ### 5. Panther AI + Python = Next-Level Detection Engineering

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brooks B. | Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 30, 2025

**What do you like best about Panther?**

Panther's new AI is a massive time-saver, it instantly pulls the right fields from complex JSON logs. The AI saves me time parsing JSON and more time for responding. The Python-based alerting is a major win too. Writing detection logic feels like proper software development: it's clean, flexible, and testable. The alert testing feature is especially powerful. No more guessing if your logic will work in production. Custom lookup tables to map things like GitHub usernames to employees, or AWS accounts to Terraform workspace, which adds powerful context to our alerts.  Implementation and integration was fast and straightforward, easy to add custom features. Their customer support is exceptional — they added a feature the very next day after our request. We use Panther every single day across the team to save hours vs. our old SIEM.

**What do you dislike about Panther?**

The core platform is strong, but a few things could be smoother. Some UI elements still feel a bit early-stage./ More out-of-the-box templates or integration options would really level up the experience.

**What problems is Panther solving and how is that benefiting you?**

Panther helps us move fast without breaking things. We’re reducing false positives, accelerating investigations, and building high-quality detections with real engineering discipline. It’s replaced our legacy SIEM with something that feels purpose-built for modern cloud security teams.

  ### 6. SIEM with best architecture

**Rating:** 4.0/5.0 stars

**Reviewed by:** Finn (Seonghwan) C. | Senior Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** April 29, 2025

**What do you like best about Panther?**

I personally think panther is well architectured SIEM that has a enormous potential to growth in various aspect such as volume increases and very flexible architecture for writing detecting rules, especially geared us many tools to help e do detection engieering

**What do you dislike about Panther?**

Panther also has some latencies, each often ignored in other SIEM solutions.
I personally love how panther shows their latencies in plain sight, and make us understand whats happening under detections. I did managed other SIEMs, but these are the first one that has tranaparencies in detection processes.

**What problems is Panther solving and how is that benefiting you?**

The ease of Integrations and their architecture to ingest more logs with less costs.

  ### 7. Great SIEM Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 29, 2025

**What do you like best about Panther?**

Panther's user interface is very intuitive, making navigation effortless even for new users. The documentation is both comprehensive and well-written, providing clear guidance throughout. Writing detecting rules in Panther is easy, and Panther provides a robust environment to test the rules.

**What do you dislike about Panther?**

It's a little tricky to manage the version of the detection rules. The "packs" and "helpers" lack individual version control. This can be workaround by using the CI/CD workflow, but on Panther UI it's not straightforward.

**What problems is Panther solving and how is that benefiting you?**

Panther is a centralized SIEM solution that provides a great platform for us to manage logs and find issues.

  ### 8. Great for Writing Detections

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Marketing and Advertising | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 08, 2025

**What do you like best about Panther?**

Writing detections in Python is super nice.
Being able to throw an indicator such as an IP address or username into Panther and having it search everywhere is convenient.

**What do you dislike about Panther?**

When we make customizations to detection rules, it often causes merge conflicts when syncing from the upstream panther-analysis repo.
Custom SQL queries are often slow (on the order of 10 minutes).

**What problems is Panther solving and how is that benefiting you?**

Having our security relevant logs in one place where we can customize alerting and easily search during manual investigations.

  ### 9. Great SIEM With Lots of Out of the Box Detections

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 15, 2025

**What do you like best about Panther?**

One of the things I like most about Panther is it's Python based detection rules. It easy to start with simple rule writing, but moving to writing more complex rules using Python is a breeze.

**What do you dislike about Panther?**

As someone responsible for triaging alerts, I’ve found the UI a bit cumbersome—it’s missing some key quality-of-life features that would streamline triaging alerts. Integrating it with automation systems could unlock a lot of value to ease some of this.

**What problems is Panther solving and how is that benefiting you?**

Panther handles log ingestion and normalization across cloud infrastructure without needing a heavy ELK stack or complex data plumbing. Panther makes it easier to focus on writing detections rather than operating a log ingestion infrastructure.

  ### 10. Excellent tool for teams using detection as code

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 13, 2023

**What do you like best about Panther?**

Panther is incredibly responsive - it's a definite partnership. The team continues to develop features with input from customers about what is most needed. The ability to write detections in Python is very helpful. New feature rollouts  make creating detections and doing searches more accessible to less technical employees. The ability to truly implement detection as code is really cool, but it's not a must to implement Panther. The flexibility of ingesting anything you can get to S3 introduces some up front work, but once a process is established, custom ingestions can be done quickly.

