Services
Security observability
Collecting security telemetry from every cluster and account, and storing it somewhere cheap to keep and fast to search.
Retention should not be a pricing decision.
Security observability has to be cheap at scale, so you keep the data an investigation needs instead of the data you can afford. We design collection, filtering and storage so the telemetry you actually investigate with stays inexpensive, and only what needs an alert reaches your SIEM.
Collect
Runtime event pipelines
Export, filter, enrich and route process, file and network events from the runtime sensors we deploy, with cluster and account identity attached.
Network flow pipelines
Flow export with field masking and filtering, landed in storage sized for the volume flows produce.
Carries data fromCilium and Hubble
Cloud audit pipelines
Organization-wide audit and finding streams ingested from S3 or EventBridge into one queryable store.
Carries data fromCloudTrailGuardDutySecurity Hub
Vector and Fluent Bit
Collection, transformation and routing, with disk buffering that survives an outage.
OpenTelemetry
Collector pipelines for logs, metrics and traces, including security signals.
Store and search
ClickHouse
High-volume security logs on low-cost storage: ingestion from S3, schemas, retention tiers and investigation queries.
Read the full service page →Elasticsearch
Index design, ILM, ingest pipelines and cost control for security workloads.
OpenSearch
Self-managed or AWS-managed clusters sized and tuned for log retention and search.
OpenObserve
Logs, metrics and traces in one self-hosted store backed by S3, with dashboards and alerting set up for security use.
Keep it healthy
Prometheus and Grafana
Monitoring for the pipeline and sensors themselves, so a silent source does not go unnoticed.