NEW200+ connectorsnow onboarded — pipe any security source into OCSF effortlessly.Read the announcement
Consulting
About us
Book a demoStart now
Back to home
Solutions · By outcome

Cut ingest 60–80%.
Keep every detection.

Normalisation makes filtering trivial. Once every source speaks OCSF, dropping low-value events is a one-liner — your SIEM only pays for the data that earns its place.

Start now Book a demo
60–80%
average ingest reduction
0
detection regressions
100%
retention in the lake
The problem

You're paying SIEM prices to store heartbeat logs.

Ingestion-based licensing punishes volume, not value. But filtering raw, inconsistent data is fragile and risky — so most teams over-ingest 'just in case' and watch the bill climb every single quarter.

Without Derwent Labs
Ingestion pricing that scales with noise, not signal
Per-source filtering rules that break constantly
Fear of dropping data you might need later
What you get

With Derwent Labs in front of your stack

Filter once, everywhere

Write a drop rule against OCSF and it applies across every connector — no per-source parser babysitting.

Cheap full-fidelity storage

Send a complete copy to object storage at a fraction of SIEM cost. Nothing is ever truly thrown away.

Replay on demand

Re-process archived data against new detections, so filtering aggressively never means losing investigative reach.

The outcome

Same detections. Same coverage. A SIEM bill that finally reflects the data you actually use.

60–80%
lower ingest
0
engineering hours duplicating rules
Instant
savings on your SIEM bill
Common questions

FAQ

How do I reduce SIEM ingestion costs?
The fastest way to reduce SIEM ingestion costs is to filter low-value events before they reach your SIEM — not after. Derwent Labs normalises every source to OCSF first, so a single drop rule applies across all connectors simultaneously. Teams typically see 60–80% ingest reduction without any detection regressions.
What are heartbeat events and why do they fill up my SIEM?
Heartbeat events are periodic keep-alive messages sent by endpoints, network devices, and security agents to confirm they are online. They carry no security signal but ingest at high frequency — often accounting for 20–40% of SIEM volume. Filtering them out pre-SIEM is one of the highest-ROI changes a security team can make.
How does SIEM licensing cost work?
Most SIEMs charge based on daily ingest volume (GB/day) or events per second. Both models mean noisy, low-value data directly inflates your bill. Reducing ingest through upstream filtering — before data reaches the SIEM — cuts the cost at source rather than paying to store and then ignore it.
How do I monitor my log ingestion?
Derwent Labs provides per-source and per-category ingest metrics in the pipeline builder, so you can see exactly what is flowing, at what volume, and where it goes. This makes it straightforward to identify high-volume, low-value sources and apply targeted filters.
Will filtering ingest break my detections?
Not if you filter against OCSF. Because every source is normalised to a common schema before filtering, drop rules target event type and value — not source-specific field names. You can test rules in the sandbox against real historical data before applying them to live ingest.
What is OCSF? — how the schema makes filtering safeReducing costs mid-migration — dual-write explainedDerwent Labs vs Cribl — cost comparison
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF. Stop maintaining parsers. Stop rewriting detections. Start shipping signal.