Stop paying your SIEM to store noise.
SEGARK Pipeline normalizes every security source to OCSF, cuts ingestion volume before it costs you, and routes the rest to any SIEM, lake, or sink you choose. Detection runs in the pipeline, so threats surface before the storage bill does.
- Open-core · AGPLv3. The free tier is actually free
- OCSF-native normalization
- 16 destinations, zero lock-in
- Detection in the pipeline, not after the bill
A simulated run, drawn to scale. Your reduction depends on your sources and your rules.
Most of what you ingest is noise, and you pay SIEM rates to store it
Your SIEM bill grows every quarter, but most of what you are paying to ingest is noise: verbose logs, duplicate events, and low-value telemetry that never triggers a detection. Meanwhile, every new data source means another brittle, vendor-specific connector, and the more you standardize on one platform, the harder it gets to ever leave. You're paying premium per-GB rates to store data you'll never query, locked into tooling you've outgrown.
- 01
Runaway ingestion costs
You pay top-dollar SIEM rates on full-fidelity firehoses, including the 60–80% of volume that has no detection or investigation value.
- 02
Vendor lock-in
Collection, normalization, and routing are all welded to one SIEM, so switching tools or adding a data lake means re-plumbing everything.
- 03
Slow, brittle onboarding
Each new source (EDR, firewall, cloud, identity) is a custom integration with its own schema, delaying coverage and leaving blind spots.
One control point between your sources and your SIEM
Five stages, in this order, on every event. Nothing here is an add-on module.
- 01
Pull from the source. Don't rebuild it.
Plugin-driven collectors talk to Wazuh, Defender, CrowdStrike, Okta, Sophos, Entra ID, CloudTrail and more. Anything without an API pushes in over HTTP. Cursors, watermarks and rate limits are the collector's problem, not yours.
- 02
One schema, applied once.
Every event is mapped to OCSF at the front of the pipeline. After that, one rule matches every vendor, and swapping a destination stops being a migration.
- 03
Decide what's worth paying for.
Drop fields, trim payloads, sample the repetitive, aggregate the countable, suppress the duplicated. All of it before the data ever reaches a metered ingest endpoint.
- 04
Catch it in transit.
Detection runs on the event while it is still moving. A hit is flagged, enriched and forwarded. A reduction rule never silences an event that matched.
- 05
Every event to exactly the destinations that need it.
Route by rule to any supported sink: SIEM, lake, object storage, Kafka, OTLP. Deliveries that fail land in a dead-letter queue you can read and replay, not a black hole.
The result: a single, vendor-neutral control point between your security data and wherever it needs to go. You cut ingestion cost, keep full control of your data, and onboard new sources without re-plumbing your stack.
The console you get on day one
These are screens from the free Community core: the same build you can run tonight.
Watch the whole path at once
Every source, route and destination in one graph. Ribbon thickness is throughput, colour is health. Click any node to drill into what it is doing right now.
Real screens from the Community core. Nothing here is behind a licence.
Collect from what you run. Deliver to what you pay for.
Sources and destinations are plugins. Adding one is a config change, not a fork.
- WazuhSIEM
- Microsoft DefenderEDR / XDR
- CrowdStrike FalconEDR / XDR
- Sophos CentralEDR / XDR
- Microsoft Entra IDIdentity
- OktaIdentity
- AWS CloudTrailCloud audit
- AWS CloudWatch LogsCloud audit
- Fortinet FortiGatepushNetwork
- Windows Event LogpushEndpoint
- NinjaOneRMM
- Veeam Backup & ReplicationBackup
- Splunk HECSIEM
- Elastic / OpenSearchSIEM
- Microsoft SentinelbetaSIEM
- Google SecOpsSIEM
- CrowdStrike Next-Gen SIEMSIEM
- CrowdStrike LogScaleSIEM
- ClickHouseData lake
- S3 / object storeObject storage
- Amazon Security LakebetaObject storage
- Apache KafkabetaStreaming
- DatadogObservability
- OTLP / OpenTelemetryObservability
- Syslog RFC 5424Syslog
- Syslog RFC 3164Syslog
- Generic webhookgenericWebhook
- JSONL fileFile
What your team actually gets
Cut your SIEM bill, not your visibility
Reduce, filter, and route security data before it hits your SIEM, so you stop paying ingestion rates for noise while keeping every event you need for detection and compliance.