**What do you dislike about Panther?**

Panther lacks some functionality you expect from the typical SIEM - visualizations specifically lag, but this can be addressed with other tools. There is a fairly steep learning curve if you are not experienced with Python, SQL, and YAML. However, all SIEMs have a fairly steep learning curve. If your team has some experience with development, the languages should be familiar and easy to get the hang of how Panther uses them.

**What problems is Panther solving and how is that benefiting you?**

Centralized monitoring, detection, and response. Ingesting data via API is straight forward and can be largely templatized for efficiency. Recent additions to ingestion options (like webhooks) will continue to make ingestions more efficient. The ability to work in code is a major benefit for teams committed to a CI/CD environment.

  ### 11. Flexible and Robust - a Modern SIEM

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 11, 2023

**What do you like best about Panther?**

The ability for our detections to be as simple or complex as Python allows is the most significant benefit to Panther as a SIEM. While specific log sources don't necessarily need this, custom log sources (such as an organization's app logs) benefit tremendously from this added flexibility. Panther helps foster collaboration in our environment and provides a tool to which all of Engineering can contribute. The ability to embed our alert building into our existing SDLC to ensure proper custody and approvals before going into production is tremendous. As a partner, Panther is transparent and always provides constant opportunities for feedback and service improvement. The community is growing faster everyday and there are always new alerts being offered for adoption by all of the community.

**What do you dislike about Panther?**

While it doesn't impact our team, a non-technical Security team could struggle to realize all of the benefits of a SIEM like Panther vs some of the drag-and-drop competitors.

**What problems is Panther solving and how is that benefiting you?**

Panther helps us solve our problem of centralized visibility and monitoring of our many (often custom) log sources. As a SIEM Panther excels at providing robust and custom alerting mechanisms so we can build out world-class detection and response capabilities.

  ### 12. Panther.io -- Modern Security Analytics, Detection & Response

**Rating:** 5.0/5.0 stars

**Reviewed by:** Timothy K. | Director, Software Engineering & DevSecOps, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 17, 2023

**What do you like best about Panther?**

Modern, cloud-based architecture. Bring your own Snowflake. Detection as Code (Python & SQL).

**What do you dislike about Panther?**

Response workflow creation (what to do with a detection) is lackluster and underdeveloped.

**What problems is Panther solving and how is that benefiting you?**

Log source integration into Snowflake. Detection as code, many good detections out of the box. Security Analytics is super simple, I don't have to worry about any details on the ingest or warehouse. Snowflake storage is super cheap. Amazing post-sales and support team.


## Panther Discussions
  - [What is Panther used for?](https://www.g2.com/discussions/what-is-panther-used-for) - 1 comment

- [View Panther pricing details and edition comparison](https://www.g2.com/products/panther/reviews?filters%5Bsentiment_snippet%5D=2058542&qs=pros-and-cons&section=pricing&secure%5Bexpires_at%5D=2026-08-14+19%3A17%3A54+-0500&secure%5Bsession_id%5D=f3b5aab1-67ed-4a32-964b-9a58390faaeb&secure%5Btoken%5D=8953a76055c9912b0365edaa94df0f002130d4be1eb5b27d4675956a1ba80e81&format=llm_user)
## Panther Integrations
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)
  - [Google Workspace](https://www.g2.com/products/google-workspace/reviews)
  - [Jira](https://www.g2.com/products/jira/reviews)
  - [Okta](https://www.g2.com/products/okta/reviews)
  - [Recorded Future](https://www.g2.com/products/recorded-future/reviews)
  - [ServiceNow IT Service Management](https://www.g2.com/products/servicenow-it-service-management/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Tines](https://www.g2.com/products/tines/reviews)
  - [Torq AI SOC Platform](https://www.g2.com/products/torq-ai-soc-platform/reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews)

