All articles

Blog #12 Agentic SIEM

The Query Multiplier Crisis

On this page

AI gives defenders a way to keep up with attackers. Its success creates a new infrastructure challenge: supplying the evidence for every investigation.

AI is giving attackers the ability to do more, faster. A major cybersecurity provider’s 2026 threat report recorded an 89% increase in attacks by AI-enabled adversaries in 2025 compared with 2024. That measures activity observed by one provider—not an 89% increase in all cyberattacks or SOC alerts—but it signals the pressure facing defenders.

Reported attacks by AI-enabled adversaries, indexed to 2024 = 100: 100 in 2024 and 189 in 2025.
Reported growth, indexed to 2024 = 100. These are not absolute attack counts or a causal estimate of AI’s effect on all cyberattacks.View full-size chart ↗

An overloaded security operations center cannot close the gap simply by asking analysts to work harder. Every investigation still needs context. While the team works through one set of questions, new alerts keep arriving.

Defenders need to investigate more activity without increasing manual effort at the same rate. AI offers a way to do that. But reducing the work required from an analyst does not necessarily reduce the work required from the data infrastructure.

The investigation still needs its evidence.

AI gives the SOC a way to catch up

In one published production deployment, a 30-minute manual investigation became an automated workflow completed in under three minutes. The pipeline combined deterministic checks, specialized AI agents, and a final review agent.

One reported production deployment reduced investigation time from 30 minutes manually to under three minutes with an agentic workflow.
A self-reported production result, not an industry-wide benchmark. The AI bar ends at the three-minute mark; the reported result was under three minutes.View full-size chart ↗

Consider a suspicious login. An agent can check the identity’s recent activity, look for endpoint evidence, examine related network events, and assemble the findings. Instead of starting with a blank investigation, the analyst starts with context.

The promise is not simply speed. It is the ability to investigate more alerts, pursue relevant leads, and reserve human attention for decisions that require judgment.

For a team struggling to keep pace, this looks like the breakthrough it needs. But the analysts are not the only ones who have to keep up.

Why now: agents are adding demand on both sides of the data layer

AI agents are not just investigators. They are also part of the environment being investigated.

In a major log-management provider’s 2026 survey of 450 senior enterprise leaders, respondents attributed an average 93% increase in logs and telemetry over the preceding year to AI. In the same survey, 85% reported difficulty ingesting logs at the scale driven by AI workloads.

These findings cover AI workloads broadly, not agents alone. But they expose the first source of pressure: more evidence to collect, retain, and make usable.

Agents add another dimension. They can both generate telemetry and consume it—retrieving information, evaluating results, taking actions, and inspecting what happened next.

That makes the agent a new kind of data user in an operational sense, not a separate population outside machine identities.

The infrastructure must support both sides: more data produced by AI workloads and more data access required by automated investigations.

That is why this matters now. The SOC can become more capable at the same time that supplying its evidence becomes harder.

The agent does not just ask the same questions faster

It can pursue more of them.

  • What else did this identity access?
  • Which endpoint was involved?
  • Has the same pattern appeared elsewhere?
  • How far back does it go?

Each answer can lead to another query.

Even the initial deterministic IP-based triage in the published production workflow can execute up to 16 queries before later investigation stages. That is not a human-versus-AI benchmark. It illustrates how much data access can sit behind a single alert.

A simple model makes the potential multiplier visible:

Daily query demand = alerts investigated per day × average queries per alert

Assume 1,000 investigated alerts per day. At four queries per alert, the backend serves 4,000 queries per day. At 40 queries per alert, it serves 40,000.

The same alert volume produces 10 times the queries under those assumptions.

Illustrative query model: 1,000 investigated alerts per day produce 4,000 daily queries at four queries per alert, or 40,000 daily queries at 40 queries per alert.
Illustrative model, not measured deployment data. The four-query and forty-query inputs are assumptions, not industry averages or a measured AI-versus-human multiplier.View full-size chart ↗

Actual demand depends on investigation depth, context reuse, query consolidation, and query budgets. More queries are not automatically better investigations.

But expanding coverage and pursuing more relevant leads can increase backend work even as manual effort falls. Running those investigations in parallel can also concentrate demand into shorter periods.

