Use case · Log processing & SIEM

Watch 100 GB of logs
become 15 GB of signal.

Reduce ingestion cost. Eliminate duplicate and low-value logs. Keep every event your detection rules actually need.

No SIEM replacement. No new agents. No rule rewrites.

SCROLL TO SEE IT HAPPEN↓
YOUR FLEET2,340 nodes
plant-0100
pos-0153
edge-0206
kiosk-0259
hub-0312
store-0365
depot-0418
cam-0471
plant-0524
pos-0577
edge-0630
kiosk-0683
hub-0736
store-0789
depot-0842
cam-0895
plant-0948
pos-0101
edge-0154
kiosk-0207
hub-0260
store-0313
depot-0366
cam-0419
plant-0472
pos-0525
edge-0578
kiosk-0631
hub-0684
store-0737
depot-0790
cam-0843
plant-0896
pos-0949
edge-0102
kiosk-0155
hub-0208
store-0261
depot-0314
cam-0367
plant-0420
pos-0473
edge-0526
kiosk-0579
hub-0632
store-0685
depot-0738
cam-0791
plant-0844
pos-0897
edge-0950
kiosk-0103
hub-0156
store-0209
depot-0262
cam-0315
plant-0368
pos-0421
edge-0474
kiosk-0527
hub-0580
store-0633
depot-0686
cam-0739
plant-0792
pos-0845
edge-0898
kiosk-0951
hub-0104
store-0157
depot-0210
plant-0316
pos-0369
edge-0422
kiosk-0475
hub-0528
store-0581
depot-0634
cam-0687
plant-0740
pos-0793
edge-0846
kiosk-0899
hub-0952
store-0105
depot-0158
cam-0211
plant-0264
pos-0317
edge-0370
kiosk-0423
hub-0476
store-0529
depot-0582
cam-0635
plant-0688
pos-0741
edge-0794
kiosk-0847
hub-0900
store-0953
depot-0106
cam-0159
plant-0212
pos-0265
edge-0318
kiosk-0371
hub-0424
store-0477
depot-0530
cam-0583
plant-0636
pos-0689
edge-0742
kiosk-0795
hub-0848
store-0901
depot-0954
cam-0107
plant-0160
pos-0213
edge-0266
kiosk-0319
hub-0372
store-0425
depot-0478
cam-0531
plant-0584
pos-0637
edge-0690
kiosk-0743
hub-0796
store-0849
depot-0902
cam-0955
plant-0108
pos-0161
edge-0214
kiosk-0267
hub-0320
store-0373
depot-0426
store-0417100 GB/day
14:02:11.031 DEBUG http ok path=/health status=200 dur=2ms
14:02:11.204 ERROR payment declined order=88213 card=4242 4242 4242 4242
14:02:11.911 DEBUG cache miss key=session:a91f4c
14:02:12.130 INFO request done path=/checkout status=200 dur=182ms
14:02:12.311 INFO login ok user=[email protected] src=pos-3
14:02:12.482 DEBUG gc pause 3ms heap=412mb
14:02:12.907 INFO request done path=/cart status=200 dur=96ms
14:02:13.245 DEBUG http ok path=/metrics status=200 dur=1ms
14:02:13.771 ERROR upstream timeout host=pos-7 key=sk_test_9f3aa21c retry=1
14:02:14.008 INFO request done path=/checkout status=200 dur=241ms
14:02:14.223 DEBUG heartbeat ok node=store-0417
14:02:14.356 WARN queue depth rising depth=1204 max=2000
14:02:14.471 DEBUG http ok path=/health status=200 dur=2ms
14:02:14.644 ERROR payment declined order=88213 card=4242 4242 4242 4242
14:02:15.351 DEBUG cache miss key=session:a91f4c
14:02:15.570 INFO request done path=/checkout status=200 dur=182ms
14:02:15.751 INFO login ok user=[email protected] src=pos-3
14:02:15.922 DEBUG gc pause 3ms heap=412mb
14:02:16.347 INFO request done path=/cart status=200 dur=96ms
14:02:16.685 DEBUG http ok path=/metrics status=200 dur=1ms
14:02:17.211 ERROR upstream timeout host=pos-7 key=sk_test_9f3aa21c retry=1
14:02:17.448 INFO request done path=/checkout status=200 dur=241ms
14:02:17.663 DEBUG heartbeat ok node=store-0417
14:02:17.796 WARN queue depth rising depth=1204 max=2000
14:02:17.911 DEBUG http ok path=/health status=200 dur=2ms
14:02:18.084 ERROR payment declined order=88213 card=4242 4242 4242 4242
14:02:18.791 DEBUG cache miss key=session:a91f4c
14:02:19.010 INFO request done path=/checkout status=200 dur=182ms
14:02:19.191 INFO login ok user=[email protected] src=pos-3
14:02:19.362 DEBUG gc pause 3ms heap=412mb
14:02:19.787 INFO request done path=/cart status=200 dur=96ms
14:02:20.125 DEBUG http ok path=/metrics status=200 dur=1ms
14:02:20.651 ERROR upstream timeout host=pos-7 key=sk_test_9f3aa21c retry=1
14:02:20.888 INFO request done path=/checkout status=200 dur=241ms
14:02:21.103 DEBUG heartbeat ok node=store-0417
14:02:21.236 WARN queue depth rising depth=1204 max=2000
14:02:21.351 DEBUG http ok path=/health status=200 dur=2ms
14:02:21.524 ERROR payment declined order=88213 card=4242 4242 4242 4242
14:02:22.231 DEBUG cache miss key=session:a91f4c
14:02:22.450 INFO request done path=/checkout status=200 dur=182ms
14:02:22.631 INFO login ok user=[email protected] src=pos-3
14:02:22.802 DEBUG gc pause 3ms heap=412mb
14:02:23.227 INFO request done path=/cart status=200 dur=96ms
14:02:23.565 DEBUG http ok path=/metrics status=200 dur=1ms
14:02:24.091 ERROR upstream timeout host=pos-7 key=sk_test_9f3aa21c retry=1
14:02:24.328 INFO request done path=/checkout status=200 dur=241ms
14:02:24.543 DEBUG heartbeat ok node=store-0417
14:02:24.676 WARN queue depth rising depth=1204 max=2000
14:02:24.791 DEBUG http ok path=/health status=200 dur=2ms
14:02:24.964 ERROR payment declined order=88213 card=4242 4242 4242 4242
14:02:25.671 DEBUG cache miss key=session:a91f4c
14:02:25.890 INFO request done path=/checkout status=200 dur=182ms
14:02:26.071 INFO login ok user=[email protected] src=pos-3
14:02:26.242 DEBUG gc pause 3ms heap=412mb
14:02:26.667 INFO request done path=/cart status=200 dur=96ms
14:02:27.005 DEBUG http ok path=/metrics status=200 dur=1ms
14:02:27.531 ERROR upstream timeout host=pos-7 key=sk_test_9f3aa21c retry=1
14:02:27.768 INFO request done path=/checkout status=200 dur=241ms
14:02:27.983 DEBUG heartbeat ok node=store-0417
14:02:28.116 WARN queue depth rising depth=1204 max=2000
> requests window=60s count=15 p95=241ms errors=0
errors · 3 eventsdelivered to Elasticsearch
metrics · 37 seriesdelivered to Prometheus
archive · 15 GBdelivered to S3
85 GB of noise never left this node.
Elasticsearch
search index
Prometheus
metrics
S3
archive
errors · 3 events→ Elasticsearch
metrics · 37 series→ Prometheus
archive · 15 GB→ S3

