One schema for every log source.
Derwent Labs normalises every byte of your security telemetry to OCSF before it reaches the SIEM. Detections, dashboards and analysts then work from one language, no matter how many tools sit upstream.
Normalisation comes first.
Everything else follows from it.
Connect any source. Map every field to OCSF. Enrich with the context your detections actually need. Filter the noise. All in flight, before a single byte reaches your SIEM.
Connect any security tool in minutes.
Pick a source and Derwent Labs handles the work you'd otherwise own: the schema, the rate limiting, the retries, and the OCSF mapping on the way out.
- 200+ pre-built connectors
- Auto-discovered schemas + sample payloads
- Universal S3 and HTTP inputs as fallback
One schema. Every tool. No exceptions.
Derwent Labs maps every source to the Open Cybersecurity Schema Framework automatically. Detections, dashboards and analysts stop caring where an event came from, because they already know what to do with it. That's on top of our library of automations and use cases.
- 100+ pre-built automations
- 100+ detection use cases, ready to run
- Write detections once, portable across every SIEM
The context your detections actually need.
Identity from your IdP, asset posture from your CSPM, threat intel from your feeds: all joined onto every normalised event in flight. Your SIEM stops doing the job of a SOAR.
- Identity, asset, geo, threat intel out of the box
- Lookup against any source: Okta, AD, Wiz, custom CSV
- JQ escape hatch for the genuinely weird cases
Stop paying to store healthchecks.
Once everything is normalised, dropping low-value events is one line. Heartbeats, polling traffic and duplicate audit chatter are gone before they hit ingest. Full-fidelity copies live in cheap object storage, ready for replay.
- 60–80% average ingest reduction
- Replay historical data against new detections
- Mask PII before it leaves your network
200+ sources.
One schema.
Every connector ships with an OCSF mapping out of the box: vetted, versioned, and inspectable. You point us at a source and we handle the normalisation.