The detection engine: correlation rules on the event stream you already forward, outside the SIEM. Sequences across hosts in log time, state that survives a crash. Rust, no JVM, embeddable.
rust kafka cep pattern-matching stream-processing complex-event-processing event-processing streaming-engine fraud-detection streaming-analytics mitre-attack threat-detection real-time-detection correlation-rules detection-engineering sigma-rules detection-as-code soc-automation flink-alternative siem-alternative
-
Updated
Sep 29, 2026 - Rust