← All Netgraph solutions
NextGen SIEMDetect & Respond

Streaming detections. Open storage. One query language.

Netgraph's SIEM core ingests any source through a back-pressure-safe streaming bus, normalises to an OCSF/ECS-conformant open schema with the raw event preserved, and correlates in-stream, so Tier-1 detections fire in under a minute, and everything lands on the same security knowledge graph the rest of the platform reads.

≤ 60s streaming MTTDOCSF / ECS normalisedNQL everywhere1,100+ curated detectionsOpen columnar storage

What is a NextGen SIEM?

A NextGen SIEM (Security Information and Event Management) platform ingests telemetry from across your infrastructure, endpoints, network, cloud, identity, applications, normalises it to an open schema, and runs streaming detections against it in real time, rather than batch-searching an index the way legacy SIEMs do. AutoCops Netgraph goes one step further: every event, alert, asset, identity, and CVE lands on a single security knowledge graph, so correlation, hunting, and response are graph traversals instead of dashboard stitching. Built and operated entirely in India, deployable self-hosted or fully air-gapped.

What ships in the module

Every SIEM function, wired to the graph.

01

Streaming ingest

Agents, syslog, cloud control planes, APIs and 70+ ready connectors feed a back-pressure-safe bus. Ingest health, parse & normalize, and per-source value dashboards keep the pipeline observable.

02

Open-schema normalization

Every event is normalised to OCSF/ECS-conformant fields with the raw JSON preserved, no lossy proprietary schema, no vendor lock-in on your own telemetry.

03

NQL: native query language

One platform-native query language across Discover, Data Search, detections and dashboards, auto-synthesized from natural language, auto-validated as you type, and federated to external SIEM dialects (KQL / SPL / AQL) where integrations are enabled.

04

Detection-as-Code

Rules are versioned, compiled and backtested through the same pipeline whether a human or an agent authored them, with CI gates, A/B comparison and automatic regression against history.

05

Curated rule content

1,100+ community detections imported and converted to NQL with MITRE ATT&CK and D3FEND mappings, shipped in monitor/tuning mode, plus the full Sigma catalog managed from the SIEM Rules console (enable, disable, monitor, edit as tenant-owned copies).

06

Aggregation & suppression

Noisy detections aggregate per rule and window with unique-host tracking; true ingest-time suppression drops known-benign patterns before they become alerts. Per-rule enable / threshold / suppress config survives upgrades.

07

Retrospective replay

Every new or changed detection automatically replays against 90-day hot/warm history and the 7-year cold archive, so a rule shipped today tells you if the technique fired last quarter.

08

Tiered open storage

Hot interactive columnar tier, warm archive, cold object storage, federated by one query layer, with configurable retention, compression and full/incremental backup per tier. Target: a fraction of legacy per-GB ingest cost.

09

Central alerting

All detection planes, SIEM, EDR, NDR, cloud, UEBA, write to one central alerts table with source attribution, feeding the L1 autopilot, case management and the Take-Action menu (enrich, TIP, runbook, add-to-case, suppress, mark-FP).

Detection engineering, closed loop

Write once in NQL. Validate, backtest, deploy: everywhere.

The Detection Workbench compiles a rule, backtests it against live history, and shows precision before anything goes live. Imported community rules, agent-drafted rules and hand-written rules all flow through the same pipeline, and the NQL correlator evaluates them continuously in-stream.

  • Compile & backtest via NQL before deploy, see matches, not hope.
  • Rule Registry lists every rule, catalog, imported, and custom, with per-rule state.
  • Monitor / tuning mode lets new content run silent before it pages anyone.
  • Detection CI fails the pipeline when attack-simulation coverage regresses.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Ingest & ProcessConnector fabric, ingest health, parse & normalize, enrichment (geo · asset · identity · intel)SOC ▸ Ingest & Process
SIEM RulesSigma catalog management, enable / disable / monitor / edit via tenant-owned deployed copiesSOC ▸ Detect ▸ SIEM Rules
Detection WorkbenchAuthor, compile, backtest and A/B detections in NQLSOC ▸ Detect ▸ Workbench
Rule RegistryEvery rule, catalog + 1,100+ imported + custom, searchable with per-rule configSOC ▸ Detect ▸ Detections
Alerts & Take-ActionCentral alert queue with enrich / TIP / runbook / case / suppress / mark-FP actionsSOC ▸ Detect ▸ Alerts
Suppression & aggregationIngest-time suppression + per-(rule, window) aggregation with unique-host trackingWorker correlator + rule config
Retro replayAuto-replay of new/changed rules across hot, warm and cold historyDetection Flywheel
Data Search / DiscoverNQL interactive search across every tier, with on-type validationVisibility ▸ Data Search

Common questions

NextGen SIEM, asked and answered

What makes Netgraph different from a traditional SIEM like Splunk or QRadar?+

Three things: architecture, cost, and sovereignty. Netgraph is graph-native, detections, entities, and findings share one typed knowledge graph instead of separate index domains. Ingest runs at roughly 15% of Splunk/QRadar cost at equivalent retention because hot, warm, and cold tiers use open columnar formats. And it is exclusively Made in India: India-resident code, infrastructure, and operations, with CERT-In 6-hour and DPDP 72-hour statutory clocks built in, not bolted on.

Is Netgraph a Make in India SIEM?+

Yes. Netgraph is designed, engineered, and operated end-to-end inside India, no offshored core, no foreign-controlled data plane, no telemetry leaving the country. It is available on GeM for government and PSU procurement and supports fully air-gapped deployment for defence and critical-infrastructure environments.

What is MTTD and MTTR on Netgraph?+

Tier-1 streaming detections achieve a mean time to detect (MTTD) of 60 seconds or less; automated playbooks across the graph achieve a mean time to respond (MTTR) of 15 minutes or less.

Can Netgraph replace my SIEM, SOAR, UEBA, and TIP together?+

That is the design goal: 23 modules, SIEM, SOAR with case management, UEBA, threat intelligence, EDR, NDR, CTEM, BAS, and more, ship as one product on one graph, so most teams consolidate multiple point tools into a single deployment.

See it live

Point your noisiest source at it. Watch the graph light up.