Streaming detections. Open storage. One query language.
Netgraph's SIEM core ingests any source through a back-pressure-safe streaming bus, normalises to an OCSF/ECS-conformant open schema with the raw event preserved, and correlates in-stream — so Tier-1 detections fire in under a minute, and everything lands on the same security knowledge graph the rest of the platform reads.
What is a NextGen SIEM?
A NextGen SIEM (Security Information and Event Management) platform ingests telemetry from across your infrastructure — endpoints, network, cloud, identity, applications — normalises it to an open schema, and runs streaming detections against it in real time, rather than batch-searching an index the way legacy SIEMs do. AutoCops Netgraph goes one step further: every event, alert, asset, identity, and CVE lands on a single security knowledge graph, so correlation, hunting, and response are graph traversals instead of dashboard stitching. Built and operated entirely in India, deployable self-hosted or fully air-gapped.
What ships in the module
Every SIEM function, wired to the graph.
Detection engineering, closed loop
Write once in NQL. Validate, backtest, deploy — everywhere.
The Detection Workbench compiles a rule, backtests it against live history, and shows precision before anything goes live. Imported community rules, agent-drafted rules and hand-written rules all flow through the same pipeline — and the NQL correlator evaluates them continuously in-stream.
- Compile & backtest via NQL before deploy — see matches, not hope.
- Rule Registry lists every rule — catalog, imported, and custom — with per-rule state.
- Monitor / tuning mode lets new content run silent before it pages anyone.
- Detection CI fails the pipeline when attack-simulation coverage regresses.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Ingest & Process | Connector fabric, ingest health, parse & normalize, enrichment (geo · asset · identity · intel) | SOC ▸ Ingest & Process |
| SIEM Rules | Sigma catalog management — enable / disable / monitor / edit via tenant-owned deployed copies | SOC ▸ Detect ▸ SIEM Rules |
| Detection Workbench | Author, compile, backtest and A/B detections in NQL | SOC ▸ Detect ▸ Workbench |
| Rule Registry | Every rule — catalog + 1,100+ imported + custom — searchable with per-rule config | SOC ▸ Detect ▸ Detections |
| Alerts & Take-Action | Central alert queue with enrich / TIP / runbook / case / suppress / mark-FP actions | SOC ▸ Detect ▸ Alerts |
| Suppression & aggregation | Ingest-time suppression + per-(rule, window) aggregation with unique-host tracking | Worker correlator + rule config |
| Retro replay | Auto-replay of new/changed rules across hot, warm and cold history | Detection Flywheel |
| Data Search / Discover | NQL interactive search across every tier, with on-type validation | Visibility ▸ Data Search |
Common questions
NextGen SIEM — asked and answered
What makes Netgraph different from a traditional SIEM like Splunk or QRadar?+
Three things: architecture, cost, and sovereignty. Netgraph is graph-native — detections, entities, and findings share one typed knowledge graph instead of separate index domains. Ingest runs at roughly 15% of Splunk/QRadar cost at equivalent retention because hot, warm, and cold tiers use open columnar formats. And it is exclusively Made in India: India-resident code, infrastructure, and operations, with CERT-In 6-hour and DPDP 72-hour statutory clocks built in, not bolted on.
Is Netgraph a Make in India SIEM?+
Yes. Netgraph is designed, engineered, and operated end-to-end inside India — no offshored core, no foreign-controlled data plane, no telemetry leaving the country. It is available on GeM for government and PSU procurement and supports fully air-gapped deployment for defence and critical-infrastructure environments.
What is MTTD and MTTR on Netgraph?+
Tier-1 streaming detections achieve a mean time to detect (MTTD) of 60 seconds or less; automated playbooks across the graph achieve a mean time to respond (MTTR) of 15 minutes or less.
Can Netgraph replace my SIEM, SOAR, UEBA, and TIP together?+
That is the design goal: 23 modules — SIEM, SOAR with case management, UEBA, threat intelligence, EDR, NDR, CTEM, BAS, and more — ship as one product on one graph, so most teams consolidate multiple point tools into a single deployment.
See it live
Point your noisiest source at it. Watch the graph light up.
Works with everything on the graph
Agentic AI SOC
The L1 autopilot triages every alert the SIEM raises — autonomously, near-real-time, on every tenant.
Explore→Threat Hunting & NQL
The same NQL that powers detections drives hypothesis-driven hunts, notebooks and scheduled hunt jobs.
Explore→Attack Simulation
BAS scenarios validate SIEM coverage against real telemetry read-back — gaps feed the detection flywheel.
Explore→