OUR SOLUTIONS

VirtualMetric DataStream

Enterprise SOC teams pull log data from a growing number of sources, each in its own native format. Converting that native format into what the SIEM or analytics platform expects takes manual mapping work, work that has to be repeated every time a source is added or changes. Analyst accuracy, and the accuracy of AI agents working the same data, depend on the quality of what reaches the SIEM. And growing data volume driving up SIEM ingest costs adds to the daily pressure on security teams. These teams require a pipeline that processes this data automatically.

Forcerta meets this need with VirtualMetric’s DataStream platform.

What DataStream Is

DataStream is VirtualMetric’s security data pipeline platform, built in Amsterdam. It collects log data from existing sources, normalizes it into standard schemas, enriches it with context, and filters out low-value events. It then routes the data to the destination of choice: SIEM platforms (Microsoft Sentinel, Elastic Security, Splunk Enterprise Security, Google SecOps, etc.), data lakes (Amazon Security Lake, Sentinel data lake, etc.), storage, or analytics platforms and custom APIs.

How It Works?

DataStream sits between log sources and their destinations, and runs five core steps:

        Collect: Gathers data from existing sources across on-premises, cloud, and hybrid environments. Collection is agentless by default, using secure, read-only access. Optional agents are available where a source needs deeper visibility.

        Normalize: Maps raw log data into standard schemas, including ASIM, OCSF, CIM, ECS, UDM, and CommonSecurityLog, converting it into the format the SIEM or analytics tool expects.

        Enrich: Adds context to events: user identities, device and host details, geo-IP, application data, and threat intelligence matches against IPs, domains, URLs, and file hashes.

        Filter: Removes duplicate or low-value events and fields, and applies sampling, reducing the volume reaching the destination.

        Route: Sends the resulting data to one or more destinations, including SIEMs, data lakes, storage, and analytics platforms. Multi-tenant routing manages separate data flows for different business units or customers from a single deployment, useful for MSSPs and shared SOC environments.

Benefits for SOC Teams

        Lower SIEM costs: Field-level filtering and event sampling reduce ingest volume by 50 to 90%, depending on source mix.

        Less manual work: Parsing, normalization, and enrichment run automatically and at scale, removing the need for manual mapping or scripting. Up to 60% reduction in manual work.

        Cleaner data for analysts and AI agents: Normalized, enriched data improves detection accuracy and cuts time spent on manual data cleanup.

        Faster source onboarding: First pipeline live in under 30 minutes, with no complex configuration or system restarts. See full setup from scratch in 14 minutes.

        Schema drift detection: Real-time validation catches schema changes before they break analytics rules or compliance audits.

        No dropped events, even at peak volume: DataStream leads PipeBench, an open benchmark for data pipelines. Events arrive complete and on time, with no drops, duplicates, or corruption under load.

Who It's For?

DataStream fits enterprise SOC teams managing multiple log sources into one or more SIEMs, teams running a SIEM migration, and MSSPs operating multi-tenant environments.

Get Started

Contact Forcerta to see how DataStream fits your current log sources and destinations.