Shape is SignalStructured Intelligence
Where it sits

SIEM preprocessing
without dropping anything.

SIET is a structural preprocessing layer for the SIEM you already run. It evaluates security telemetry before that telemetry reaches your SIEM, forwards the events that are structurally significant along with the evidence behind them, and retains everything else at full fidelity outside the per-GB index.

No SIEM replacement. No new analyst console. No rules to write about which of your logs are worth keeping.

Where it sits in the pipeline

One layer, between the telemetry you already collect and the SIEM you already pay for.

Your telemetry

endpoints, network, identity, cloud

→

SIET

reads every event, decides what matters

→

Your SIEM

cases, and the logs behind them

Full-fidelity archive

everything else, in full, nothing dropped

The routing decision is arithmetic

Nothing about which tier an event lands in involves a model, an inference call or a judgement. SIET measures how far each part of your estate has moved from its own recorded history, and that number decides where the event goes.

So it is deterministic and repeatable. The same input produces the same decision every time, and you can be told exactly why any event went where it went. No model to retrain, nothing to hallucinate, and no inference bill that scales with log volume.

What does not change

  • /Your SIEM stays where it is. SIET feeds it, it does not replace it.
  • /Your analysts keep working in the console they already use.
  • /Your existing detection rules keep running throughout, including during warm-up.
  • /Your retention is unchanged. Every raw log is still kept, in full.
  • /No endpoint agent, no new console, no rip and replace.

Every other answer decides in advance

The market has converged on one shape of answer to SIEM ingest cost: work out ahead of time which telemetry is not worth paying for, and stop paying for it. Filter at source, trim in the pipeline, or assign the cheap sources to a cheap tier.

Each of those requires somebody to decide what will not matter, before knowing what the data contains. That decision is where coverage is lost, and it is a decision that has to be maintained forever as the estate changes.

ApproachTypicallyWhat decidesWhat happens to the rest
Source filteringData collection rules, ingest actionsA person names sources or event IDs not worth indexingDropped before collection. Gone.
Pipeline rulesCribl, Databahn, Edge Delta, TenzirA person writes rules about what to trim, summarise or rerouteReduced or rerouted. What survives is still indexed per GB.
TieringThe cheap tier your SIEM already shipsA person assigns each source to a tier up frontKept, but slow and restricted to query. Detection is untouched.
Structural preprocessingSIETMeasured departure from each component’s own recorded historyImplicated events indexed. Everything else archived in full.

SIET decides nothing in advance. Every event is read and evaluated. What is structurally significant goes to the SIEM, and what is not goes to archive-class storage in full, because it was examined rather than assumed to be uninteresting.

What comes off the bill

On the CICIDS2017 benchmark, 99.4% of events avoided indexing entirely on the benign control day, and 72.9% across the full test week. The lowest figure was 28.4% on the DDoS replay, which is almost entirely attack traffic by construction. Nothing was discarded to reach any of those numbers.

At 1 TB a day, a year of telemetry costs roughly £886,000 to hold in a per-GB index and roughly £1,750 to hold in archive-class object storage. The week-wide figure is a pessimistic bound, because seven of the eight replay segments carry attack traffic by construction and no production estate looks like that. The question a preprocessing layer has to answer is which events needed the expensive path, and answering it by measurement rather than by policy is the whole difference. The full cost model.

Which SIEMs this works with

Any SIEM that accepts documents over HTTP. SIET takes ECS or OCSF in and emits three streams: cases for the analyst queue, the raw logs behind each case, and a health stream for whoever owns the pipeline.

That interface has been exercised against Elastic Security and OpenSearch. The same interface applies to Splunk, Microsoft Sentinel, QRadar and Falcon LogScale, none of which require anything SIET does not already emit. What SIET needs and what comes back.

Detection and routing are separable. SIET-Core is the detection engine alone and changes nothing about your storage. SIET-Enterprise adds the routing layer described here. Both tiers.

Run it in front of your SIEM and compare.

Switch nothing off. Leave your existing detection content running, put SIET in the path, and compare what each one raised and what each one asked you to index.