NEW200+ connectorsnow onboarded — pipe any security source into OCSF effortlessly.Read the announcement
Consulting
About us
Book a demoStart now
NEWOCSF 1.7 is live — one schema across 200+ security tools

One schema for
every log source.

Derwent Labs normalise every byte of your security telemetry to OCSF before it hits the SIEM — so your detections, dashboards and analysts speak one language, no matter how many tools sit upstream.

Start now View integrations
OCSF 1.7 out of the box
app.derwentlabs.com / pipelines / prod-edr-router
Live · 18.4k rps
Sources11 connected
AWS CloudTrail
AWS CloudTrail
2.8k rps
ocsf
Okta · Audit
Okta · Audit
4.2k rps
ocsf
C
CrowdStrike FDR
11.4k rps
ocsf
GitHub Audit
GitHub Audit
240 rps
ocsf
Normalise · Enrich · Filterv1.42.0
Normalise to OCSF 1.7100%
Normalise · timestamps to UTC42 fields
Enrich · identity (Okta + AD)98.4%
Enrich · asset (Wiz CMDB)92.1%
Filter · drop heartbeat events−34%
Destinations3 active
Splunk · HEC
Splunk · HEC
OCSF · high-value
L
S3 Data Lake
OCSF · full fidelity
D
Datadog SIEM
OCSF · cloud only
Throughput
18.4krps
+12%
OCSF mapped
100%
Enriched
96.2%
p95 latency
48ms
Errors (1h)
0
How Derwent Labs works

Normalisation is the unlock.
Everything else follows.

Connect any source. Map every field to OCSF. Enrich with the context your detections actually need. Filter the noise. All in flight, before a single byte reaches your SIEM.

01 · Managed connectors

Connect any security tool in minutes.

Pick a source and Derwent Labs quietly handles the work you'd otherwise own — the schema, the rate limiting, the retries, and the OCSF mapping on the way out.

  • 200+ pre-built connectors
  • Auto-discovered schemas + sample payloads
  • Universal S3 and HTTP inputs as fallback
app.derwentlabs.com / sources
Search 200+ connectors…
Okta
Okta
Identity
LIVE
C
CrowdStrike
EDR
LIVE
AWS CloudTrail
AWS CloudTrail
Cloud
LIVE
W
Wiz
CSPM
LIVE
GitHub
GitHub
Developer
LIVE
Duo
Duo
Identity
Connect →
T
Tines Events
SOAR
Connect →
S
Semgrep
AppSec
Connect →
02 · Normalise to OCSF

One schema. Every tool. No exceptions.

Derwent Labs maps every source to the Open Cybersecurity Schema Framework — automatically. Detections, dashboards and analysts stop caring where it came from, they already know what to do. Leverage the power of Derwent Labs' library of automations and use cases.

  • 100+ pre-built automations
  • 100+ detection use cases, ready to run
  • Write detections once — portable across every SIEM
normalise · OCSF 1.7 · authentication
Raw · 3 vendors · 4 schemas
Okta
Okta
system_log
eventType
actor.alternateId
outcome.result
published
C
CrowdStrike
FDR · UserLogonEvent
event_simpleName
UserName
Success
@timestamp
AWS
AWS
CloudTrail · ConsoleLogin
eventName
userIdentity.userName
errorCode
eventTime
OCSF · Authentication · 3002
1 SCHEMA
activity_id
1 · Logon
3 sources
actor.user.email
alex.lee@navan.com
3 sources
status_id
1 · Success
3 sources
time
1715583122
3 sources
Coverage 100%Write once · run everywhere
03 · Enrich in flight

The context your detections actually need.

Identity from your IdP, asset posture from your CSPM, threat intel from your feeds — joined onto every normalised event in flight. Your SIEM stops being a SOAR-with-extra-steps.

  • Identity, asset, geo, threat intel out of the box
  • Lookup against any source — Okta, AD, Wiz, custom CSV
  • JQ escape hatch for the genuinely weird cases
pipeline · sandbox · enrich identity + asset
enrich.jq · authentication
1# join identity context
2lookup(.actor.user.email)
3| .actor.user.department
4| .actor.user.is_privileged
5| .device += wiz.posture
6
Enriched event (OCSF)
4 lookups · 38ms
{
  "activity_id": 1,
  "actor.user.email": "a.lee@co.com",
  "department": "engineering",
  "is_privileged": true
}
04 · Filter the noise

Stop paying to store healthchecks.

