Enhanced federated search makes security analysts more efficient and provides powerful insights on all data while addressing compliance, data ownership and licensing model concerns
Los Angeles, Calif, – April 18, 2024 – Gurucul, the leader in security analytics and the most visionary Next-Gen SIEM provider, today announced enhancements to its federated search capabilities. Gurucul federated search empowers users to run queries from a single console across any data source including data lakes, cloud object storage, databases, identity systems, threat intel sources, and SIEMs – including Splunk. This universal search capability uses a familiar syntax and workflow that makes security analysts more efficient by significantly increasing the data available to them and adding context to security investigations. Since federated search keeps data in the same location it resides, users can maintain compliance and ownership of the data, and reduce data transfer and ingestion costs.
“Compliance, data ownership, and licensing models make broad data collection cost-prohibitive and thwart contextual threat detection and fast response. A powerful single console to search all security and observability data for investigations, regardless of where it resides, is a technical milestone for SIEM and observability use cases while significantly reducing costs and meeting data residency compliance needs” said Nilesh Dherange, CTO at Gurucul. “Gurucul federated search provides radical insights into data that is not centralized, equipping organizations to store data in the most cost-efficient way and supercharging security analysts’ productivity.”
Most organizations are facing one or many of these concerns: ingestion volume-based licensing models, data residency compliance requirements, and high data transfer costs which inhibit centralized data and log collection. In addition, searching disparate individual data sources makes it challenging to harness valuable insights and increases the risk of missed detections and long response times.
Gurucul federated search encompasses all data sources without requiring cross-cloud or restricted cross-region data transfers to a centralized location or manual logins to different applications. It also eliminates the need to ingest and re-index data from federated sources, which provides significant cost reduction.
Other benefits of Gurucul federated search include:
Gurucul federated search is available now as part of the Gurucul Security Analytics Platform. For more information, visit the website here.
Gurucul is a security analytics company founded in data science that delivers radical clarity about cyber risk. We analyze enterprise data at scale using machine learning and native, secure artificial intelligence. Instead of useless alerts, you get real-time, actionable information about true threats. Our cloud-native platform is open and flexible, so it accommodates your environment and processes. Deploy it anywhere, use any data lake, and integrate it with any security tool. To learn more, visit https://gurucul.com/ and follow us on LinkedIn and Twitter.
Austin Williams
Voxus PR for Gurucul
awilliams@voxuspr.com