NEW200+ connectors now onboarded. Map any security source to OCSF with a single pipeline.Read the announcement
Consulting
About us
Book a demoStart now
Security data pipeline

One schema for every log source.

Derwent Labs normalises every byte of your security telemetry to OCSF before it reaches the SIEM. Detections, dashboards and analysts then work from one language, no matter how many tools sit upstream.

OCSF 1.7 out of the box
app.derwentlabs.com / pipelines / prod-edr-router
Live · 18.4k rps
Sources11 connected
AWS CloudTrail
AWS CloudTrail
2.8k rps
ocsf
Okta · Audit
Okta · Audit
4.2k rps
ocsf
C
CrowdStrike FDR
11.4k rps
ocsf
GitHub Audit
GitHub Audit
240 rps
ocsf
Normalise · Enrich · Filterv1.42.0
Normalise to OCSF 1.7100%
Normalise · timestamps to UTC42 fields
Enrich · identity (Okta + AD)98.4%
Enrich · asset (Wiz CMDB)92.1%
Filter · drop heartbeat events−34%
Destinations3 active
Splunk · HEC
Splunk · HEC
OCSF · high-value
L
S3 Data Lake
OCSF · full fidelity
D
Datadog SIEM
OCSF · cloud only
Throughput
18.4krps
+12%
OCSF mapped
100%
Enriched
96.2%
p95 latency
48ms
Errors (1h)
0
How Derwent Labs works

Normalisation comes first.
Everything else follows from it.

Connect any source. Map every field to OCSF. Enrich with the context your detections actually need. Filter the noise. All in flight, before a single byte reaches your SIEM.

01 · Managed connectors

Connect any security tool in minutes.

Pick a source and Derwent Labs handles the work you'd otherwise own: the schema, the rate limiting, the retries, and the OCSF mapping on the way out.

  • 200+ pre-built connectors
  • Auto-discovered schemas + sample payloads
  • Universal S3 and HTTP inputs as fallback
app.derwentlabs.com / sources
Search 200+ connectors…
Okta
Okta
Identity
LIVE
C
CrowdStrike
EDR
LIVE
AWS CloudTrail
AWS CloudTrail
Cloud
LIVE
W
Wiz
CSPM
LIVE
GitHub
GitHub
Developer
LIVE
Duo
Duo
Identity
Connect →
T
Tines Events
SOAR
Connect →
S
Semgrep
AppSec
Connect →
02 · Normalise to OCSF

One schema. Every tool. No exceptions.

Derwent Labs maps every source to the Open Cybersecurity Schema Framework automatically. Detections, dashboards and analysts stop caring where an event came from, because they already know what to do with it. That's on top of our library of automations and use cases.

  • 100+ pre-built automations
  • 100+ detection use cases, ready to run
  • Write detections once, portable across every SIEM
normalise · OCSF 1.7 · authentication
Raw · 3 vendors · 4 schemas
Okta
Okta
system_log
eventType
actor.alternateId
outcome.result
published
C
CrowdStrike
FDR · UserLogonEvent
event_simpleName
UserName
Success
@timestamp
AWS
AWS
CloudTrail · ConsoleLogin
eventName
userIdentity.userName
errorCode
eventTime
OCSF · Authentication · 3002
1 SCHEMA
activity_id
1 · Logon
3 sources
actor.user.email
alex.lee@navan.com
3 sources
status_id
1 · Success
3 sources
time
1715583122
3 sources
Coverage 100%Write once · run everywhere
03 · Enrich in flight

The context your detections actually need.

Identity from your IdP, asset posture from your CSPM, threat intel from your feeds: all joined onto every normalised event in flight. Your SIEM stops doing the job of a SOAR.

  • Identity, asset, geo, threat intel out of the box
  • Lookup against any source: Okta, AD, Wiz, custom CSV
  • JQ escape hatch for the genuinely weird cases
pipeline · sandbox · enrich identity + asset
enrich.jq · authentication
1# join identity context
2lookup(.actor.user.email)
3| .actor.user.department
4| .actor.user.is_privileged
5| .device += wiz.posture
6
Enriched event (OCSF)
4 lookups · 38ms
{
  "activity_id": 1,
  "actor.user.email": "a.lee@co.com",
  "department": "engineering",
  "is_privileged": true
}
04 · Filter the noise

Stop paying to store healthchecks.

