SIEM and search

Every event, one store, every one kept.

One pipeline normalises, one store keeps it all. Every event keeps its original document next to the parsed fields, and anything that fails to parse is kept and flagged.

A capture of the XenXDR console running on demo data.

Ingest

Send it however it already leaves the device.

The SIEM works with any source. If it can emit syslog, JSON or a Splunk HEC payload, it can land in XenXDR.

Beats over TLS

Your own winlogbeat and filebeat fleet, pointed at the ingest endpoint.

Syslog, CEF, LEEF

Firewalls, appliances and Linux hosts over TLS, with plain UDP and TCP available on trusted segments.

HTTP JSON

Anything scriptable: post an object or an array with a per-organization ingest key and it is stamped to the right tenant.

Splunk HEC

Products that already speak HEC point at XenXDR without a rewrite.

Normalisation

One canonical name per field.

Fields follow a dotted, ECS-compatible naming scheme with a published dictionary. Every field has one name, one type and one description, and the query bar knows all of them.

  • The raw event is stored alongside the parsed fields, so evidence stays intact for audits.
  • Events that fail to parse are kept in an unparsed queue with its own retention.
  • IPs, hashes, users and domains are extracted as entities for cross-source pivots.
  • Per-organization ingest keys stamp tenancy server-side, so every event lands in the right tenant.

Search

Discover, the way analysts already work.

A query bar with dictionary autocomplete, a histogram, a field rail with top values, and expandable documents. Every filter is one click from a value, and every alert is one click from its evidence.

Search tabs and saved views

Keep several investigations open. Views are saved privately on the analyst's machine, so shared links keep your filters to yourself.

Find in results

Search inside the current result set without re-running the query.

Process tree and activity graph

From any process event, unfold the parent chain and what the process did next.

AI Hunt

Ask in plain language. The hunt runs bounded, read-only queries and shows you exactly what it ran.

A capture of the XenXDR console running on demo data.

Retention

Defaults you can change.

Retention is a setting, not a pricing tier. The defaults below ship with the platform; the docs explain how to change them per deployment.

DataDefault retention
Events90 days
Unparsed events14 days
Analyst audit trail365 days

See XenXDR on your own telemetry.

A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.