Skip to content

Helix SIEM

Security analytics platform

Helix SIEM brings the logs of operating systems, network equipment, security tools, clouds, applications and databases into one loop, reduces them to a single data model and builds search, correlation, incidents and reporting on top.

A SIEM Does Not Replace Your Security Tools

Every security tool sees only its own event: antivirus sees a file, the firewall a connection, the WAF a request. None of them knows what the others saw. An attack passes exactly between them.

A SIEM does not take their place — it builds one layer of observability, detection and record-keeping above them. A single query works across every source, because events are reduced to one model: a field of the same name means the same thing whatever the vendor.

So search, correlation rules, dashboards and reports are not tied to a source type. Adding a new vendor does not mean rewriting the rules.

An event's path through the platform
StageWhat happens
IngestSource verified, buffered to disk, duplicates and losses accounted for
ProcessingParsing, normalisation to the single model, categorisation, enrichment with context
DetectionCorrelation rules, behavioural profiles, alerts raised
PresentationIncidents, dashboards, reports and forwarding to external systems
Platform capabilities

What It Is Made Of

Data collection

  • 13 ingest methods: Syslog (UDP/TCP/TLS), agent, REST API, WMI, SNMP, files, databases, queues, clouds, NetFlow
  • 600+ source types with ready parsing rules in the base distribution
  • Agent and agentless: a network method wherever an agent cannot be installed
  • Your own decoder is written as configuration — without touching product code

Storage: Three Tiers And Retention Profiles

An event moves between tiers by age, by tier volume or by space used. Retention is set per source class; events that entered an incident follow their own policy.

Typical retention profiles
ProfileHotWarmCold-archive
Short · 30 days7 days23 days
Base · 90 days14 days76 daysper policy
Extended · 180 days30 days150 daysup to 365 days
Annual · 365 days30 days180 days185 days
Long · 1825 days30 days180 days1615 days

The profiles are example configurations. Typical compression on text logs is 6–12×.

Where It Runs

Functionality is identical across all four options — only image delivery and the scaling mechanism differ.

Deployment options
OptionDeliveryScaling
PhysicalRPM / DEB packages, ISO imageAdding nodes and disk shelves
VirtualisationOVA / QCOW2 / VHDX imagesChanging VM resources, cloning
Private and public cloudVM images, IaC templatesScaling groups, object storage
Containers and hybridOCI images, Helm chartsChanging replica counts, StatefulSet

For multi-site infrastructure a central-node / remote-site scheme applies: a Helix Collector at the site receives events locally, buffers them for 1–72 hours and forwards to the centre over TLS 1.2/1.3.

Questions

Frequently Asked Questions

No. A SIEM is not a security control but a layer of observability and record-keeping above them. The controls do their job; the SIEM brings their events together, relates them and forms an incident.

The base distribution carries ready parsing rules for 600+ source types. For anything outside that list a decoder is written as configuration — product code is not changed and components are not rebuilt.

No. The agent is used on endpoints where it is needed; network equipment, security tools and cloud services are collected agentlessly — over Syslog, REST API, WMI, SNMP or the provider's API.

The source record is stored unmodified, a checksum is computed for each record and included in a block hash chain. Tampering or deletion is caught by scheduled background verification, and an integrity report can be produced for a period.

That depends on your event volume and retention period. Typical compression on text logs is 6–12×, and storage is split across three tiers — the expensive NVMe is only needed for hot. An exact figure follows once your stream has been measured.

Let's Measure Your Stream And Size The Configuration

We establish which sources, what volume and what retention you need — then give a precise proposal for components and storage.

Let’s start
Request a consultation
Request a consultation