Once everything is normalised, dropping low-value events is one line. Heartbeats, polling traffic, duplicate audit chatter — gone before they hit ingest. Full-fidelity copies live in cheap object storage, ready for replay.

  • 60–80% average ingest reduction
  • Replay historical data against new detections
  • Mask PII before it leaves your network
pipeline · filter · last 24h
Volume by stage · last 24h
full-fidelity copy → S3
Raw ingest
100k rps
baseline
Dedup
92k rps
−8%
Drop healthchecks
65k rps
−29%
Drop low-value
38k rps
−42%
To SIEM
32k rps
−16%
Ingest reduction
68%
SIEM bill / yr
$1.2M
saved
Detection regressions
0
full-fidelity replay
Integrations

200+ sources.
One schema.

Every connector ships with an OCSF mapping out of the box — vetted, versioned, and inspectable. You connect. We normalise.

200+pre-mapped connectors
OCSF 1.7out of the box
< 5 minmedian time-to-first-event
Explore all integrations
Splunk
Splunk
Microsoft Sentinel
Microsoft Sentinel
C
CrowdStrike Falcon
W
Wiz
Okta
Okta
AWS CloudTrail
AWS CloudTrail
Azure Monitor
Azure Monitor
GCP Audit Logs
GCP Audit Logs
GitHub Enterprise
GitHub Enterprise
Z
Zscaler
D
Defender for Endpoint
Duo Security
Duo Security
T
Tines
Jira
Jira
T
Tenable Nessus
Chronicle
Chronicle
Qualys VMDR
Qualys VMDR
Sumo Logic
Sumo Logic
Elastic
Elastic
P
Proofpoint
200+ more connectorsRequest integration
Why teams choose Derwent Labs

Normalisation isn't a feature.
It's the whole point.

5 min
to adopt years of work

Detections and automations become portable.

Because every source maps to OCSF, detections and automations stop being tied to one stack — they're transferable and unified. A set of automations another team spent years building can drop into your pipeline in five minutes.

60–80%
average ingest reduction

Cost optimisation at every step.

Once your data is normalised, dropping noise is one line of JQ. Smart filtering kills heartbeat traffic before it hits expensive storage — less noise, lower bills, more budget for real security work.

< 5 min
to first OCSF event

Onboard in minutes.

No professional services. No implementation consultants. No 6-month deployments. Connect your first source and you'll have normalised OCSF data flowing before your coffee gets cold.

3+ SIEMs
dual-write supported

Vendor independence.

Sentinel getting expensive? Splunk looking shiny? When your data is centralised before ingestion, you can dual-write today and migrate tomorrow.

Get started

From signup to signal in three steps.

01.

Connect your security stack

Seamlessly connect your existing tools — no coding needed. Derwent Labs securely ingests your security data in minutes.

Search 200+ connectors
Okta
Okta
● Connected
C
CrowdStrike
AWS
AWS
W
Wiz
GitHub
GitHub
D
Datadog
02.

Normalise to OCSF, automatically

Every byte from every source is mapped to OCSF 1.7 on the way in. One schema, one mental model, one query language.

NORMALISE → OCSF 1.7
eventType activity_id
actor.alternateId actor.user.email
outcome.result status_id
published time
Okta · system_log4/4 mapped
03.

Enrich and ship clean data

Identity, asset, and threat context joined in flight. Filter the noise. Ship signal to your SIEM — and a full-fidelity copy to your lake.

Splunk
Splunk
OCSF · high-value
LIVE
L
S3 Lake
OCSF · full fidelity
LIVE
Sentinel
Sentinel
OCSF · cloud only
LIVE
FAQ

Frequently asked questions.

Hit "Start now" at the top of this page and get a call booked in. We'll walk you through connecting your first source and get normalised OCSF data flowing.
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF. Stop maintaining parsers. Stop rewriting detections. Start shipping signal.