Market guide

Security Data Pipelines

  • SIEM pricing is a function of ingest volume, and log volume roughly doubles every 18 months. The pipeline exists to break that link.
  • Two acquisitions in a fortnight in 2025 (CrowdStrike/Onum, SentinelOne/Observo AI) took the two fastest-moving independents off the board.
  • Vendor neutrality is the independents' central claim, and it is exactly what a SIEM vendor's ownership complicates.
  • The demos all look the same. What separates the products is what happens to dropped data, who maintains the parsers, and where it can run.
  • Detection is moving upstream into the pipeline, which turns the SIEM into a query layer rather than the place analysis happens.

The market at a glance

Vendors tracked
10
Deals recorded
4
Raised
$15.0M
Acquired for
$515.0M

Every security tool an organisation runs produces logs, and for twenty years the answer to what to do with them was the same: send everything to the SIEM. That answer has stopped working. Log volume roughly doubles every eighteen months while SIEM pricing is still largely a function of how much data you ingest, so the bill grows faster than the security team’s budget and faster than the value of the data being stored. A security data pipeline sits between the sources and the destination and decides what actually needs to go there.

The category has moved quickly from an optimisation to an architectural layer. The pitch began as cost reduction: filter the noise, drop the duplicate Windows events, and cut the SIEM bill by half. It has since become something more structural, because once a pipeline is parsing, normalising and enriching data in stream, it is a control point. It decides what the SIEM sees, what goes to cheap object storage for compliance, and increasingly what gets detected on the way past.

Why this market exists

Four pressures created it, and none of them is easing.

Volume. Cloud estates, identity providers, EDR agents and now AI applications each emit their own telemetry, and the number of sources grows with every tool added. A large enterprise commonly runs forty to fifty security products, each with its own log format.

SIEM economics. Ingest-based pricing was tolerable when the data was firewall and endpoint logs. It is not tolerable when a single cloud provider’s audit trail can exceed the whole previous estate. The pipeline vendors’ most quoted number is the reduction they achieve before ingest, typically claimed between 50% and 80%.

Format sprawl. Detection content is written against fields. When every source names its fields differently, the security team spends its time on parsers rather than on detections. Normalisation in the pipeline moves that work to one place.

Retention rules that differ from detection needs. Regulation often requires keeping data for years that nobody will query in anger. Splitting the hot path from the archive path is cheaper than storing everything where it is most expensive.

What changed in 2025

Two acquisitions inside a fortnight moved this from an emerging category to a contested one. On 27 August 2025 CrowdStrike agreed to buy Onum, a Madrid telemetry-pipeline company, for around $290m. On 8 September SentinelOne agreed to buy Observo AI for roughly $225m in cash and stock. Both buyers sell SIEM products; both bought the layer that decides what reaches a SIEM.

That is worth reading carefully if you are choosing a pipeline. The independent vendors argue their value is vendor-neutrality: a pipeline that will route to any destination gives you leverage over the SIEM contract. When a SIEM vendor owns the pipeline, that argument does not disappear, but it does become a claim the buyer has to test rather than assume. Cribl, the largest independent, has made neutrality its explicit position.

How to evaluate one

The demos in this category look alike, because they all show the same thing: a stream of noisy logs going in and a smaller, tidier stream coming out. The questions that separate the products are less photogenic.

What happens to what you drop? Reduction that discards data is different from reduction that routes it to cheap storage. If an incident later requires the discarded events, the difference is the investigation.

Who writes the parsers, and what happens when a source changes its format? This is the recurring maintenance cost of the category, and the main thing the AI-native entrants claim to solve.

Where does it run? Data residency, air-gapped estates and egress costs all push processing toward the edge. Support for on-premise and hybrid deployment varies sharply.

What does exit look like? A pipeline is a control point by design, which means it is also a dependency. Ask what happens to your parsing and routing logic if you leave.

