Observability Pipeline
LimaCharlie collects telemetry from any source, normalizes it, and routes it to any destination, with one difference from a conventional pipeline: it can act on the data in flight. Detection and response run inside the pipeline rather than at the far end of it.
Ingest
Stream data from endpoints, cloud platforms, SaaS applications, and security tools. Adapters cover the common sources, and the API covers everything else.
Normalize
All telemetry lands as structured JSON, which makes cross-source correlation and rule writing uniform regardless of where the data came from.
Act in flight
Because the detection engine sits in the pipeline, responses fire before routing. A suspicious O365 login can trigger an account suspension in the same pass that forwards the event downstream.
Route and retain
Send only the telemetry your SIEM actually needs and keep everything in LimaCharlie's included one-year searchable retention. SIEM ingest costs drop without giving up data for compliance or investigation.
Deploy your first sensor on the free community tier, or walk through it with a solutions engineer.
Start freeBook a demo