Every source, one question away.
7AI Federated SIEM connects your security sources, including the SIEM you already run, and lets you search across all of them in plain language, normalized to a common schema. Keep your data wherever it makes sense, ask one question, get answers from every source at once, and turn any search into a detection.
However you want to work
You decide where your data lives.
A federated approach does not mean ripping anything out. Keep your SIEM and connect it as a source. Keep it, and move some logs into cheaper hot storage. Or run fully federated with no central index at all. 7AI works across every source either way, so you choose how much to centralize and how much to reach where it already lives.
01 / Detections on All of It
Detections that span your whole estate.
Detection rules run across the normalized data from every source, mapped to MITRE ATT&CK, so one rule can reason over identity, endpoint, and cloud signals together. Draft a new rule from a federated search in a click.
- Rules across every connected source, not one tool.
- Mapped to MITRE ATT&CK coverage.
- Draft a rule straight from a federated search.
| Source & Rule | Type | MITRE ATT&CK | Recent Detections |
|---|---|---|---|
| DefUser Reported Phishing | Custom | T1566 PhishingT1566.001 Spearphishing Attachment | 798 |
| SplHigh Risk Okta Login | Custom | T1078 Valid AccountsT1110 Brute Force | 1,170 |
| 7AIPassword Spray | Custom | T1110 Brute ForceT1110.003 Password Spraying | 1,000 |
| CSSoftware Vulnerability Detected | Custom | T1190 Exploit Public-Facing AppT1068 Privilege Escalation | 402 |
| S1Unusual Network Traffic | Custom | T1071 Application Layer ProtocolT1048 Exfiltration Alt Protocol | 324 |
| 7AIImpossible Travel | Custom | T1078 Valid AccountsT1078.004 Cloud Accounts | 348 |
02 / Your Logs, Your Way
Keep what you want, where you want.
Bring in the sources you want 7AI to retain, identity, endpoint, cloud, and network, and it ingests, normalizes, and keeps them in hot storage, always searchable. Leave the rest where it lives and reach it through federated search. Health and volume for every source at a glance.
- Retain logs in 7AI, your existing SIEM, or both.
- Hot storage that stays searchable, not cold archive.
- Health and volume monitoring for every source.
| Source Name | Status | Last Received | Volume |
|---|---|---|---|
| OkOkta | ACTIVE | Just Now | 4.5 GB |
| CSCrowdStrike | ACTIVE | Just Now | 18.0 GB |
| MSMicrosoft Sentinel | ACTIVE | Just Now | 120.0 GB |
| AWSAWS CloudTrail | ACTIVE | Yesterday | 7.0 GB |
| DefMicrosoft Defender | ACTIVE | 2 Days Ago | 14.0 GB |
| WizWiz | ACTIVE | 4 Days Ago | 2.0 GB |
03 / Search Across Everything
Ask once. Answer from every source.
Federated Search runs a single natural-language question across all your connected sources at once and returns results normalized to a common schema, so an Okta sign-in and a CrowdStrike detection line up side by side. Export the results, or turn the search straight into a detection rule.
- Natural-language search across every connected source.
- Results normalized to OCSF, not source-specific formats.
- Export to CSV, or draft a detection from any search.
| Time | Source | OCSF class | Principal | Detail |
|---|---|---|---|---|
| 22:13:51Z | OkOkta | authentication | w.bryant@okami-ai.com | INVALID_CREDENTIALS · 185.220.101.45 |
| 22:12:47Z | OkOkta | authentication | s.thompson@okami-ai.com | INVALID_CREDENTIALS · 185.220.101.45 |
| 22:11:34Z | OkOkta | authentication | mikael.eriksson@okami-ai.com | PASSWORD_RESET_REQUIRED · 185.220.101.45 |
| 22:09:13Z | OkOkta | authentication | j.harrington@okami-ai.com | INVALID_CREDENTIALS · 185.220.101.45 |
| Apr 5 14:23:11Z | CSCrowdStrike Falcon | detection_finding | NBK-MERIK-01 | LummaC2 · T1555.003 Credentials from Web Browsers · high |
Questions
Federated SIEM, answered.
A security data platform that connects your existing sources, including your current SIEM, and lets you search across all of them in plain language, normalized to a common schema, then run detections on top. You choose how much to centralize.
No. Federated means you work however suits you. Keep your SIEM and connect it as a source. Keep it and move some logs into cheaper hot storage. Or run fully federated with no central SIEM at all. 7AI searches across all of them, so the choice stays yours.
No. You ask in plain language and 7AI builds and runs the query across your sources, then returns normalized results you can export or turn into a detection.
Results from different sources are mapped to a shared model based on OCSF, so an Okta authentication and a CrowdStrike detection share the same fields and line up in one view.
Federated SIEM is the data foundation the rest of the platform runs on. The same normalized data powers detection, investigation, response, and hunting.
Yes. 7AI Federated SIEM is generally available. Connect your sources, including the SIEM you already run, and search across all of them right away.
Take the full tour
See Federated SIEM on your sources.
We will walk you through federated search, log management, and detections across your own sources, including the SIEM you already run.