## Panther Features
**AI/Machine Learning**
- AI/Machine Learning

**Reporting/Analytics**
- Reporting/Analytics

**Endpoint Protection**
- Endpoint Protection

**Threat Propagation Visualization**
- Threat Propagation Visualization

**Performance Metrics**
- Performance Metrics

**Natural Language Security Querying**
- Natural Language Security Querying

**Threat Response**
- Threat Response

**Activity Monitoring**
- Activity Monitoring

**Network Security**
- Network Security

**Automated Threat Containment**
- Automated Threat Containment

**Intelligent Alert Noise Reduction**
- Intelligent Alert Noise Reduction

**Explainable AI (XAI) Audit Trail**
- Explainable AI (XAI) Audit Trail

**Predefined Protocols**
- Predefined Protocols

**Activity Monitoring**
- Usage Monitoring
- Database Monitoring
- API Monitoring
- Activity Monitoring

**Data Preparation**
- Data Sources
- Indexing
- Automated Tagging
- Data Blending

**Threat Detection & Triage - AI SOC Agents**
- Anomaly Detection & Correlation
- False‑Positive Suppression
- AI‑Driven Alert Triage

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**Network Management**
- Activity Monitoring
- Asset Management
- Log Management
- Network Monitoring
- Server Monitoring
- File Integrity Monitoring
- Real-Time Monitoring
- User Management
- Endpoint Management
- Compliance Management
- Incident Management
- Vulnerability Management
- Policy Management
- Event Logs

**Security**
- Compliance Monitoring
- Risk Analysis
- Reporting

**Analysis**
- Track Trends
- Detect Anomalies
- Metric and Event Data
- Search
- Alerts
- Live Tail
- Real-Time Data

**Investigation & Enrichment - AI SOC Agents**
- Autonomous Case Investigation
- Contextual Enrichment from Multiple Sources
- Attack Path Mapping

**Security**
- Data Security
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Incident Management**
- Event Management
- Automated Response
- Incident Reporting
- Real-Time Reporting

**Administration**
- Security Automation
- Security Integration
- Multicloud Visibility

**Visualization**
- Dashboards
- Data Discovery
- Activity Dashboard
- Activity Dashboard
- Customizable Dashboard

**Response & Remediation - AI SOC Agents**
- Mean Time Reduction Metrics
- Playbook‑Free Dynamic Workflows
- Automated Response Execution

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Security Intelligence**
- Threat Intelligence
- Vulnerability Assessment
- Behavioral Analytics
- Data Examination
- Real-Time Data

**Agentic AI - Security Information and Event Management (SIEM)**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Agentic AI - Cloud Security Monitoring and Analytics**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Agentic AI - Log Analysis**
- Autonomous Task Execution
- Multi-step Planning
- Cross-system Integration
- Adaptive Learning
- Natural Language Interaction
- Proactive Assistance
- Decision Making
- Third-Party Integrations

**InfoSec Experience & Governance - AI SOC Agents**
- Conversational Analyst Interface
- Manual Feedback Learning Loop
- Explainability & Audit Trail

**Additional Functionality**
- Continuous Monitoring
- Reporting/Analytics
- Real-Time Analytics
- Issue Tracking
- Anomaly Detection
- Visual Analytics
- Data Visualization
- Monitoring
- AI Copilot
- Audit Management
- Correlation Analysis
- Generative AI
- Reporting & Statistics
- Search/Filter
- Data Import/Export
- Data Classification
- Audit Trail
- Pattern Detection and Recognition
- Analytics
- Activity Tracking
- Event Tracking
- Log Collection
- Alerts/Notifications
- Log Analysis
- Event Logs
- Data Analysis Tools
- HIPAA Compliant
- Predictive Analytics
- Performance Metrics
- Secure Data Storage
- Dashboard Creation
- Real-Time Monitoring
- Alerts/Escalation
- Remediation Management
- Compliance Tracking
- Single Sign On
- Prioritization
- Uptime Reporting
- Log Rotation
- Real-Time Notifications
- Compliance Management
- Server Logs
- Incident Management
- Role-Based Permissions
- PCI Compliance
- Charting
- Log Parsing
- Archiving & Retention
- Server Monitoring
- API
- Diagnostic Tools
- Customizable Reports
- Real-Time Reporting
- Policy Management
- Issue Management
- Vulnerability Scanning

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Additional Functionality**
- Real-Time Notifications
- Audit Trail
- Application Security
- Risk Analysis
- AI Copilot
- Data Import/Export
- Alerts/Notifications
- Prioritization
- Security Auditing
- Search/Filter
- Compliance Tracking
- Generative AI
- API
- Third-Party Integrations
- Activity Dashboard
- Data Visualization

## Top Panther Alternatives
  - [Datadog](https://www.g2.com/products/datadog/reviews) - 4.4/5.0 (715 reviews)
  - [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews) - 4.3/5.0 (392 reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews) - 4.3/5.0 (415 reviews)

