The problem
You're paying SIEM prices to store heartbeat logs.
Ingestion-based licensing punishes volume, not value. But filtering raw, inconsistent data is fragile and risky — so most teams over-ingest 'just in case' and watch the bill climb every single quarter.
Without Derwent Labs
Ingestion pricing that scales with noise, not signal
Per-source filtering rules that break constantly
Fear of dropping data you might need later
What you get
With Derwent Labs in front of your stack
Filter once, everywhere
Write a drop rule against OCSF and it applies across every connector — no per-source parser babysitting.
Cheap full-fidelity storage
Send a complete copy to object storage at a fraction of SIEM cost. Nothing is ever truly thrown away.
Replay on demand
Re-process archived data against new detections, so filtering aggressively never means losing investigative reach.
Common questions
FAQ
- How do I reduce SIEM ingestion costs?
- The fastest way to reduce SIEM ingestion costs is to filter low-value events before they reach your SIEM — not after. Derwent Labs normalises every source to OCSF first, so a single drop rule applies across all connectors simultaneously. Teams typically see 60–80% ingest reduction without any detection regressions.
- What are heartbeat events and why do they fill up my SIEM?
- Heartbeat events are periodic keep-alive messages sent by endpoints, network devices, and security agents to confirm they are online. They carry no security signal but ingest at high frequency — often accounting for 20–40% of SIEM volume. Filtering them out pre-SIEM is one of the highest-ROI changes a security team can make.
- How does SIEM licensing cost work?
- Most SIEMs charge based on daily ingest volume (GB/day) or events per second. Both models mean noisy, low-value data directly inflates your bill. Reducing ingest through upstream filtering — before data reaches the SIEM — cuts the cost at source rather than paying to store and then ignore it.
- How do I monitor my log ingestion?
- Derwent Labs provides per-source and per-category ingest metrics in the pipeline builder, so you can see exactly what is flowing, at what volume, and where it goes. This makes it straightforward to identify high-volume, low-value sources and apply targeted filters.
- Will filtering ingest break my detections?
- Not if you filter against OCSF. Because every source is normalised to a common schema before filtering, drop rules target event type and value — not source-specific field names. You can test rules in the sandbox against real historical data before applying them to live ingest.