AI can relieve the analyst bottleneck while exposing the infrastructure bottleneck.

The query multiplier can hit two different walls

The Query Multiplier Crisis is the risk that successful automation outgrows either the capacity or the economics of the systems supplying its evidence.

Those are different problems.

A concurrency wall

Published documentation for an enterprise search platform describes finite concurrent-search slots. When those slots are occupied, additional searches can be queued or rejected, depending on configuration.

An agent may know exactly which question to ask next and still have to wait for the backend to accept it.

Adding more automated investigators does not solve that constraint. Faster reasoning cannot compensate for unavailable search capacity.

A billing wall

In scan-priced systems, the cost depends on how much data each query processes. One published cloud-query pricing example uses $5 per terabyte scanned.

Apply that rate to the earlier workload model, assuming 0.01 TB scanned per query and a 30-day month.

At 4,000 daily queries, the modeled monthly scan charge is $6,000. At 40,000 daily queries, it is $60,000.

Illustrative scan-cost model: 4,000 daily queries cost $6,000 per 30 days, while 40,000 daily queries cost $60,000, assuming 0.01 TB scanned per query and $5 per TB.
Modeled scan charge = queries per day × 0.01 TB per query × $5 per TB × 30 days. Scan volume is assumed. This is not a customer bill or a Rover price comparison, and it excludes storage, requests, and AI charges.View full-size chart ↗

The outcome is not inevitable. Compression, columnar formats, and selective queries can reduce the bytes scanned. Not every data platform uses scan-based pricing.

But where that pricing applies, repeated evidence retrieval becomes an operating-cost variable that the automation plan must account for.

Keeping data affordably and investigating it affordably are not the same problem.

Enterprises are already rationing access to evidence

This is not only a hypothetical capacity-planning exercise.

In the same 2026 enterprise survey, respondents estimated average annual spending of $2.47 million on logging solutions, including ingestion, management, storage, indexing, rehydration, and querying. 75% reported higher log-management costs over the preceding year.

The more important finding is how organizations respond.

38% limit the number of queries and/or the amount of data queried. Another reported measure, used by 34%, is limiting investigations to avoid the cost of restoring logs from cold storage.

These measures can overlap, and they cover enterprise log management—not exclusively security operations. But their implication for an AI SOC is clear: a more capable investigator delivers less value when it cannot access the evidence it needs.

The friction also reaches AI deployment. 80% said the effort required to turn telemetry into actionable insights was hurting customer experience and delaying the transition of AI projects from pilot to production.

That does not establish that AI has overwhelmed every data platform. It establishes that data cost and usability are already constraining what some enterprises investigate and deploy.

The tempting response is to make the agent ask fewer questions. Sometimes tighter query discipline is appropriate. But restricting useful investigation merely to fit the infrastructure can sacrifice the depth that made automation attractive.

The answer should not be to make a better investigator stop following relevant evidence.

Rover is built for the questions an AI SOC asks

Rover approaches the problem through how evidence is indexed and how query compute is provisioned.

Indexed search in your own object storage

Rover stores inverted indexes alongside security records in customer-owned object storage. The query engine can use those indexes to locate relevant evidence rather than depend on repeated broad scans.

Compute allocated per query

Rover’s serverless query engine uses ephemeral, per-query compute. Query execution is separated from a permanently provisioned search cluster, so storage growth and investigative demand do not have to drive the same infrastructure decisions.

History without a restore step

Retained security history remains searchable without first rehydrating it from a cold archive. An investigation can follow a lead into older evidence rather than treating the recent hot tier as its boundary.

These are architectural design choices, not a claim of unlimited capacity or zero query cost. They address the two questions at the center of the problem: how evidence is found, and how the work of retrieving it is provisioned.

Let the SOC keep the advantage

The purpose of an AI SOC is not to generate more queries. It is to reach better-supported conclusions across more of the activity that deserves investigation.

That requires a data-infrastructure plan alongside the automation plan. The question is no longer only, “How much investigative work can we automate?” It is also, “Can we supply the evidence that work requires, at a sustainable cost and acceptable latency?”

AI gives the SOC the ability to ask more questions. The data infrastructure should help it get answers—not force it to stop asking.