Correlation that runs on the stream
Most security information and event management (SIEM) tools write logs to disk first and search them later. UTMStack runs its 600+ detection rules on each event as it is processed, then stores it. Rules can also look back over stored logs, for example to spot five failed logins from the same address within 12 hours.