Tenzir logo

Tenzir

Security Information and Event Mgmt. (SIEM)

Open Source
Free Tier
Free Tier
E
Enterprise
Self-hosted
OpenMSP Score
31
6
Reddit Impact Score
Github Score
40M
731Stars
104Forks
27KCommits
BSD 3-Clause "New" or "Revised" LicenseLicense
Mar 21, 2026Last commit
Open source security data pipeline for collecting, transforming, and analyzing security telemetry More detailed information about this vendor will be added soon.
image media
1 / 2

Key Features

Security Data Pipelines

Purpose-built data pipeline engine for security teams with native operators for detection, enrichment, and threat intelligence

Tenzir Query Language (TQL)

Powerful yet simple pipeline language for data collection, routing, processing, and enrichment with live and retro execution

Open Standards Integration

Built on Apache Arrow, Parquet, SIGMA, and STIX standards with extensive connector library for security tools

Cost Optimization

Reduces SIEM, cloud, and data costs by 30-50% through intelligent data routing and processing at the edge

Federated Architecture

Multi-node pipeline management enabling federated detection and response architectures across organizations

Pros and Cons

Pros

Security-Native Design

First data pipeline solution purpose-designed for security use cases with native detection and enrichment operators

Open Source Foundation

Open-core platform built on open standards, avoiding vendor lock-in and enabling customization

Significant Cost Savings

Customers report 30-50% reduction in SIEM ingestion costs and overall data processing expenses

Rapid Deployment

Pre-built pipeline modules and OCSF mappings enable deployment in hours instead of weeks

Cons

Emerging Platform

Relatively new platform with smaller ecosystem compared to established data pipeline solutions

Security Focus Limitation

Specialized for security use cases, may not be suitable for general-purpose data processing needs

Learning Curve

TQL and pipeline concepts require learning new syntax and methodology for data operations

Limited Enterprise Features

Enterprise edition features and pricing not fully transparent, requiring sales engagement

Feature Comparison

Comments

Armina RustamiSecureFlow Hub

Armina RustamiSecureFlow Hub

Jun 25, 2025

Powerful security data pipeline

Tenzir handles security telemetry collection and analysis well across client environments. Data transformation capabilities are flexible and performance is solid.

Daniel ScottTechGuard MSP

Daniel ScottTechGuard MSP

Jun 22, 2025

Good for security analytics

Using Tenzir for client security data processing. Open source model is appealing and pipeline flexibility helps with diverse data sources. Learning curve exists.

Mila HorvatDataFlow Hub

Mila HorvatDataFlow Hub

Jun 19, 2025

Effective data transformation

Tenzir processes large volumes of security data effectively. Real-time capabilities work well and integration options are comprehensive. Documentation could improve.