SEGARK / Pipeline

Stop paying your SIEM to store noise.

SEGARK Pipeline normalizes every security source to OCSF, cuts ingestion volume before it costs you, and routes the rest to any SIEM, lake, or sink you choose. Detection runs in the pipeline, so threats surface before the storage bill does.

  • Open-core · AGPLv3. The free tier is actually free
  • OCSF-native normalization
  • 16 destinations, zero lock-in
  • Detection in the pipeline, not after the bill
Ingested138 MB/s
Avoided87 MB/s
Delivered51 MB/s

A simulated run, drawn to scale. Your reduction depends on your sources and your rules.

Route by rule
The problem

Most of what you ingest is noise, and you pay SIEM rates to store it

Your SIEM bill grows every quarter, but most of what you are paying to ingest is noise: verbose logs, duplicate events, and low-value telemetry that never triggers a detection. Meanwhile, every new data source means another brittle, vendor-specific connector, and the more you standardize on one platform, the harder it gets to ever leave. You're paying premium per-GB rates to store data you'll never query, locked into tooling you've outgrown.

  • 01

    Runaway ingestion costs

    You pay top-dollar SIEM rates on full-fidelity firehoses, including the 60–80% of volume that has no detection or investigation value.

  • 02

    Vendor lock-in

    Collection, normalization, and routing are all welded to one SIEM, so switching tools or adding a data lake means re-plumbing everything.

  • 03

    Slow, brittle onboarding

    Each new source (EDR, firewall, cloud, identity) is a custom integration with its own schema, delaying coverage and leaving blind spots.

How it works

One control point between your sources and your SIEM

Five stages, in this order, on every event. Nothing here is an add-on module.

  1. 01

    Pull from the source. Don't rebuild it.

    Plugin-driven collectors talk to Wazuh, Defender, CrowdStrike, Okta, Sophos, Entra ID, CloudTrail and more. Anything without an API pushes in over HTTP. Cursors, watermarks and rate limits are the collector's problem, not yours.

  2. 02

    One schema, applied once.

    Every event is mapped to OCSF at the front of the pipeline. After that, one rule matches every vendor, and swapping a destination stops being a migration.

  3. 03

    Decide what's worth paying for.

    Drop fields, trim payloads, sample the repetitive, aggregate the countable, suppress the duplicated. All of it before the data ever reaches a metered ingest endpoint.

  4. 04

    Catch it in transit.

    Detection runs on the event while it is still moving. A hit is flagged, enriched and forwarded. A reduction rule never silences an event that matched.

  5. 05

    Every event to exactly the destinations that need it.

    Route by rule to any supported sink: SIEM, lake, object storage, Kafka, OTLP. Deliveries that fail land in a dead-letter queue you can read and replay, not a black hole.

The result: a single, vendor-neutral control point between your security data and wherever it needs to go. You cut ingestion cost, keep full control of your data, and onboard new sources without re-plumbing your stack.

See it working

The console you get on day one

These are screens from the free Community core: the same build you can run tonight.

Flow mapLive
Collected71.4k/s
Avoided44.8k/s
Delivered26.6k/s
DLQ312
Sources
wazuh · detections18.4k/s
defender · alerts2.1k/s
entra id · signins9.7k/s
fortigate · traffic41.2k/s
Routes
siem-critical6.0k/s
lake-archive63.9k/s
netflow-sample1.5k/s
Destinations
splunk-prod6.0k/s
s3-archive63.9k/s
sentinel-eu0/s

Watch the whole path at once

Every source, route and destination in one graph. Ribbon thickness is throughput, colour is health. Click any node to drill into what it is doing right now.

Real screens from the Community core. Nothing here is behind a licence.

Coverage

Collect from what you run. Deliver to what you pay for.

Sources and destinations are plugins. Adding one is a config change, not a fork.

Sources1216 collector streams
  • Wazuh
  • Microsoft Defender
  • CrowdStrike Falcon
  • Sophos Central
  • Microsoft Entra ID
  • Okta
  • AWS CloudTrail
  • AWS CloudWatch Logs
  • Fortinet FortiGatepush
  • Windows Event Logpush
  • NinjaOne
  • Veeam Backup & Replication
Destinations1612 stable
  • Splunk HEC
  • Elastic / OpenSearch
  • Microsoft Sentinelbeta
  • Google SecOps
  • CrowdStrike Next-Gen SIEM
  • CrowdStrike LogScale
  • ClickHouse
  • S3 / object store
  • Amazon Security Lakebeta
  • Apache Kafkabeta
  • Datadog
  • OTLP / OpenTelemetry
  • Syslog RFC 5424
  • Syslog RFC 3164
  • Generic webhookgeneric
  • JSONL file
Outcomes

What your team actually gets

Cut your SIEM bill, not your visibility

Reduce, filter, and route security data before it hits your SIEM, so you stop paying ingestion rates for noise while keeping every event you need for detection and compliance.