Own your data, skip the lock-in
Vendor-neutral routing to 16 destinations, from Splunk and Elastic to Sentinel, ClickHouse, S3, Kafka and LogScale. You move sources and sinks freely instead of being trapped by one vendor's format or contract.
Built for MSSPs, isolated by default
Multi-tenant hierarchy with reseller and partner management gives every customer hard-walled isolation from one console, so you onboard new tenants fast without spinning up separate stacks.
Detect and normalize in the pipeline
Every event is normalized to OCSF and run through in-pipeline detection as it flows, so threats surface in transit and downstream tools receive clean, consistent, analysis-ready data.
Open-core honesty, security-grade engineering
The differences that matter when you put a pipeline in front of every security source.
A free tier that's actually free
SEGARK Pipeline is built on CentralOps, its open-source engine: full AGPLv3, self-hosted, and recompilable, with complete ingestion, routing, all 16 sinks, in-pipeline detection, and an OCSF base. No feature is held hostage behind a license check.
No SSO tax
SSO, OIDC, and RBAC ship in the free core. Access security is table stakes, not an upsell.
Detection happens in the pipeline
We do not just forward data and hope your SIEM catches it. Detection runs in-stream, so signal is surfaced and enriched before storage, on its way to wherever you send it.
OCSF-native, end to end
Normalization to the Open Cybersecurity Schema Framework is built into the core path, not a bolt-on adapter. You get consistent, portable events across every source and destination.
MSSP-grade multi-tenancy
A real tenant and reseller hierarchy with enforced cross-tenant isolation, designed for managed-service scale from day one rather than retrofitted onto a single-org product.
Secrets handled like you'd expect
Credentials and keys are managed through KMS or HashiCorp Vault, with no plaintext secrets sitting in config. Licensing is offline-verifiable and air-gap-friendly, for the most restricted environments.
Start free. Scale when you do.
The Community core is free forever. Pay only when you need a commercial posture, MSSP multi-tenancy, or Enterprise scale.
Security engineers and single-team SOCs who want a real, self-hosted pipeline without a sales call.
Get started free- Full ingestion from any source: Wazuh, Defender/Sentinel, CrowdStrike, FortiGate, syslog, Windows Event Log, push-ingest
- Vendor-neutral routing to 16 destinations: Splunk HEC, Elastic, ClickHouse, S3, Sentinel, Kafka, LogScale, and more
- In-pipeline detection and volume reduction: act on and shrink data before it hits your SIEM
- OCSF-native normalization out of the box
- SSO/OIDC, RBAC and KMS/Vault secrets, included free
- OTel-native observability; self-host on Docker Compose or Kubernetes
A single organization that's running SEGARK Pipeline in production and wants a supported, commercial posture.
Start with Starter- Everything in Community
- Commercial license (no AGPL copyleft obligations)
- Supported, single-tenant production posture with defined SLAs
- Priority bug fixes and security patches
- Onboarding assistance and version-upgrade guidance
- Email/ticket support
Managed security providers and resellers running many customers from one platform.
Talk to sales- Everything in Starter
- Multi-tenant hierarchy with hard cross-tenant isolation
- Reseller / partner management and per-org administration
- Per-tenant routing, detection, quotas, and reporting
- Scoped org-admin roles (delegated tenant management)
- Onboard new customer orgs fast, without new deployments
- MSSP-grade support and onboarding
Large security orgs and regulated environments needing federated search, compliance-grade audit, fleet scale, and air-gapped operation.
Talk to sales- Everything in MSSP
- Federated cross-source, async search across all tenants and sources
- Cross-tenant audit & compliance reporting
- HA / fleet operations at scale
- Offline-verifiable, air-gapped-friendly licensing
- Data residency / data-control controls
- Premium support with named contacts and priority response
Answers before you ask
Everything teams want to know before they run SEGARK Pipeline in production.
Stop paying to store noise.
Spin up the free Community core in minutes. No sales call, no credit card. Upgrade to Starter, MSSP, or Enterprise whenever you're ready.