Most SIEMs look up context after something fires, when IPs have been reassigned and the trail has gone cold. Aleph enriches every signal the moment it arrives, so detections, investigations, and AI work with the full picture.
See enrichment in actionSIEM enrichment is the process of adding context to raw security events: who the user is, what the asset does, whether the IP is known-bad, where the connection came from. An enriched event answers those questions on its own. A raw event only raises them.
The SIEM stores raw events. When an alert fires, an analyst or an automation looks up context in other tools. Every investigation repeats the same lookups, and the answers describe now, not the moment the event happened.
The pipeline parses and enriches events in stream, before they are stored. Context is captured while it is still true and becomes part of the event itself. Detections, searches, and AI all inherit it for free.
Ever pivoted through four consoles to answer "is this IP even ours?" That lookup tax is the query-time model at work, and it costs more than time.
Cloud IPs get reassigned in minutes. Users change teams. Containers live for an hour. A lookup done during the investigation describes today's environment, not the one where the event happened.
The same user, asset, and intel lookups get repeated in every investigation, by every analyst, for every alert. None of that work makes the next alert any faster.
A rule that only sees a raw event can't tell an admin's expected login from an attacker's. That gap is where false positives come from, and where real attacks hide.
1
Events stream in from your stack and are parsed into a clean, consistent schema at the edge.
2
Aleph joins each event with identity, asset, threat intelligence, and business context in real time.
3
Events land in your data lake with their context attached, searchable and ready for investigation.
4
Detection rules and AI investigation run on enriched events, with the full picture from the first millisecond.
1M+
Events enriched every second
<1s
From event to detection
95%
Fewer false positives with full context
80%
Lower total SIEM cost versus legacy platforms
Who is behind the event: the user, their role, their team, and whether the login fits how they normally work.
What the machine is: owner, environment, criticality, and exposure, pulled from your asset inventory.
Whether the indicator is known-bad, which campaigns it belongs to, and who else has seen it.
Where the connection came from, what network it crossed, and whether that path makes sense.
What this user or asset did before, so a single event becomes part of a pattern instead of a data point.
Correlation links events to each other. Enrichment adds outside context to each individual event. They work best together: correlation rules running on enriched events can match on user, asset, and intel fields that raw logs simply don't have.
Enriched fields add little on top of compressed raw events, and the economics favor it: storage is cheap, analyst time is not. Aleph customers see around 80% lower total SIEM cost than legacy platforms, because enrichment happens once in the pipeline instead of over and over in investigations.
Yes. Aleph keeps a full backup of your raw events and can re-stream them through the pipeline, so historical data can be enriched, re-parsed, or replayed against new detections at any time.
Your identity provider, asset inventory, cloud platforms, threat intelligence feeds, and the rest of your connected stack. Aleph ships with integrations for the common sources and lets you add your own business context.
Bring one noisy log source. We'll show you what it looks like when every event arrives with context attached.
Book a demo