zcrSIEM - Security Information and Event Management (SIEM)
Centralized SIEM that collects, correlates, analyzes, and investigates security events across on-premises, hybrid-cloud, and multi-cloud environments.
What environments and sources can zcrSIEM connect?
The datasheet covers on-premises, hybrid-cloud, multi-cloud, private cloud, hosted cloud, containers, Kubernetes, network devices, firewalls, IDS/IPS, Windows, Linux, identity, applications, databases, endpoints, email security, and cloud platforms.
How does zcrSIEM handle growth and burst volume?
Capacity is licensed by daily ingest volume in GB/day, not by events per second, so a short burst does not breach the licence — there is no license-level EPS cap. Processing scales through scale-out and horizontal scaling, with buffering, queue management, distributed processing, rate limiting, and quota allocation.
How does it protect retained security data?
The datasheet describes at least 90 days of historical storage, source-specific retention and archive tiers, TLS 1.3 or equivalent in transit, data-at-rest encryption, data masking, anonymization, and source-side filtering.
How does it help analysts investigate?
Analysts can use predefined and custom rules, UEBA, risk prioritization, MITRE ATT&CK, threat intelligence, cross-domain cases, timelines, entity graphs, PCAP links, natural-language queries, AI summaries, and incident reports.