Inside the reportWhat the full report contains
The opening pages of the PDF, reproduced here: study scale, abstract, table of contents and introduction. Download the full report for the results, discussion and appendices.
- 10,000 Buyer-intent queries
- 160,000 AI engine responses
- 4 AI engines
- 4 Markets
- 954,000 Cited sources
- 121 Distinct product entries
- Published
- October 2026
- Research period
- October 2026
- Category
- Enterprise security information and event management (SIEM) and security operations platforms
- Prepared by
- GrackerAI ยท AI Search Visibility Benchmark Series
Table 1. Study scale by AI engine
Responses recorded and sources cited, per engine.
| AI engine | Responses | Cited sources | Markets |
|---|
| ChatGPT | 40,000 | 216,000 | 4 |
|---|
| Gemini | 40,000 | 124,000 | 4 |
|---|
| Google AI Overview | 40,000 | 393,000 | 4 |
|---|
| Google AI Mode | 40,000 | 221,000 | 4 |
|---|
| Total | 160,000 | 954,000 | 4 |
|---|
Abstract
Enterprise security buyers increasingly meet their first vendor shortlist inside an AI-generated response, so the vendors an AI engine names now shape the consideration set before any vendor is contacted. This study measures how four commercial AI search engines answer buyer-intent questions about enterprise security information and event management (SIEM). A set of 10,000 buyer-intent queries, built from five core buyer questions and reworded variants of each, was issued to ChatGPT, Gemini, Google AI Overview and Google AI Mode in the United States, Canada, India and Germany during October 2026. The 160,000 AI engine responses carried 954,000 cited sources. For every response the study recorded length, citations, cited domains, source reachability, hedging, recency anchoring, truncation, and each brand and product mention with its ordinal position. Microsoft is the most-mentioned brand in every engine and every market, with 161,000 of 921,000 brand mentions, and Microsoft Sentinel is the most-mentioned product entry at 118,000 mentions. The engines agree far less on evidence than on vendors: no pair of engines shares more than 0.29 of its cited domains, measured by the Jaccard coefficient. Citation behaviour diverges sharply, from 0.6 citations per 100 words in Gemini to 4.6 in Google AI Overview, and from a 94.9% vendor-site share of ChatGPT citations to 30.5% for Google AI Overview. The results show a stable shortlist produced from largely separate evidence bases, which means a measurement taken on one engine does not describe the others.
Contents
- 1. Introduction
- 1.1 Background
- 1.2 Why this category
- 1.3 Contribution
- 2. Research Questions
- 3. Methodology
- 3.1 Study design
- 3.2 Engines under test
- 3.3 Markets
- 3.4 Query construction
- 3.5 Corpus and unit of analysis
- 3.6 Metric definitions
- 3.7 Data collection and processing
- 3.8 Scope exclusions
- 4. Results
- 4.1 Response characteristics by engine
- 4.2 Brand visibility and share of voice
- 4.3 Product-level results
- 4.4 Citation volume and source concentration
- 4.5 Source quality and link decay
- 4.6 Cross-engine source overlap
- 4.7 First-mention position
- 4.8 Geographic variance
- 4.9 Inter-engine disagreement
- 5. Discussion
- 6. Threats to Validity
- 7. Limitations
- 8. Practical Implications
- 9. Conclusion
- Disclosure
- 10. Reproducibility and Data Availability
- How to cite this report
- Appendix A. Brand visibility by AI engine
- Appendix B. Source mix and most-cited domains
- Appendix C. Product entries
- Appendix D. Query set and markets
- Appendix E. Metric computation
1. Introduction
1.1 Background
An AI search engine does not return a list of documents for the reader to rank. It returns a composed response that names a small number of vendors, places them in an order and attaches a reason to each. For a high-consideration enterprise security purchase, that single response performs work a buyer once spread across analyst notes, peer conversations and many search results. It sets the category boundary, states the evaluation criteria and nominates the candidates.
The consequence for a vendor is structural rather than competitive. A vendor absent from the returned shortlist is not losing on price, capability or references. It is simply not present when the consideration set forms. Conventional search metrics do not detect this condition: a vendor can rank well for its category terms and still be missing from the responses that increasingly come before a click.
1.2 Why this category
Security information and event management is a suitable instrument for four reasons. First, the vendor set is mature and heavily documented: the engines in this study named 100 distinct brand entries, and a group of 20 brands appears in all four engines. Second, the evaluation criteria are stable and publicly articulated. The engine responses recorded here repeatedly organise the category around the same capabilities: detection mapped to MITRE ATT&CK, user and entity behaviour analytics (UEBA), threat intelligence integration, built-in security orchestration, automation and response (SOAR), and the cost of log ingestion and retention. That shared vocabulary makes responses comparable across engines, markets and phrasings.
Third, the buying process is research-heavy: the core questions used here describe replacing a legacy SIEM, equipping a small security operations centre (SOC), and consolidating alerts from many tools. Fourth, a SIEM sits at the centre of security operations and is costly to replace, so omission from an early shortlist is hard to recover from later in the cycle.
1.3 Contribution
This study contributes a directly measured, cross-engine baseline for a single enterprise security category. It reports brand visibility and ordinal position separately rather than merging them into one share-of-voice figure. It quantifies how far the engines draw on shared or separate evidence, which determines whether a measurement on one engine generalises to another. It records length, citation density, source type and cited-source reachability as properties of the category's AI search layer. Finally, it tests whether the leading vendors hold their position when the buyer question changes.