Database security has followed the same playbook for years. Pick your ten or twenty most critical databases, deploy Imperva or Guardium on them, and take the eighteen-month, seven-figure hit. For the other several hundred databases, turn on native audit, ship the logs to your SIEM, and call it monitoring.
That playbook made sense when Database Activity Monitoring (DAM) was hard, when the only databases anyone bothered to protect were the ones facing regulatory scrutiny, and when the riskiest users hitting them were humans.
None of those assumptions hold anymore, and security professionals are exhausted by the burdens and costs of Guardium and Imperva deployments. The "ship it to Splunk" part of the playbook (the part covering most databases) was never database security. It was compliance theater with a receipt. And now it's not a handful of human users hitting those databases, it's hundreds or thousands of autonomous agents, and a pile of logs in your SIEM does not secure any of it.
Varonis Next-Gen DAM brings every database into our unified Data Security Platform through native audit collection. All you need to do is point the logs your databases generated to Varonis and you get real findings instead of raw events piling up in your SIEM.
What "ship it to SIEM" actually delivers
Talk to any team pushing native database logs into a SIEM today, and the picture is the same:
-
The bill is enormous: Raw audit volume is massive, and SIEM ingest is priced by the gigabyte. No matter which SIEM you use, this quietly becomes the most expensive piece of database monitoring infrastructure your organization owns, and none of this money is buying security.
-
The alerts mean nothing: The SIEM has no idea which tables contain regulated data or the difference between a Select and a Show in SQL. Every event looks the same. Writing rules to find the activities that matter requires deep database knowledge the SOC does not have. Most teams give up and don't write the rules at all.
-
The audit report is still a manual process: Quarterly, someone runs custom queries against the log store, hand-formats the output, and prays the auditor accepts it. It does nothing to reduce risk or secure data.
"We create and send our database logs to our SIEM to have an audit checkbox. Nothing is done with them other than proving they exist.”
CISO, Fortune 500 Financial Services Company
Meanwhile, the databases under an agent-based DAM tool are stuck in their own trap. Agent deployments take years, cover a fraction of the estate, and drown teams in undifferentiated alerts. The people who built that category will tell you so themselves.
Ron Bennatan, VP of Strategy at Varonis, explains: "We built agent-based DAM in an era with real hardware constraints and a real need for inline controls like blocking, dynamic masking, and connection throttling. The hardware constraints have been closed for years with cloud and modern storage, and inline controls are now primarily needed for AI agents. Databases now need high-fidelity detection and a way to make sure AI agents don't cause unintended consequences. The interesting problem now is how you turn millions of activity records into a small number of findings that actually mean something and how you understand agent intent."
Prior to joining Varonis, Ron spent 25 years building agent-based DAM as co-founder of Guardium (acquired by IBM) and jSonar (acquired by Imperva). Native audit overhead on modern databases is now measured well under five percent on par with agent-based collection.
The industry ended up with two failed modes running in parallel: (1) legacy DAM monitors a small subset of databases at enormous cost, and (2) SIEMs cover the rest, but don’t provide any security.
Why the combination of legacy DAM + SIEM stopped working
The legacy DAM-SIEM compromise assumed the databases not covered by DAM weren't worth the effort. That assumption dies the moment an AI agent starts querying them.
Consider a customer support agent built on an internal LLM:
-
A user asks it a question
-
The model decides it needs three rows from a customer database
-
The MCP server runs the query under a shared service account
-
The native log records: svc_ai_support read 3 rows from customers.payment_methods at 14:02
Multiply that by ten thousand queries a day across a dozen AI workflows, and you have a feed that is both massive and useless. The human who triggered the request is invisible. The service account is doing things it wouldn't have been doing six months ago.
The SIEM has no context into the sensitivity of the data being accessed. Without that context, the SIEM has no way to tell whether any of this activity is normal. Multiply that by 100 or 1,000 agents, each capable of taking autonomous actions, prone to unintended behavior, or even going full "rogue," and now every database is at risk and not just the ten earmarked for legacy DAM coverage.
Secure every database with Varonis Next-Gen DAM
For years, the reason security teams didn't monitor every database was because monitoring every database was hard and came with a lot of overhead. Varonis Next-Gen DAM changes the math with two collection methods that share one SaaS platform:
Native Audit Collection for the vast majority of your databases. All you need to do is point the built-in audit streams that ship with SQL Server, Oracle, PostgreSQL, MySQL, Snowflake, Databricks, Amazon RDS, and every other major engine at a Varonis collector. Nothing to install on the database host, no agents, inline devices, or DBA tickets.
The Varonis Gatekeeper for the smaller set of hypercritical databases where you need inline enforcement like blocking, dynamic masking, and legacy database version support. This is the workload that used to justify agents in the first place.
Both feed the same SaaS platform. Which means every database, the ten critical ones and the several hundred that used to live in Splunk purgatory, get the same security treatment.
What Varonis Next-Gen DAM delivers
A log entry becomes a finding when the platform processing it knows three things: whether the data being touched is sensitive, whether the user should have access to it, and whether the behavior is normal for them.
Take a 2 a.m. SELECT against a customer table. To a SIEM ingesting raw audit, it is one event out of millions. To Varonis, three things happen in parallel:
-
The classification engine already knows the destination table holds PII, down to the column.
-
The identity graph resolves the database account back to a real corporate identity through Active Directory or Entra.
-
Then, by leveraging User Entity Behavior Analytics (UEBA), Varonis shows that this user has never touched this table or column and rarely works after hours.
The result is a clear alert that something is wrong: this account just read regulated data it has never touched before, off-hours, from a new endpoint.
Apply the same three-way intersection to the AI agent example above. Classification knows customers.payment_methods is PCI scope. The identity layer traces svc_ai_support back to the originating workflow and, ultimately, the user prompt. Behavior modeling knows whether this agent has any business hitting this table at this volume. The log becomes a finding the same way it does for a human user.
That is the difference between shipping logs somewhere for a report and securing databases.
"You don't need more logs. You need to make sure that every alert you get actually means something."
Terry Ray, VP of Product Strategy at Varonis
Why DAM is easier than you think
Now, you can easily extend DAM to every database in your estate. The same database logs you've shipped to Splunk for years can now point at Varonis instead. Same stream, same effort, but now you get specific findings with complete data classification and identity resolution rather than a per-gigabyte bill for events that nobody reads.
Run a free Varonis Data Risk Assessment to get started. Bring in any combination of databases (SQL Server, Oracle, PostgreSQL, MySQL, RDS, Snowflake, Databricks, and more) alongside your unstructured data in OneDrive, SharePoint, Google Workspace, Box, Salesforce, NAS, and the rest. One classification model, one identity graph, one set of findings.
What you get:
-
A complete map of where sensitive data lives across every database and every file store, with exposure and access risk quantified
-
Identity mapping that resolves database accounts back to real corporate identities through Active Directory and Entra
-
Live activity alerts surfaced by Varonis UEBA, watched 24x7x365 by an MDDR analyst for the length of the assessment
-
An executive-ready report with a prioritized remediation path, yours to keep whether you become a customer or not
Setup takes less than an hour, with findings showing up within 24 hours.
Varonis Next-Gen DAM is built for the modern era
Gain complete visibility and control over your databases.
Schedule a personalized demo to see how Varonis Next-Gen DAM can help you secure both structured and unstructured data in one unified platform.