Security Lakehouse

What is a security lakehouse?

A security lakehouse stores every event as open Parquet on storage you own, keeps a hot tier for fast search, and runs detection, investigation and AI analysis directly on that data. It is what you get when you stop paying a SIEM vendor per gigabyte to hold your logs in a format only they can read. SIEMonster builds the only one that is resident at the edge: EDG3.

The three layers

Lake economics, warehouse speed, SIEM outcomes.

The name is literal. A lakehouse puts a warehouse layer on top of a data lake, and a security lakehouse puts the security operations layer on top of both.

01 / THE LAKE

Open columnar storage

Every event lands as Parquet on object storage in your own cloud tenant. Columnar files compress security telemetry extremely well, so years of retention cost what months cost in a SIEM index, and any Parquet-capable engine can read the data.

02 / THE HOUSE

Hot tier and schema

Recent data sits on NVMe for sub-second search and correlation, synced to object storage behind it. Schema is normalised on the way in (OCSF where available) so cross-source queries across endpoint, network, cloud and identity logs work without a parsing project.

03 / THE SECURITY LAYER

Detection, triage, response

Detection-as-Code rules, agentic triage that cites its evidence with ATT&CK context and a confidence score, case management, forensics and approval-gated response, all running on the same data. No second copy in a separate SIEM.

Why now

The SIEM pricing model is the problem the lakehouse solves.

Every traditional SIEM charges by what you send it: gigabytes per day, events per second, or a workload metric that tracks the same thing. The result is predictable. Security teams filter, sample and drop the telemetry they most need, because keeping it is unaffordable. RMIT found 300GB a day on its previous provider astronomical. UMass left an EPS-priced SIEM to secure 9,000 workstations for a fraction of the cost. BlueScope needed 350,000 events per second from SCADA and blast furnaces that no per-EPS vendor would price sanely.

A lakehouse breaks the link between data volume and cost because open columnar storage is cheap and the vendor does not own the format. That changes behaviour: you collect everything, keep it for years, and run detections across the full history rather than a 30-day window. It also ends lock-in, because the day you want to leave, your data is already in Parquet.

The same economics are why SIEMonster V5 was built on open components (OpenSearch, Kafka, Kubernetes) and priced per server with no EPS penalties rather than per gigabyte. EDG3 takes the next step and makes the storage layer itself open and yours.

Edge-resident

Most lakehouses live in the cloud. Yours should live where the attack happens.

Severing the telemetry link is an attacker's first move. A cloud-only lakehouse, like a cloud-only SIEM, goes blind the moment that link drops.

At the endpoint

The EDG3 agent runs deterministic Detection-as-Code locally on Linux, Windows and macOS, with native Windows event collection and Linux eBPF process telemetry. Ransomware behaviour triggers autonomous network isolation on the host, with a safety deadman that restores connectivity if the control channel stays down. Every other response is approval-gated.

In your tenant

The cloud side holds the Parquet lakehouse with an NVMe hot tier, per-tenant storage and keys, regional deployment choice, cross-source correlation with AWS CloudTrail, Microsoft 365, Entra, Okta, GitHub and more, and the AI analyst with its append-only investigation history. Controls map to CIS, NIST 800-53, SOC 2, HIPAA and PCI DSS.

FAQs

Security lakehouse, answered.

A security lakehouse is a security analytics platform that stores all telemetry in open columnar files (Parquet) on object storage, keeps a hot tier for fast queries, and runs detection, search, investigation and AI analysis directly on that data. It combines the economics and retention of a data lake with the real-time alerting of a SIEM, without a proprietary index in between.
A security data lake is storage: cheap, open, long retention, but you bring your own query engine and detection logic. A lakehouse adds the warehouse layer on top of the lake: schema, indexing in the hot tier, a detection engine, and the analyst tooling, so the lake is directly usable for security operations instead of being an archive next to the SIEM.
It replaces the SIEM's storage and analytics tier, which is where the cost and the lock-in live. Correlation rules, dashboards, alerting, case management and SOAR still exist; they run on the lakehouse instead of on a per-gigabyte index. In EDG3 these are built in, and SIEMonster V5 remains available for teams that want a conventional cloud SIEM at scale.
Most lakehouse products are cloud-only: the endpoint ships telemetry to the cloud and all detection happens there. If an attacker severs that link, detection stops. An edge-resident lakehouse runs deterministic detection and autonomous ransomware isolation inside the endpoint agent, so containment continues when the cloud path is cut, and the cloud lakehouse catches up when the link returns.
Because storage is open Parquet on object storage, there is no reason to meter ingestion. EDG3 is priced by endpoint tier with retention included: 6 months on Starter, 1 year on Professional, 3 years on Enterprise and 7+ years on Enterprise Plus. SIEMonster V5 is priced per hosting server. Neither charges per gigabyte or per event.
You do. EDG3 stores Parquet in an isolated tenant with per-tenant storage and keys, in the region you choose. Any engine that reads Parquet (Spark, DuckDB, Athena, Trino, pandas) can query your history directly, so there is no export project if you ever change tools.

See a security lakehouse running at the edge.

EDG3 is live. Start on edg3.io or talk to the SIEMonster team.