It's a pretty complex diagram:
https://github.com/matanolabs/matano/blob/main/website/src/a...
It's a pretty complex diagram:
https://github.com/matanolabs/matano/blob/main/website/src/a...
I see the term zero-ops. But maintaining and debugging this pipeline is going to require some ops, even if you are not managing VMs.
The serverless data ingestion pipeline means you don't need to over-provision for ingestion (Logstash and Splunk Forwarders are notorious for related costs / ops in high scale use-cases) in the write path. For reads, since Matano queries Iceberg tables backed by highly-compressed parquet files on object storage you won't pay anything close to what you would for a database or search engine based SIEM.
Where do you show an example of querying anything? There's an empty "detector" in the examples directory, which I guess gets called once per row of this 20MiB/s alleged elsewhere?
Anyway, I find comparing this to Splunk to be a bit premature
This means as a dev you don’t need to maintain a server, or even container image, you just deploy the code, which is less maintenance overhead and more scalable.
The diagram just shows how it interacts with the other components of the log pipeline.