Own your data, skip the lock-in

Vendor-neutral routing to 16 destinations, from Splunk and Elastic to Sentinel, ClickHouse, S3, Kafka and LogScale. You move sources and sinks freely instead of being trapped by one vendor's format or contract.

Built for MSSPs, isolated by default

Multi-tenant hierarchy with reseller and partner management gives every customer hard-walled isolation from one console, so you onboard new tenants fast without spinning up separate stacks.

Detect and normalize in the pipeline

Every event is normalized to OCSF and run through in-pipeline detection as it flows, so threats surface in transit and downstream tools receive clean, consistent, analysis-ready data.

Why SEGARK Pipeline

Open-core honesty, security-grade engineering

The differences that matter when you put a pipeline in front of every security source.

A free tier that's actually free

SEGARK Pipeline is built on CentralOps, its open-source engine: full AGPLv3, self-hosted, and recompilable, with complete ingestion, routing, all 16 sinks, in-pipeline detection, and an OCSF base. No feature is held hostage behind a license check.

No SSO tax

SSO, OIDC, and RBAC ship in the free core. Access security is table stakes, not an upsell.

Detection happens in the pipeline

We do not just forward data and hope your SIEM catches it. Detection runs in-stream, so signal is surfaced and enriched before storage, on its way to wherever you send it.

OCSF-native, end to end

Normalization to the Open Cybersecurity Schema Framework is built into the core path, not a bolt-on adapter. You get consistent, portable events across every source and destination.

MSSP-grade multi-tenancy

A real tenant and reseller hierarchy with enforced cross-tenant isolation, designed for managed-service scale from day one rather than retrofitted onto a single-org product.

Secrets handled like you'd expect

Credentials and keys are managed through KMS or HashiCorp Vault, with no plaintext secrets sitting in config. Licensing is offline-verifiable and air-gap-friendly, for the most restricted environments.

Pricing

Start free. Scale when you do.

The Community core is free forever. Pay only when you need a commercial posture, MSSP multi-tenancy, or Enterprise scale.

CommunityFree, forever

Security engineers and single-team SOCs who want a real, self-hosted pipeline without a sales call.

Get started free
  • Full ingestion from any source: Wazuh, Defender/Sentinel, CrowdStrike, FortiGate, syslog, Windows Event Log, push-ingest
  • Vendor-neutral routing to 16 destinations: Splunk HEC, Elastic, ClickHouse, S3, Sentinel, Kafka, LogScale, and more
  • In-pipeline detection and volume reduction: act on and shrink data before it hits your SIEM
  • OCSF-native normalization out of the box
  • SSO/OIDC, RBAC and KMS/Vault secrets, included free
  • OTel-native observability; self-host on Docker Compose or Kubernetes
StarterFrom a flat monthly fee

A single organization that's running SEGARK Pipeline in production and wants a supported, commercial posture.

Start with Starter
  • Everything in Community
  • Commercial license (no AGPL copyleft obligations)
  • Supported, single-tenant production posture with defined SLAs
  • Priority bug fixes and security patches
  • Onboarding assistance and version-upgrade guidance
  • Email/ticket support
MSSPMost popularTalk to sales

Managed security providers and resellers running many customers from one platform.

Talk to sales
  • Everything in Starter
  • Multi-tenant hierarchy with hard cross-tenant isolation
  • Reseller / partner management and per-org administration
  • Per-tenant routing, detection, quotas, and reporting
  • Scoped org-admin roles (delegated tenant management)
  • Onboard new customer orgs fast, without new deployments
  • MSSP-grade support and onboarding
EnterpriseTalk to sales

Large security orgs and regulated environments needing federated search, compliance-grade audit, fleet scale, and air-gapped operation.

Talk to sales
  • Everything in MSSP
  • Federated cross-source, async search across all tenants and sources
  • Cross-tenant audit & compliance reporting
  • HA / fleet operations at scale
  • Offline-verifiable, air-gapped-friendly licensing
  • Data residency / data-control controls
  • Premium support with named contacts and priority response
FAQ

Answers before you ask

Everything teams want to know before they run SEGARK Pipeline in production.

Stop paying to store noise.

Spin up the free Community core in minutes. No sales call, no credit card. Upgrade to Starter, MSSP, or Enterprise whenever you're ready.