Unified schema
Endpoint, network, email, identity, cloud — same shape. Same query.
Central event store. Fast KQL-style queries. Investigation pivots.
SIEM and Search is the central event store and query layer of the platform. Every signal from every module lands here in a single normalized schema. The query language is KQL-style — familiar to analysts coming from Microsoft Sentinel or Elastic — and runs distributed across hot, warm and cold storage tiers tuned by you, not the vendor. Saved hunts, scheduled correlations and investigation timelines are built in.
Endpoint, network, email, identity, cloud — same shape. Same query.
Familiar syntax, fast autocomplete, time-travel queries, saved hunts.
Rules in Git. Review via pull request. Deploy via CI. Roll back instantly.
You decide hot (30d), warm (1y), cold (5y). No mandatory retention upcharges.
Pin alerts to a case, build narrative, share with peers, export to audit.
Hypothesis-driven queries across modules. Save, schedule, share with team.
SOC 2, ISO 27001 evidence built from the same data analysts query.
Author rules in Sigma or DSL. Test against historical data. Deploy with confidence.
| Ingest rate | Up to 2 PB/day per cluster |
| Query language | Protoxol DSL (KQL-compatible) |
| Query latency | Sub-second for 30d hot tier |
| Retention max | 10 years cold storage available |
Traditional SIEM is expensive, slow and rules-heavy. Modern alternatives focus on cost or search speed but rarely both. Protoxol SIEM is built for analysts who keyboard, not for procurement decks.
| Vendor | Strength | Tradeoff |
|---|---|---|
| Splunk | Mature. Massive app ecosystem. | Ingest-tier pricing. Slow at scale without expertise. |
| Elastic Security | Open core. Fast queries. | DIY-heavy. Detection rules need engineering. |
| Microsoft Sentinel | Native Azure logs. Strong M365 fit. | Costs balloon outside Azure. UI lags. |
EDR, NDR, mail and cloud queryable with the same surface.
Designed for keyboard pivots, not BI dashboards.
Pay for what you store, not what you ingest.
Thirty minutes. Your environment. The modules that fit. No slideware.