Documentation  /  Modules

Security operations

Log ingestion, detections, correlation and forensics — with retention policy, compliance holds, and an ingestion stop you cannot miss.

Ingestion

Syslog, Windows Event Log, cloud audit logs, firewall and endpoint telemetry. Parsers cover the common sources; unparsed events are retained as residue rather than discarded.

An event that could not be parsed is kept and counted. A pipeline that quietly drops what it does not understand is a pipeline that will drop the one event that mattered.

Detections

Rule-based detections with correlation across sources. Every detection cites the events that fired it, and a proposed rule is never enabled by itself.

Log forensics

Drop a log file and get ranked candidates, each citing the lines it read. Novel formats are handled structurally rather than by needing a parser first.

Silence is a finding. A source that stopped logging mid-window is reported as stopped, with the time and the duration — not as a quiet period.

What it refuses to do

  • Correlate across sources with unbounded clock skew — it says the offset is unknown rather than assuming zero
  • Name a cause it cannot evidence
  • Treat a novel log shape as a finding on its own — every shape in an unseen log is novel

Retention

Per tenant and source class, with compliance holds that outrank it. Deletion is recorded — what, how much, under which policy.

Storage headroom is projected. If ingestion ever stops, it raises a finding at the highest prominence — not a metric nobody watches.

← Monitoring & topology  ·  Patch & vulnerability →

Not running it yet? Start a thirty-day evaluation — read-only, on your own estate, no card.

Thirty days · read-only · no card

Run it beside what you already have, against your real clients. It tells you what your tools are reporting that is not true.

Start an evaluation