01Filter

Debug noise is dropped on the node. Most of the volume never ships.

02Redact

Cards, emails, and keys are masked before they can travel.

03Aggregate

Request logs collapse into one latency metric, computed on the node. Summaries ship, raw stays.

04Ship

Compressed, packaged, and routed. Signal only.

Here’s the math

Every transformation you just watched happened before a byte crossed the network. That is where the cost, speed, and compliance wins come from. The numbers below come from one production deployment, a European automotive OEM: treat them as a reference point, since your results will depend on your log mix.

100 GB → 15 GB

raw logs in, signal out, measured on one node.

5×

lower total logging cost across transfer, ingest, and storage.

10×

faster queries against indexes that hold signal, not noise.

<1s

to alert on critical patterns, detected at the edge.

SOURCE: PRODUCTION DEPLOYMENT, EUROPEAN AUTOMOTIVE OEM

“Can’t our SIEM just filter this?”

It can, but only after you have paid to ship and ingest every byte. Filtering downstream trims what you see, not what you spend. Expanso sits in front of Splunk, Sentinel, Elastic, Datadog, or any SIEM, and leaves your rules where they are.

Filtering after the ingest meter bills 100 GB; filtering on the node bills 15 GB.$ THE INGEST METERNode100 GBWITHOUT EXPANSOfilterSIEMbilled 100 GBfilterWITH EXPANSOSIEMbilled 15 GB
Without Expanso
The filter runs after the ingest meter.
billed 100 GB
With Expanso
The filter runs on the node, before the meter.
billed 15 GB
The bill lands first

Ingest pricing is charged on arrival. A filter inside the SIEM runs after the meter, at the edge it runs before.

PII has already traveled

Redaction downstream means sensitive fields crossed the network and sat in queues. Masking on the node means they never left it.

One pipeline, every tool

SIEM rules only shape what enters that SIEM. Edge processing feeds search, metrics, and archive from a single place.

Why security teams deploy Expanso

Log pipelines are usually an observability purchase. Security teams sponsor this one because it shrinks what they have to defend, and because the reduction is deterministic: duplicates and debug noise are removed by rule, not by sampling, so nothing your detection rules depend on is gambled away.

Smaller breach blast radius

PII that never leaves the node cannot be exposed in transit, in a queue, or in a downstream index. Redaction at the source removes whole categories of incident.

Sovereignty by construction

Regional data stays in region because processing happens there. GDPR and HIPAA reviews get simpler when the answer is “it never crossed the border.”

Alerts before ingestion

Critical patterns fire on the node in under a second, not after batching, shipping, and indexing. Detection latency stops depending on pipeline depth.

Audit trail without the bulk

Full fidelity logs land in cheap archive storage, already redacted, while only signal reaches the SIEM. Investigations keep their evidence, budgets keep their headroom.

Live before your next SIEM invoice.

Your data is your data. The pipeline runs on your nodes, under your control, and ships only what you decide to ship. No SIEM replacement. No new agents. No rule rewrites.