-
Scanner.dev
-
Indexing
We've built a proprietary, cloud-native log search engine designed for petabyte scale. Our indexes are efficiently maintained in cloud storage instead of in-memory like legacy SIEMs. Users have access to fast advanced queries via serverless compute and monoid data structures.
-
Scanner for Splunk
Move your logs out of expensive Splunk ingestion and into S3. Then, query them using our API directly inside Splunk with a custom command for speeds up to 10TB/sec. Users maintain access to custom content, reports, dashboards, alerts, and more and can save up to 90% on their Splunk bill.
-
Dashboards
Scanner makes it easy to explore your data with out-of-the-box dashboards and the ability to create your own. Users can click into these to easily drill down into a search directly for further analysis at high speeds. We'll have out-of-the-box dashboard examples for different log sources in our public Github repos, which users can pull in and modify as they see fit.
-
Detections-as-code with Github Sync
This feature allows users to manage their detection rules directly in their own GitHub repositories. Threat detections are one of the most important pillars of SIEMs, and we’re excited to help users streamline their threat detection development lifecycle. By embracing software development practices like code reviews, testing, and CI/CD, teams can develop and deploy detections faster.