Event Data Warehouse

The growing demands placed on event information systems come primarily from two recent developments:

  1. The exploding amount of event data that has to be managed
  2. The increased length of time event data must be stored

Very few event data management solutions can handle the scale – both volume and duration. Aside from Sensage, no others were purpose-built to address those needs.

Sensage was founded on the assumption that security event logging, management and response would evolve into a data management problem. Our solution is built atop an event data warehouse that leverages a columnar database uniquely designed for time-stamped, unstructured data to be correlated and analyzed - in real time or years at a time.

  • Clustered, Columnar Database
    • Distributed and parallel data loading
    • Distributed and parallel query processing
    • Compressed data retention
    • Linear scalability using Massively Parallel Processing (MPP)
  • Real-Time Correlation
    • Real-time event parsing and correlation
    • Threshold-based and scenario-based correlation
    • Single, multi- and cross-source event alert generation
    • Contextual drill-down into events 
  • Historical Correlation
    • Data archived from online data storage to archival data storage (historical data)
    • Transparent access to online and archival data
    • Long range analysis of persistent and contributing events

The entire solution runs in a massively parallel cluster that leverages commodity hardware and storage for enhanced load and query throughput; up to 40:1 data compression when compared to relational databases; and extremely large total data retention (e.g., petabytes). The Sensage event data warehouse provides seamless and transparent way to archive the data and retrieve archived data, relieving the burden from the application.