Unified Ingestion Lakehouse
Real-time log database tracking security telemetry streams, operating systems, network events, and hardware inventories.
Operational Data Marts
Stores raw syslogs, emails, chat logs, images, and unparsed system events.
Active Directory, Kerberos authentications, and PowerShell audits.
SSH logons, systemd processes, and daemon events.
Mainframe transaction journals and RACF access logs.
Network transit packets, firewall rules, and port states.
SailPoint IGA, role access changes, and SSO events.
Device types, CPU layout, RAM metrics, and MAC addresses.
Installed agent binary versions and local dependency paths.
Unstructured & Raw Logs
Table: clickhouse.unstructured_raw| timestamp | source_ip | data_type | raw_content |
|---|---|---|---|
| 11:33:02 | 10.100.12.45 | Subject: Security Alert Alert - phishing reported on node 'BOS-01' | |
| 11:33:10 | 10.100.14.78 | CHAT | Slack: #incident-response: vm containment executed by orchestrator |
| 11:33:12 | 10.200.4.5 | RAW_SYSLOG | OS390: syslog: RACF access granted to admin key |
| 11:33:20 | 10.100.12.45 | IMAGE | Asset capture: bios_motherboard_revision_b.jpg (SHA256: 8fa12c9b...) |
Database Fields Schema
Stores raw syslogs, emails, chat logs, images, and unparsed system events.
Ingestion time
Origin host IP
Type of unstructured payload
Unstructured message, conversation text, or image metadata