StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.

For more details, see our announcement post.

At a high-level

  • Deployment is automated: simple, safe and repeatable for any AWS account
  • Easily scalable from megabytes to terabytes per day
  • Infrastructure maintenance is minimal, no devops expertise required
  • Infrastructure security is a default, no security expertise required
  • Supports data from different environments (ex: IT, PCI, Engineering)
  • Supports data from different environment types (ex: Cloud, Datacenter, Office)
  • Supports different types of data (Ex: JSON, CSV, Key-Value, and Syslog)
  • Supports different use-cases like security, infrastructure, compliance and more


StreamAlert High Level Architecture

(Click figure to enlarge)

Table of Contents