Skip to content
§ FAQ

Frequently asked questions.

Everything you need to know about LogSeam, from getting started to enterprise deployment.

General

What is LogSeam? +

LogSeam is the agentic SOC platform. An open security data lake, the Lake, stores all your security logs as open Parquet in your own bucket, and the platform on top runs your entire SOC: detection-as-code, AI agents that triage and investigate every alert, structured incident response, and real-time dashboards. One system, from raw logs to closed cases.

Who is LogSeam built for? +

LogSeam is built for security teams of all sizes, from lean two-person SOCs to enterprise security operations centers. If you're drowning in SIEM costs, struggling with alert fatigue, or running incident response on spreadsheets and Slack, LogSeam was built for you.

How long does it take to get started? +

Most teams are ingesting data within hours. Connect your first source, and you'll see logs flowing into the lake immediately. Detection rules can be deployed the same day. A broader rollout typically takes one to two weeks: tuning rules, building dashboards, and training your team.

Can I use the Lake without the rest of the platform? +

Yes. The Lake works as standalone security data storage: open Parquet in your bucket, queryable with your own tools. You can adopt detection, triage, and the agent fleet whenever you're ready. The platform requires the Lake as its data backend; the Lake doesn't require the platform.

The Lake

What data sources does LogSeam support? +

LogSeam supports 100+ integrations across SIEMs (Splunk, Sentinel, QRadar), EDR (CrowdStrike, SentinelOne, Carbon Black), identity (Okta, Azure AD, Duo), cloud (AWS, Azure, GCP), firewalls, DNS, email gateways, and more.

What log formats does LogSeam accept? +

Common formats include JSON, Syslog, CEF, LEEF, CSV, and custom formats. The ingestion pipeline automatically detects and parses most standard formats.

How does pricing compare to traditional SIEMs? +

LogSeam charges one thing: per compute node. Storage, compute, and AI are pass-through at cost. Your data lives as open Parquet in object storage instead of a hot cluster, which is what collapses the bill. You keep all your data: no more choosing which logs to drop because of budget constraints. The pricing page publishes the full rate card and assumptions.

What does "open format" mean for my data? +

Your data is stored on your own object storage in an open, queryable format. If you ever leave LogSeam, your data stays with you in a format standard tools can read. No vendor lock-in and no export fees.

How does the AI enrichment work? +

Log events can be enriched during ingestion with threat intelligence, geolocation, ASN data, and entity classification. The AI layer adds behavioral context: identifying anomalous patterns, correlating events across sources, and tagging entities for investigation.

Detection & response

What is Detection-as-Code? +

Detection-as-Code means your detection rules are written in Sigma/YAML, the open vendor-agnostic standard, not locked in a proprietary format. You can version control them, test them against real data before deploying, and share them across teams. LogSeam supports five rule types: Sigma, behavioral, statistical, graph analysis, and ML/AI.

How does AI-powered alert triage work? +

When a detection rule fires, AI pre-assesses the alert with a verdict (benign, suspicious, or malicious), a confidence score, risk assessment, and extracted IOCs. It can enrich indicators against sources like VirusTotal, AbuseIPDB, IPinfo, and URLScan, all in parallel, so analysts start with context instead of a blank alert.

Can I customize detection rules? +

Absolutely. Author rules in Sigma/YAML or write SQL directly. The editor shows a live SQL preview of your Sigma rule so you see exactly what will execute. Classify by MITRE ATT&CK, set severity, and add metadata. Test rules against real data before promoting them to production, with quality gates for precision and false-positive targets.

What kind of reports does LogSeam generate? +

Five report types, all AI-assisted: executive reports for your CISO and board, compliance reports mapped to SOC 2/ISO 27001/HIPAA, incident reports with full timelines and IOC inventories, technical reports with rule performance and ATT&CK coverage, and custom reports that mix sections from any type.

How does the investigation workspace (Spaces) work? +

Spaces are infinite, zoomable investigation canvases. Drag widgets onto the canvas: search results, timelines, MITRE ATT&CK matrix, entity cards, enrichment data, and correlation maps. An AI copilot sees your entire canvas, suggests next queries, enriches IOCs, and generates investigation findings. Multiple analysts collaborate in real time with live cursor tracking.

Integrations & Data

How does LogSeam integrate with my existing SIEM? +

Start alongside your SIEM; replace it on your timeline. Export your SIEM logs to object storage (S3, Azure Blob, GCS) and LogSeam ingests them automatically, with pre-built connectors for Splunk, Sentinel, and QRadar to make setup straightforward. As detection coverage moves into the lake, most teams retire their per-GB tiers rather than renew them.

How do AI agents integrate with LogSeam? +

LogSeam includes an MCP (Model Context Protocol) server for AI agent integration. The MCP server lets AI agents like Claude, Cursor, and custom tools query your security data directly.

How long is data retained? +

As long as you need it. Because LogSeam uses object storage, retention is limited by your storage policy and budget, not by hot compute costs. Many teams use this model to retain years of full-fidelity data at a lower cost than keeping short hot-retention windows in a traditional SIEM.

Security & Compliance

Is my data secure with LogSeam? +

Yes. AES-256 encryption at rest and TLS 1.3 in transit. Role-based access control with SSO/SAML support. Full audit trails for every action. Your data lives in your own object storage. LogSeam processes it but never takes custody of it.

What compliance frameworks does LogSeam support? +

LogSeam generates compliance reports mapped to SOC 2, ISO 27001, and HIPAA. Detection coverage is mapped to MITRE ATT&CK tactics and techniques. The platform captures analyst action audit trails for compliance evidence, reducing the manual prep needed for recurring reports.

Deployment & Support

What deployment options are available? +

Three options: LogSeam Managed (we run it in our cloud), Your Cloud (compute and storage in your own AWS, Azure, or GCP account), or On-Premises for strict data-residency requirements. Same platform, same feature set, in all three.

What support is available? +

Core Support includes 8x5 response, software updates, email or chat support, and standard triage. Critical Support includes 24x7 response, software updates, priority communication, and incident bridge support.

Can I try LogSeam before committing? +

Yes. Contact us for a guided demo, or request a proof-of-concept deployment on your own data. We'll help you connect a data source and see results before you make any commitment.

Still have questions?

We'll answer them, usually the same business day.

See the platform