Once everything is normalised, dropping low-value events is one line. Heartbeats, polling traffic and duplicate audit chatter are gone before they hit ingest. Full-fidelity copies live in cheap object storage, ready for replay.

  • 60–80% average ingest reduction
  • Replay historical data against new detections
  • Mask PII before it leaves your network
pipeline · filter · last 24h
Volume by stage · last 24h
full-fidelity copy → S3
Raw ingest
100k rps
baseline
Dedup
92k rps
−8%
Drop healthchecks
65k rps
−29%
Drop low-value
38k rps
−42%
To SIEM
32k rps
−16%
Ingest reduction
68%
SIEM bill / yr
$1.2M
saved
Detection regressions
0
full-fidelity replay
Integrations

200+ sources.
One schema.

Every connector ships with an OCSF mapping out of the box: vetted, versioned, and inspectable. You point us at a source and we handle the normalisation.

200+pre-mapped connectors
OCSF 1.7out of the box
< 5 minmedian time-to-first-event
Explore all integrations
Splunk
Splunk
Microsoft Sentinel
Microsoft Sentinel
C
CrowdStrike Falcon
W
Wiz
Okta
Okta
AWS CloudTrail
AWS CloudTrail
Azure Monitor
Azure Monitor
GCP Audit Logs
GCP Audit Logs
GitHub Enterprise
GitHub Enterprise
Z
Zscaler
D
Defender for Endpoint
Duo Security
Duo Security
T
Tines
Jira
Jira
T
Tenable Nessus
Chronicle
Chronicle
Qualys VMDR
Qualys VMDR
Sumo Logic
Sumo Logic
Elastic
Elastic
P
Proofpoint
200+ more connectorsRequest integration
Why teams choose Derwent Labs

What a single schema
does for your team.

5 min
to adopt years of work

Detections and automations become portable.

Because every source maps to the same OCSF schema, detections and automations aren't tied to one stack. A set of automations another team spent years building can drop into your pipeline in about five minutes.

60–80%
average ingest reduction

Cost control at every step.

Once your data is normalised, dropping noise is one line of JQ. Filtering heartbeat and polling traffic before it reaches storage means less clutter, a smaller bill, and more budget for real security work.

< 5 min
to first OCSF event

Onboard in minutes.

There's no professional services engagement and no multi-month deployment plan. Connect your first source and normalised OCSF data starts flowing within minutes.

3+ SIEMs
dual-write supported

Vendor independence.

If your SIEM bill or licence terms stop working for you, that's fine. Because your data is centralised before ingestion, you can dual-write today and migrate on your own timeline.

Get started

Set up and start seeing signal in three steps.

01.

Connect your security stack

Connect your existing tools with no coding required. Derwent Labs ingests your security data securely, usually within minutes.

Search 200+ connectors
Okta
Okta
● Connected
C
CrowdStrike
AWS
AWS
W
Wiz
GitHub
GitHub
D
Datadog
02.

Normalise to OCSF, automatically

Every byte from every source is mapped to OCSF 1.7 on the way in, so you're left with one schema and one query language to learn.

NORMALISE → OCSF 1.7
eventType activity_id
actor.alternateId actor.user.email
outcome.result status_id
published time
Okta · system_log4/4 mapped
03.

Enrich and ship clean data

Identity, asset, and threat context get joined in flight, and the noise gets filtered out. Signal goes to your SIEM, with a full-fidelity copy kept in your data lake.

Splunk
Splunk
OCSF · high-value
LIVE
L
S3 Lake
OCSF · full fidelity
LIVE
Sentinel
Sentinel
OCSF · cloud only
LIVE
FAQ

Frequently asked questions.

Hit "Start now" at the top of this page and get a call booked in. We'll walk you through connecting your first source and get normalised OCSF data flowing.
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF, and you can stop maintaining parsers and rewriting detections every time a vendor changes a field.