Where it is going

The clear direction is detection moving upstream. If the pipeline is already parsing and enriching every event in stream, running detection logic there is a short step, and several vendors have taken it, which starts to make the SIEM a query and storage layer rather than the place where analysis happens. Abstract Security has been most explicit about this, positioning a streaming pipeline with embedded detection as a SIEM replacement rather than an adjunct.

The counter-pressure is consolidation. If the major SIEM and endpoint vendors each own a pipeline, the independent market narrows to organisations that specifically want neutrality, which is a real constituency but a smaller one than the whole market. The next year of deals will show which way that resolves.

How the market divides

Independent pipelines
Vendor-neutral by design, routing to any destination. Cribl is the category creator and by far the largest; DataBahn, Axoflow, Tenzir and VirtualMetric compete on automation, deployment model or a specific SIEM.
SIEM-owned pipelines
Acquired by, or built inside, a SIEM or endpoint vendor. CrowdStrike's Onum and SentinelOne's Observo AI, plus Splunk and Datadog's own pipeline products. Tight integration with one destination, in exchange for the neutrality argument.
AI-native entrants
Newer companies whose pitch is that parsing, classification and reduction should be inferred rather than configured, attacking the category's main running cost. Realm.Security and Abstract Security sit here.
Pipeline as SIEM replacement
Vendors moving detection into the stream, leaving storage and query to something cheaper. The most aggressive reading of where the category goes, and the one that would reshape the SIEM market rather than optimise it.

Vendor profiles

Every company we track in this segment, in the same shape: what it does, who it suits, and what to check. Ordered alphabetically: this is not a ranking.

Abstract provides a composable SIEM platform for security operations.

Where it fits. For teams willing to move detection out of the SIEM and into the stream. Sold as a SIEM alternative rather than something that sits in front of one.

Watch for. The most architecturally ambitious position in the category, which makes it the biggest change to how a SOC works. Detection content and analyst workflow have to move with it.

Axoflow provides an autonomous security data layer that curates and manages security data for SecOps.

Where it fits. Built by the author of syslog-ng, and aimed at teams whose pain is classifying and parsing messy sources rather than routing them.

Watch for. Small and European, so US enterprise support and partner coverage are worth checking. Strongest on ingestion problems, less broad elsewhere.

Cribl provides a vendor-agnostic platform for managing, investigating, and analyzing telemetry data.

Where it fits. The default choice for large enterprises that want one pipeline in front of several destinations and do not want their pipeline owned by a SIEM vendor.

Watch for. The most expensive option in the category, and the breadth that suits a large estate is overhead for a small one. Its neutrality is a commercial position rather than a technical guarantee, so it is worth confirming contractually.

DataBahn provides an agentic data control plane for managing and optimizing enterprise telemetry.

Where it fits. Aimed at security teams that want reduction working quickly without building it themselves, using packaged rules per source rather than hand-written pipelines.

Watch for. Younger than Cribl with a smaller partner network. Packaged reduction is fast to start with and less flexible when a source does something unusual.

Where it fits. A developer-facing control plane rather than a UI-first product: pipelines defined as code, for teams that already work that way.

Watch for. Assumes engineering capacity a smaller security team may not have. Its acquisition of Tarsal in 2025 broadened it, and integration is still worth asking about.

Observo AI built an AI-native security data pipeline that filtered and enriched telemetry before it reached the SIEM.

Where it fits. Now SentinelOne's pipeline. Relevant to SentinelOne customers; no longer an independent option.

Watch for. Acquired September 2025. As with Onum, what matters is whether it remains usable with destinations other than its owner's.

Onum built a real-time telemetry pipeline that filtered, enriched and routed security data in stream.

Where it fits. Now CrowdStrike's pipeline, sold into Falcon Next-Gen SIEM. Relevant to CrowdStrike customers; no longer an independent option.

Watch for. Acquired August 2025. Standalone availability and roadmap outside Falcon are the open questions.

Realm Security provides a SOC-aware security data pipeline that reduces SIEM log volume without breaking threat detections.

