Every source, one question away.
7AI Federated SIEM connects your security sources, including the SIEM you already run, and lets you search across all of them in plain language, normalized to a common schema. Keep your data wherever it makes sense, ask one question, get answers from every source at once, and turn any search into a detection.
However you want to work
You decide where your data lives.
A federated approach does not mean ripping anything out. Keep your SIEM and connect it as a source. Keep it, and move some logs into cheaper hot storage. Or run fully federated with no central index at all. 7AI works across every source either way, so you choose how much to centralize and how much to reach where it already lives.
Inside Federated SIEM
The data foundation, shown the way the platform shows it.
Ask once. Answer from every source.
Federated Search runs a single natural-language question across all your connected sources at once and returns results normalized to a common schema, so an Okta sign-in and a CrowdStrike detection line up side by side. Export the results, or turn the search straight into a detection rule.
- Natural-language search across every connected source.
- Results normalized to OCSF, not source-specific formats.
- Export to CSV, or draft a detection from any search.
| Time | Source | OCSF class | Principal | Detail |
|---|---|---|---|---|
| 22:13:51Z | OkOkta | authentication | w.bryant@okami-ai.com | INVALID_CREDENTIALS · 185.220.101.45 |
| 22:12:47Z | OkOkta | authentication | s.thompson@okami-ai.com | INVALID_CREDENTIALS · 185.220.101.45 |
| 22:11:34Z | OkOkta | authentication | mikael.eriksson@okami-ai.com | PASSWORD_RESET_REQUIRED · 185.220.101.45 |
| 22:09:13Z | OkOkta | authentication | j.harrington@okami-ai.com | INVALID_CREDENTIALS · 185.220.101.45 |
| Apr 5 14:23:11Z | CSCrowdStrike Falcon | detection_finding | NBK-MERIK-01 | LummaC2 · T1555.003 Credentials from Web Browsers · high |
Keep what you want, where you want.
Bring in the sources you want 7AI to retain, identity, endpoint, cloud, and network, and it ingests, normalizes, and keeps them in hot storage, always searchable. Leave the rest where it lives and reach it through federated search. Health and volume for every source at a glance.
- Retain logs in 7AI, your existing SIEM, or both.
- Hot storage that stays searchable, not cold archive.
- Health and volume monitoring for every source.
| Source Name | Status | Last Received | Volume |
|---|---|---|---|
| OkOkta | ACTIVE | Just Now | 4.5 GB |
| CSCrowdStrike | ACTIVE | Just Now | 18.0 GB |
| MSMicrosoft Sentinel | ACTIVE | Just Now | 120.0 GB |
| AWSAWS CloudTrail | ACTIVE | Yesterday | 7.0 GB |
| DefMicrosoft Defender | ACTIVE | 2 Days Ago | 14.0 GB |
| WizWiz | ACTIVE | 4 Days Ago | 2.0 GB |
Detections that span your whole estate.
Detection rules run across the normalized data from every source, mapped to MITRE ATT&CK, so one rule can reason over identity, endpoint, and cloud signals together. Draft a new rule from a federated search in a click.
- Rules across every connected source, not one tool.
- Mapped to MITRE ATT&CK coverage.
- Draft a rule straight from a federated search.
| Source & Rule | Type | MITRE ATT&CK | Recent Detections |
|---|---|---|---|
| DefUser Reported Phishing | Custom | T1566 PhishingT1566.001 Spearphishing Attachment | 798 |
| SplHigh Risk Okta Login | Custom | T1078 Valid AccountsT1110 Brute Force | 1,170 |
| 7AIPassword Spray | Custom | T1110 Brute ForceT1110.003 Password Spraying | 1,000 |
| CSSoftware Vulnerability Detected | Custom | T1190 Exploit Public-Facing AppT1068 Privilege Escalation | 402 |
| S1Unusual Network Traffic | Custom | T1071 Application Layer ProtocolT1048 Exfiltration Alt Protocol | 324 |
| 7AIImpossible Travel | Custom | T1078 Valid AccountsT1078.004 Cloud Accounts | 348 |
What you get
Built to fit how your data already lives.
The data foundation under detect, investigate, respond, and hunt.
Questions
Federated SIEM, answered.
What is 7AI Federated SIEM?
A security data platform that connects your existing sources, including your current SIEM, and lets you search across all of them in plain language, normalized to a common schema, then run detections on top. You choose how much to centralize.
Do I have to replace my SIEM?
No. Federated means you work however suits you. Keep your SIEM and connect it as a source. Keep it and move some logs into cheaper hot storage. Or run fully federated with no central SIEM at all. 7AI searches across all of them, so the choice stays yours.
Do I have to learn a query language?
No. You ask in plain language and 7AI builds and runs the query across your sources, then returns normalized results you can export or turn into a detection.
What does normalized to a common schema mean?
Results from different sources are mapped to a shared model based on OCSF, so an Okta authentication and a CrowdStrike detection share the same fields and line up in one view.
How does this connect to the rest of 7AI?
Federated SIEM is the data foundation the rest of the platform runs on. The same normalized data powers detection, investigation, response, and hunting.
Is 7AI Federated SIEM available today?
Yes. 7AI Federated SIEM is generally available. Connect your sources, including the SIEM you already run, and you can search across all of them right away.
Take the full tour
See Federated SIEM on your sources.
We will walk you through federated search, log management, and detections across your own sources, including the SIEM you already run.