Open source security data lake for AWS
Matano Open Source Security data lake is an open source cloud-native security data lake, built for security teams on AWS.
[!NOTE]
Matano offers a commercial managed Cloud SIEM for a complete enterprise Security Operations platform. Learn more.
Features
- Security Data Lake: Normalize unstructured security logs into a structured realtime data lake in your AWS account.
- Collect All Your Logs: Integrates out of the box with 50+ sources for security logs and can easily be extended with custom sources.
- Detection-as-Code: Use Python to build realtime detections as code. Support for automatic import of Sigma detections to Matano.
- Log Transformation Pipeline: Supports custom VRL (Vector Remap Language) scripting to parse, enrich, normalize and transform your logs as they are ingested without managing any servers.
- No Vendor Lock-In: Uses an open table format (Apache Iceberg) and open schema standards (ECS), to give you full ownership of your security data in a vendor-neutral format.
- Bring Your Own Analytics: Query your security lake directly from any Iceberg-compatible engine (AWS Athena, Snowflake, Spark, Trino etc.) without having to copy data around.
- Serverless: Fully serverless and designed specifically for AWS and focuses on enabling high scale, low cost, and zero-ops.
Architecture
👀 Use cases
- Reduce SIEM costs.
- Augment your SIEM with a security data lake for additional context during investigations.
- Write detections-as-code using Python to detect suspicious behavior & create contextualized alerts.
- ECS-compatible serverless alternative to ELK / Elastic Security stack.
✨ Integrations
Managed log sources
Alert destinations
Query engines
Quick start
View the complete installation instructions
Installation
Install the matano CLI to deploy Matano into your AWS account, and manage your deployment.
Linux
curl -OL https://github.com/matanolabs/matano/releases/download/nightly/matano-linux-x64.sh
chmod +x matano-linux-x64.sh
sudo ./matano-linux-x64.sh
macOS
curl -OL https://github.com/matanolabs/matano/releases/download/nightly/matano-macos-x64.sh
chmod +x matano-macos-x64.sh
sudo ./matano-macos-x64.sh
Deployment
Read the complete docs on getting started
To get started, run the matano init command.