Where it fits. The newest entrant, arguing that reduction should be inferred from what detections actually use rather than configured by hand.

Watch for. Founded in 2024 and $20m raised, so the smallest reference base in this guide. The claim to protect detections while cutting volume is exactly what to test on your own data.

Tenzir provides an agentic telemetry pipeline for data-driven cyber defenders.

Where it fits. Research-led and pipeline-language-first, for teams that want to express processing precisely rather than assemble it in a UI.

Watch for. The smallest commercial presence of the independents here. Suits teams comfortable with an open, technical product and a young support organisation.

VirtualMetric provides a security data pipeline platform that collects, normalizes, enriches, filters, and routes data to SIEMs.

Where it fits. Specialised on Microsoft Sentinel. The clearest fit for organisations standardised on Microsoft security whose problem is Sentinel's ingest bill.

Watch for. That focus is the trade: less compelling for a multi-SIEM estate, and it ties a cost-control layer to one destination's roadmap.

Capability comparison

How many vendors claim each capabilityVendor-neutral4Reduction4Enrichment4AI-assisted parsing4Own storage4Packaged rules4Hybrid / on-prem3Pipelines as code3In-stream detection3
Vendors claiming each capability, of 4 profiled. What every vendor claims is table stakes; the short bars are where the products actually differ. Taken from what vendors publish, not from testing.
VendorVendor-neutralReductionEnrichmentAI-assisted parsingOwn storagePackaged rulesIn-stream detectionHybrid / on-premPipelines as code
Abstract Security··
Axoflow
Cribl·
Realm.Security
DataBahnNot yet checked against the vendor’s own material
MonadNot yet checked against the vendor’s own material
Observo AINot yet checked against the vendor’s own material
OnumNot yet checked against the vendor’s own material
TenzirNot yet checked against the vendor’s own material
VirtualMetricNot yet checked against the vendor’s own material

A tick means the capability is stated in the vendor’s own published material, checked vendor by vendor. It is not a test result, a score, or a judgement about how well the thing is done: we have not run these products. A dot means we found no such claim, which is not the same as the product lacking it. 4 of 10 vendors have been checked so far; the rest are listed as unchecked rather than left looking like they claim nothing, because those are very different things. † marks a list recorded from our own knowledge of the product rather than the vendor’s published material (Realm.Security). We have asked the vendor to confirm it, and will say so here when they do. Dates and sources are on each company’s page.

The shape of the market

Two things worth knowing about any segment before reading vendor by vendor: how old the companies in it are, and what the money has done.

Founding year of the vendors in this segment201612017120181201902020120210202222023320241
Founding year, for the 10 vendors of 10 whose year we hold.
Disclosed deal value by year2025 acquired515m2025 raised15m
Disclosed amounts only, in US dollars, from the deals recorded above. Undisclosed rounds and acquisitions are not estimated, so this is a floor rather than a total.

Recorded deals

Every funding round and acquisition we hold for this segment, each linked to the report it came from.

DateCompanyTypeAmountSource
2026-08-19CriblAcquisitionUndisclosedsiliconangle.com
2025-10-09Realm.SecurityFunding · Series A$15.0Mwww.securityweek.com
2025-09-08Observo AIAcquisition$225.0Mwww.securityweek.com
2025-08-27OnumAcquisition$290.0Mwww.bankinfosecurity.com

How this guide is made

The prose is written and reviewed by us. The vendor list, the figures, the capability matrix, the deal table and the news below are queried from our directory each time this page loads, so they do not go stale between reviews.

What sits behind it: public reporting, each company’s own published material, and the funding and acquisition records we keep, every one of which links to its source. We have not run these products, spoken to their customers under NDA, or taken payment from anyone named here. Where a capability is listed it is because the vendor states it, not because we verified it. Treat this as a map of the market and a set of questions to ask, not as a substitute for a trial on your own data.

Something wrong or missing? Tell us: corrections are made on the page.