Security & AssurancePRODUCT SIEM

SIEM

Security events, correlated and queryable

PlannedOn the roadmap. Not built, and not yet scheduled.

Collect security-relevant events from across your estate, correlate them, and let someone ask a question and get an answer quickly. The intended difference is that agent and LLM activity is a first-class event source rather than an awkward afterthought.

What it is meant to do4 CAPABILITIES

The capability we are building toward

  1. 01

    Broad event collection

    Hosts, cloud control planes, identity providers, applications — and agent activity alongside them.

  2. 02

    Correlation across sources

    Single events are rarely the story. Sequences across sources usually are.

  3. 03

    Detection as reviewable code

    Detections should be version-controlled, testable and diffable, not configured in a form and forgotten.

  4. 04

    Investigation that does not stall

    The value of a SIEM is set by how fast an analyst can ask the third and fourth question, not the first.

Why it lives here

One pipeline, not another agent to install

SIEM reads the same instrumented stream as everything else on the platform. That means one collector in your infrastructure, one redaction policy applied before anything leaves it, and one usage bill — rather than a separate vendor, agent and contract per question you want answered.

See how the pipeline fits together →