The problem
You're paying SIEM prices to store heartbeat logs.
Ingestion-based licensing punishes volume, not value. But filtering raw, inconsistent data is fragile and risky, so most teams over-ingest 'just in case' and watch the bill climb every quarter.
Without Derwent Labs
Ingestion pricing that scales with noise, not signal
Per-source filtering rules that break constantly
Fear of dropping data you might need later
What you get
With Derwent Labs in front of your stack
Filter once, everywhere
Write a drop rule against OCSF and it applies across every connector, with no per-source parser babysitting.
Cheap full-fidelity storage
Send a complete copy to object storage at a fraction of SIEM cost. Nothing is ever truly thrown away.
Replay on demand
Re-process archived data against new detections, so filtering aggressively never means losing investigative reach.
Common questions
FAQ
- How do I reduce SIEM ingestion costs?
- The fastest way to reduce SIEM ingestion costs is to filter low-value events before they reach your SIEM, not after. Derwent Labs normalises every source to OCSF first, so a single drop rule applies across all connectors simultaneously. Teams typically see 60–80% ingest reduction without any detection regressions.
- What are heartbeat events and why do they fill up my SIEM?
- Heartbeat events are periodic keep-alive messages sent by endpoints, network devices, and security agents to confirm they are online. They carry no security signal but ingest at high frequency, often accounting for 20–40% of SIEM volume. Filtering them out pre-SIEM is one of the highest-ROI changes a security team can make.
- How does SIEM licensing cost work?
- Most SIEMs charge based on daily ingest volume (GB/day) or events per second. Both models mean noisy, low-value data directly inflates your bill. Reducing ingest through upstream filtering (before data reaches the SIEM) cuts the cost at source, rather than paying to store data and then ignore it.
- How do I monitor my log ingestion?
- Derwent Labs provides per-source and per-category ingest metrics in the pipeline builder, so you can see exactly what is flowing, at what volume, and where it goes. This makes it straightforward to identify high-volume, low-value sources and apply targeted filters.
- Will filtering ingest break my detections?
- Not if you filter against OCSF. Because every source is normalised to a common schema before filtering, drop rules target event type and value, not source-specific field names. You can test rules in the sandbox against real historical data before applying them to live ingest.