
CrowdStrike announced its intent to acquire Onum, a leader in real-time telemetry pipeline management, on August 27, 2025. This acquisition aims to supercharge the Falcon Next-Gen Security Information and Event Management (SIEM) platform by integrating Onum’s advanced data pipeline capabilities, enabling faster, cost-effective, and autonomous cybersecurity solutions.
The acquisition integrates Onum’s stateless, in-memory architecture into the Falcon platform, enhancing its role as the “operating system of cybersecurity.” Onum’s technology processes security and observability data in real-time, delivering up to five times more events per second than competitors and reducing storage costs by up to 50% through smart filtering. This enables faster onboarding and in-pipeline threat detection, starting before data enters the Falcon platform.
Onum’s integration offers:
“Onum was founded on the belief that pipelines should do more than transport data, they should transform data into real-time intelligence,” said Pedro Castillo, founder and CEO of Onum. “By joining CrowdStrike, we can deliver this vision at unprecedented scale.”
Previously, migrating data to Next-Gen SIEM required third-party tools, creating friction and costs. Onum’s technology eliminates these bottlenecks, enabling native data streaming and autonomous detection within the Falcon platform, streamlining SOC transformation.
The acquisition aligns with CrowdStrike’s focus on AI-driven SOC transformation, positioning Falcon Next-Gen SIEM as a leader in cybersecurity. With 95% growth in annual recurring revenue (ARR) for the platform, reaching $430 million in Q2 FY2026, CrowdStrike is disrupting legacy SIEM vendors like Splunk by offering a cloud-native, AI-powered solution.
CrowdStrike’s acquisition of Onum enhances its Falcon Next-Gen SIEM, delivering unmatched speed, cost efficiency, and autonomous threat detection. This move solidifies CrowdStrike’s leadership in modernizing SOCs and addressing complex security challenges globally.
CrowdStrike (NASDAQ: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data.
Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.