
Matano
Serverless security data lake for AWS with detection-as-code
Why teams choose it
- Normalize unstructured logs into a structured, real‑time data lake using Apache Iceberg.
- Integrates out‑of‑the‑box with 50+ security log sources and custom VRL pipelines.
- Detection‑as‑code with Python, including automatic Sigma import.
Watch for
Tied to AWS services; not multi‑cloud out of the box.
Migration highlight
Reduce SIEM licensing costs
Ingest all security logs into Matano’s data lake and query with Athena, eliminating the need for expensive third‑party SIEM storage.




