Detection & Response
Live Tail
Watch every log and detection stream in real time.
Available as a standalone module · Add to my package12Open incidents
41,208Events / sec
27Auto-contained
- Real-time WebSocket streamActive
- Filter by source, host and severityActive
- Matched SIGMA, YARA and IOC hits inlineActive
- Pause, inspect and pivotActive
What it does
A live, filterable stream of normalised events and rule matches from every source, delivered over WebSocket with no page refresh.
Real-time WebSocket stream
Filter by source, host and severity
Matched SIGMA, YARA and IOC hits inline
Pause, inspect and pivot
Live demo
Runs in your browser on sample data. Click around, nothing here touches a real system.
0
Events/sec
0
Total Today
6
Sources
0
Alerts
Agents
Firewall
Syslog
DNS
IDS/IPS
Kafka
| Time | Source | Severity | Message | IP |
|---|
How it worksin three steps.
Collect
Events from agents, syslog and connectors are normalised into one schema.
Detect
SIGMA, YARA and IOC matches run in real time and are correlated into incidents.
Respond
Contain the threat from the console, with approval for high-impact actions.
Works best withthese modules.
See all 30 modules
Endpoint Security
Agents
Signed lightweight agents for Windows, Linux and macOS.
Learn more Threat IntelligenceThreat Intelligence Feeds
IOC feeds matched against every event.
Learn more Automation & AISOC Automation
Visual flows from detection to response.
Learn moreAlso in Detection & Response
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.