Query provides a federated search platform that enables security teams to access and analyze data from various sources, including data lakes and cloud services, without the need for data movement or duplication. This technology reduces storage costs and accelerates investigations by delivering OCSF-normalized and enriched search results in real-time, enhancing visibility and context for security operations.
Funding
$19.6M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.


CSSDFounders
Product
Problem
Security teams struggle to efficiently access and analyze data scattered across diverse sources, including data lakes, cloud services, and SIEMs. Centralizing this data through traditional methods incurs high storage costs and requires complex data engineering pipelines. This complexity slows down security investigations and limits the ability to leverage all available data for threat detection and incident response.
Solution
Query offers a federated search platform that enables security teams to directly query data across various sources without requiring data movement or duplication. The platform provides fast data source connectivity, automatic data enrichment, and data normalization to the OCSF standard. By delivering enriched search results in real-time, Query accelerates security investigations, enhances visibility, and provides comprehensive context for security operations, all while reducing storage costs and eliminating the need for extensive data pipelining.
Target Audience
The primary target audience includes security teams, security operations centers (SOCs), and managed security service providers (MSSPs) seeking to improve threat detection, incident response, and security investigations.
Features
- Federated search across platforms, SaaS tools, and data lakes
- Connectors for Amazon Athena, Amazon CloudWatch Logs, Amazon Security Lake, Azure Log Analytics, Google BigQuery, Snowflake, Splunk, and more
- OCSF normalization at search time
- Automatic data enrichment
- API integrations and search translations
- Pre-built connectors for cloud infrastructure, email security, endpoint protection, identity management, and SIEM solutions
- Splunk App to expand search capabilities without increasing Splunk costs