Cloud SIEMs send your logs off-site.
Every event leaves your perimeter for a vendor cloud you can't fully audit — a non-starter for classified, air-gapped, and regulated networks.
AI-Driven Secure Log Intelligence
Self-hosted log management and threat detection for classified, air-gapped, and regulated networks. Collect, enrich, detect, and respond — entirely inside your environment. No telemetry. No call-home.
Every event leaves your perimeter for a vendor cloud you can't fully audit — a non-starter for classified, air-gapped, and regulated networks.
Months of tuning, brittle correlation rules, and per-GB bills that punish you for collecting more of the data you need.
Most “AI security” ships your data to someone else's model. logrok runs detection where your data already lives — no call-home.
What logrok does
syslog TCP/UDP/TLS, webhooks, cloud APIs, and files — 200K+ events/sec on a single node.
plain text, regex, Lucene, and natural-language AI search across billions of events.
automatically classify, route, or suppress repetitive log patterns to surface what matters.
25+ built-in rules with MITRE ATT&CK mapping, correlation logic, and a custom rule DSL.
curated IOC feeds matched live against the ingest stream.
route to S3, Kafka, Splunk, Elasticsearch, Azure, GCP, Loki, Datadog, and more.
Architecture
REST API, web UI, and an AI agent interface. Pipelines, search, alerts, and automation.
High-performance log collector with config agents. Zero-touch pipeline deployment.
SQL analytics engine, config store with row-level security, SSO, and encrypted local storage.
Runs entirely in your environment. No data leaves your perimeter.
FIPS-hardened Linux appliance on any major hypervisor or bare metal.
Offline container images. No call-home license activation.
Helm charts. Each plane scales independently.
Single-host evaluation in under 5 minutes.
Data sovereignty and air-gap capability, zero telemetry, and no per-GB pricing surprises. Your logs never leave infrastructure you control.
AI-assisted triage and a modern, schema-native architecture — detection without a standing army of rule engineers.
FIPS 140-3 (OS-level CMVP #4823, #4750) · DISA STIG · CIS Level 1 · NIST SP 800-53 · CMMC Level 2 · OCSF v1.3
Zero telemetry. Sovereign on-premises operation.
Book a guided demo, or stand up the full platform with Docker Compose in under five minutes.