Documentation / Modules
Security operations
Log ingestion, detections, correlation and forensics — with retention policy, compliance holds, and an ingestion stop you cannot miss.
Ingestion
Syslog, Windows Event Log, cloud audit logs, firewall and endpoint telemetry. Parsers cover the common sources; unparsed events are retained as residue rather than discarded.
An event that could not be parsed is kept and counted. A pipeline that quietly drops what it does not understand is a pipeline that will drop the one event that mattered.
Detections
Rule-based detections with correlation across sources. Every detection cites the events that fired it, and a proposed rule is never enabled by itself.
Log forensics
Drop a log file and get ranked candidates, each citing the lines it read. Novel formats are handled structurally rather than by needing a parser first.
Silence is a finding. A source that stopped logging mid-window is reported as stopped, with the time and the duration — not as a quiet period.
What it refuses to do
- Correlate across sources with unbounded clock skew — it says the offset is unknown rather than assuming zero
- Name a cause it cannot evidence
- Treat a novel log shape as a finding on its own — every shape in an unseen log is novel
Retention
Per tenant and source class, with compliance holds that outrank it. Deletion is recorded — what, how much, under which policy.
Storage headroom is projected. If ingestion ever stops, it raises a finding at the highest prominence — not a metric nobody watches.
Not running it yet? Start a thirty-day evaluation — read-only, on your own estate, no card.
Thirty days · read-only · no card
Run it beside what you already have, against your real clients. It tells you what your tools are reporting that is not true.