NEW200+ connectors now onboarded. Map any security source to OCSF with a single pipeline.Read the announcement
Consulting
About us
Book a demoStart now
Back to home
Solutions · By outcome

Cut ingest 60–80%.
Keep every detection.

Normalisation makes filtering trivial. Once every source speaks OCSF, dropping low-value events is a one-liner. Your SIEM only pays for the data that earns its place.

Start now Book a demo
60–80%
average ingest reduction
0
detection regressions
100%
retention in the lake
The problem

You're paying SIEM prices to store heartbeat logs.

Ingestion-based licensing punishes volume, not value. But filtering raw, inconsistent data is fragile and risky, so most teams over-ingest 'just in case' and watch the bill climb every quarter.

Without Derwent Labs
Ingestion pricing that scales with noise, not signal
Per-source filtering rules that break constantly
Fear of dropping data you might need later
What you get

With Derwent Labs in front of your stack

Filter once, everywhere

Write a drop rule against OCSF and it applies across every connector, with no per-source parser babysitting.

Cheap full-fidelity storage

Send a complete copy to object storage at a fraction of SIEM cost. Nothing is ever truly thrown away.

Replay on demand

Re-process archived data against new detections, so filtering aggressively never means losing investigative reach.

The outcome

Same detections and the same coverage, but a SIEM bill that finally reflects the data you actually use.

60–80%
lower ingest
0
engineering hours duplicating rules
Instant
savings on your SIEM bill
Common questions

FAQ

How do I reduce SIEM ingestion costs?
The fastest way to reduce SIEM ingestion costs is to filter low-value events before they reach your SIEM, not after. Derwent Labs normalises every source to OCSF first, so a single drop rule applies across all connectors simultaneously. Teams typically see 60–80% ingest reduction without any detection regressions.
What are heartbeat events and why do they fill up my SIEM?
Heartbeat events are periodic keep-alive messages sent by endpoints, network devices, and security agents to confirm they are online. They carry no security signal but ingest at high frequency, often accounting for 20–40% of SIEM volume. Filtering them out pre-SIEM is one of the highest-ROI changes a security team can make.
How does SIEM licensing cost work?
Most SIEMs charge based on daily ingest volume (GB/day) or events per second. Both models mean noisy, low-value data directly inflates your bill. Reducing ingest through upstream filtering (before data reaches the SIEM) cuts the cost at source, rather than paying to store data and then ignore it.
How do I monitor my log ingestion?
Derwent Labs provides per-source and per-category ingest metrics in the pipeline builder, so you can see exactly what is flowing, at what volume, and where it goes. This makes it straightforward to identify high-volume, low-value sources and apply targeted filters.
Will filtering ingest break my detections?
Not if you filter against OCSF. Because every source is normalised to a common schema before filtering, drop rules target event type and value, not source-specific field names. You can test rules in the sandbox against real historical data before applying them to live ingest.
What is OCSF: how the schema makes filtering safeReducing costs mid-migration: dual-write explainedDerwent Labs vs Cribl: cost comparison
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF, and you can stop maintaining parsers and rewriting detections every time a vendor changes a field.