Black Hat 2026. Find us at Booth #1839  ·  Las Vegas, August Learn more →
7AI Platform

Every source, one question away.

7AI Federated SIEM connects your security sources, including the SIEM you already run, and lets you search across all of them in plain language, normalized to a common schema. Keep your data wherever it makes sense, ask one question, get answers from every source at once, and turn any search into a detection.

app.sevenai.com / detect / federated-search
Run a Federated Search using natural language across all connected sources.
Enter what you are looking for...All sources (17)Run Search
May 20, 2026 · Priya Patel
Show me failed authentication attempts from external IPs in the last 24 hours
⏲ 245 Events
OkMS
Mar 22, 2026 · Lisa Martinez
Lateral movement indicators on endpoints in the past 24 hours
⏲ 89 Events
CSS1
Mar 21, 2026 · Priya Patel
Unusual outbound traffic volumes by host exceeding baseline thresholds over last 7 days
⏲ 1,247 Events
DefCSMS

However you want to work

You decide where your data lives.

A federated approach does not mean ripping anything out. Keep your SIEM and connect it as a source. Keep it, and move some logs into cheaper hot storage. Or run fully federated with no central index at all. 7AI works across every source either way, so you choose how much to centralize and how much to reach where it already lives.

Inside Federated SIEM

The data foundation, shown the way the platform shows it.

01 / Search Across Everything

Ask once. Answer from every source.

Federated Search runs a single natural-language question across all your connected sources at once and returns results normalized to a common schema, so an Okta sign-in and a CrowdStrike detection line up side by side. Export the results, or turn the search straight into a detection rule.

  • Natural-language search across every connected source.
  • Results normalized to OCSF, not source-specific formats.
  • Export to CSV, or draft a detection from any search.
app.sevenai.com / detect / federated-search
Show every event tied to source IP 185.220.101.45 or to any of the 18 users it targeted, including auth attempts and credential-theft endpoint activity in the past 90 days. 7AI 7AI ▾Search Complete
14 Events1/1 queries Export CSV Draft Rule
TimeSourceOCSF classPrincipalDetail
22:13:51Z OkOkta authentication w.bryant@okami-ai.com INVALID_CREDENTIALS · 185.220.101.45
22:12:47Z OkOkta authentication s.thompson@okami-ai.com INVALID_CREDENTIALS · 185.220.101.45
22:11:34Z OkOkta authentication mikael.eriksson@okami-ai.com PASSWORD_RESET_REQUIRED · 185.220.101.45
22:09:13Z OkOkta authentication j.harrington@okami-ai.com INVALID_CREDENTIALS · 185.220.101.45
Apr 5 14:23:11Z CSCrowdStrike Falcon detection_finding NBK-MERIK-01 LummaC2 · T1555.003 Credentials from Web Browsers · high
Results from every source, normalized to one OCSF schema.
02 / Your Logs, Your Way

Keep what you want, where you want.

Bring in the sources you want 7AI to retain, identity, endpoint, cloud, and network, and it ingests, normalizes, and keeps them in hot storage, always searchable. Leave the rest where it lives and reach it through federated search. Health and volume for every source at a glance.

  • Retain logs in 7AI, your existing SIEM, or both.
  • Hot storage that stays searchable, not cold archive.
  • Health and volume monitoring for every source.
app.sevenai.com / store / logs
Total Log Sources
6
Unhealthy
0
Processed Logs · Hot Storage
1,127.4M
165.5 GB
Source NameStatusLast ReceivedVolume
OkOktaACTIVEJust Now4.5 GB
CSCrowdStrikeACTIVEJust Now18.0 GB
MSMicrosoft SentinelACTIVEJust Now120.0 GB
AWSAWS CloudTrailACTIVEYesterday7.0 GB
DefMicrosoft DefenderACTIVE2 Days Ago14.0 GB
WizWizACTIVE4 Days Ago2.0 GB
03 / Detections on All of It

Detections that span your whole estate.

Detection rules run across the normalized data from every source, mapped to MITRE ATT&CK, so one rule can reason over identity, endpoint, and cloud signals together. Draft a new rule from a federated search in a click.

  • Rules across every connected source, not one tool.
  • Mapped to MITRE ATT&CK coverage.
  • Draft a rule straight from a federated search.
app.sevenai.com / detect / detection-rules
Total Detection Rules
222
Triggered Alerts
24,475
MITRE Coverage
78%
Source & RuleTypeMITRE ATT&CKRecent Detections
DefUser Reported PhishingCustom
T1566 PhishingT1566.001 Spearphishing Attachment
798
SplHigh Risk Okta LoginCustom
T1078 Valid AccountsT1110 Brute Force
1,170
7AIPassword SprayCustom
T1110 Brute ForceT1110.003 Password Spraying
1,000
CSSoftware Vulnerability DetectedCustom
T1190 Exploit Public-Facing AppT1068 Privilege Escalation
402
S1Unusual Network TrafficCustom
T1071 Application Layer ProtocolT1048 Exfiltration Alt Protocol
324
7AIImpossible TravelCustom
T1078 Valid AccountsT1078.004 Cloud Accounts
348

What you get

Built to fit how your data already lives.

FederatedSearch in placeOne natural-language question across every connected source.
NormalizedOne schemaEvery source mapped to a common OCSF model.
FlexibleYour callRetain in 7AI hot storage, your existing SIEM, or both.
DetectionsAcross sourcesRules that span your whole estate, mapped to MITRE.

The data foundation under detect, investigate, respond, and hunt.

Questions

Federated SIEM, answered.

What is 7AI Federated SIEM?

A security data platform that connects your existing sources, including your current SIEM, and lets you search across all of them in plain language, normalized to a common schema, then run detections on top. You choose how much to centralize.

Do I have to replace my SIEM?

No. Federated means you work however suits you. Keep your SIEM and connect it as a source. Keep it and move some logs into cheaper hot storage. Or run fully federated with no central SIEM at all. 7AI searches across all of them, so the choice stays yours.

Do I have to learn a query language?

No. You ask in plain language and 7AI builds and runs the query across your sources, then returns normalized results you can export or turn into a detection.

What does normalized to a common schema mean?

Results from different sources are mapped to a shared model based on OCSF, so an Okta authentication and a CrowdStrike detection share the same fields and line up in one view.

How does this connect to the rest of 7AI?

Federated SIEM is the data foundation the rest of the platform runs on. The same normalized data powers detection, investigation, response, and hunting.

Is 7AI Federated SIEM available today?

Yes. 7AI Federated SIEM is generally available. Connect your sources, including the SIEM you already run, and you can search across all of them right away.

Take the full tour

See Federated SIEM on your sources.

We will walk you through federated search, log management, and detections across your own sources, including the SIEM you already run.