What is a security lakehouse?
A security lakehouse stores every event as open Parquet on storage you own, keeps a hot tier for fast search, and runs detection, investigation and AI analysis directly on that data. It is what you get when you stop paying a SIEM vendor per gigabyte to hold your logs in a format only they can read. SIEMonster builds the only one that is resident at the edge: EDG3.
Lake economics, warehouse speed, SIEM outcomes.
The name is literal. A lakehouse puts a warehouse layer on top of a data lake, and a security lakehouse puts the security operations layer on top of both.
Open columnar storage
Every event lands as Parquet on object storage in your own cloud tenant. Columnar files compress security telemetry extremely well, so years of retention cost what months cost in a SIEM index, and any Parquet-capable engine can read the data.
Hot tier and schema
Recent data sits on NVMe for sub-second search and correlation, synced to object storage behind it. Schema is normalised on the way in (OCSF where available) so cross-source queries across endpoint, network, cloud and identity logs work without a parsing project.
Detection, triage, response
Detection-as-Code rules, agentic triage that cites its evidence with ATT&CK context and a confidence score, case management, forensics and approval-gated response, all running on the same data. No second copy in a separate SIEM.
The SIEM pricing model is the problem the lakehouse solves.
Every traditional SIEM charges by what you send it: gigabytes per day, events per second, or a workload metric that tracks the same thing. The result is predictable. Security teams filter, sample and drop the telemetry they most need, because keeping it is unaffordable. RMIT found 300GB a day on its previous provider astronomical. UMass left an EPS-priced SIEM to secure 9,000 workstations for a fraction of the cost. BlueScope needed 350,000 events per second from SCADA and blast furnaces that no per-EPS vendor would price sanely.
A lakehouse breaks the link between data volume and cost because open columnar storage is cheap and the vendor does not own the format. That changes behaviour: you collect everything, keep it for years, and run detections across the full history rather than a 30-day window. It also ends lock-in, because the day you want to leave, your data is already in Parquet.
The same economics are why SIEMonster V5 was built on open components (OpenSearch, Kafka, Kubernetes) and priced per server with no EPS penalties rather than per gigabyte. EDG3 takes the next step and makes the storage layer itself open and yours.
Most lakehouses live in the cloud. Yours should live where the attack happens.
Severing the telemetry link is an attacker's first move. A cloud-only lakehouse, like a cloud-only SIEM, goes blind the moment that link drops.
At the endpoint
The EDG3 agent runs deterministic Detection-as-Code locally on Linux, Windows and macOS, with native Windows event collection and Linux eBPF process telemetry. Ransomware behaviour triggers autonomous network isolation on the host, with a safety deadman that restores connectivity if the control channel stays down. Every other response is approval-gated.
In your tenant
The cloud side holds the Parquet lakehouse with an NVMe hot tier, per-tenant storage and keys, regional deployment choice, cross-source correlation with AWS CloudTrail, Microsoft 365, Entra, Okta, GitHub and more, and the AI analyst with its append-only investigation history. Controls map to CIS, NIST 800-53, SOC 2, HIPAA and PCI DSS.
Security lakehouse, answered.
See a security lakehouse running at the edge.
EDG3 is live. Start on edg3.io or talk to the SIEMonster team.