UTMStack

Collect every log and check it for threats before it is stored

UTMStack collects logs from every system you run, turns them into one standard format and checks them against detection rules while they stream in. It keeps every event, not only alerts, so you can investigate and prove compliance later.

UTMStack · Data Processing
The data processing view shows how many events each source sent and how many were parsed, analyzed, stored or dropped, with the reason for each drop.
  • Correlation before storage

    Detection rules check each event while it is processed, before it is written to disk. Alerts fire in real time instead of waiting for indexing and slow searches.

  • Every event kept

    UTMStack stores all events and log data, not only the ones tied to alerts. The original log line is always kept next to the parsed version for your audit trail.

  • Cold data you can still search

    Data is stored in hot and cold tiers. Cold data stays searchable without restoring a snapshot first.

  • Retention up to 5 years

    Keep logs as long as your policy or regulator requires, up to 5 years.

  • Lighter on hardware

    Efficient storage and processing keep disk and server needs low, so you need less infrastructure as you grow.

  • One format for every vendor

    Pipelines turn each vendor's log format into one standard event, so a single rule works across firewalls, clouds and servers.

Correlation that runs on the stream

Most security information and event management (SIEM) tools write logs to disk first and search them later. UTMStack runs its 600+ detection rules on each event as it is processed, then stores it. Rules can also look back over stored logs, for example to spot five failed logins from the same address within 12 hours.

UTMStack · Alerting Rules
The alerting rules list with each rule's data types, MITRE ATT&CK technique and impact score. Opening a rule shows its condition as a tree of checks.

Test before you save

The playground takes a sample log and shows exactly how a pipeline parses it and which rules would fire. You catch a wrong field name or a noisy rule before it reaches production.

UTMStack · Rule Playground
The playground turns a sample raw log into a parsed event and lists the alerts it would raise.

Pipelines you control

Pipelines, also called parsing filters, read each raw log, pull out the fields that matter and map them to a standard event with an origin and a target. Build or edit a pipeline step by step in the interface, write it as YAML code, or ask the AI assistant to write it. You also decide the order in which pipelines run.

  • Built-in pipelines for every included integration
  • Steps for JSON, CSV, key-value and pattern extraction, renaming, type conversion and cleanup
  • Drop noisy logs you never need before they use disk
  • A data processing view with received, parsed, analyzed, stored and dropped counts for each source

Storage that grows with you

Storage runs on ClickHouse, a fast column-based database, with hot and cold tiers. Recent data stays on fast disks, older data moves to cheaper storage, and both answer the same searches. The platform scales out automatically with Kubernetes as workloads and data volumes increase.

Questions buyers ask

What does correlation before storage mean?

UTMStack checks each event against detection rules while it is being processed, before it is written to storage. Traditional SIEM tools store first and search later, which adds delay and load. Correlating first is how UTMStack raises alerts in real time.

How long can I keep logs?

You set retention, up to 5 years. UTMStack keeps recent data in a hot tier and older data in a cold tier, and both stay searchable without restoring snapshots. Disk needs depend on how many sources you connect and how long you keep data hot.

Can I bring logs from a source that is not in the integration list?

Yes. Any source can be added as a custom integration over syslog, as JSON, or through the HTTP intake endpoint. You then build a pipeline for it in the interface, in code or with the AI assistant, and test it in the playground.

Does UTMStack store only alerts or all logs?

All of them. UTMStack keeps every event and its original raw log, not only the events tied to alerts. Investigators get full context and auditors get complete records.

How much hardware does it need?

It depends on the number of data sources and how long you keep data in the hot tier. The documentation lists sizing tiers, and our team can size a deployment with you.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.