SIEM
Ingest, correlate, investigate — without per-GB sticker shock
Surfaces
Events · Alerts · Rules
Search
KQL / ESQL
Forwarders
Multi-vendor
What it does
The SIEM module covers events, alerts, correlation rules, investigations, and search surfaces (including KQL/ESQL-style explorers). Inbound connectors and outbound forwarders sit alongside native analytics so ops stays in one console.
- Events, alerts, correlation rules
- Investigation workspaces
- Inbound connectors + outbound forwarders
/dashboard/siem. This page is a static capability preview — not a live workspace.Synthetic mockup
| Time | Rule | Severity | Status |
|---|---|---|---|
| 14:02 | Impossible travel | High | Open |
| 13:41 | New local admin | Medium | Investigating |
| 12:18 | Beaconing JA3 | Critical | Escalated |
See it with your data
Request a managed demonstration — staff walks you through this module on a provisioned environment with realistic scenarios.
Request a managed demonstration