The Boston-based company’s new Detection Integrity feature uses its Clarity AI layer to audit existing SIEM rules, mapping them against required log sources. By analyzing Sigma, KQL, and SPL formats, the system generates protection rules that allow teams to reduce volume without inadvertently disabling security alerts. One global manufacturer reportedly used the tool to translate over 1,000 KQL rules in 72 hours, a process that traditionally requires weeks of manual labor.
To address the "blind spot" created by archiving logs outside the SIEM, Realm also introduced search capabilities to its Data Haven retention layer. Unlike traditional archive tiers that require time-consuming restores or complex schema transformations, this layer allows analysts to query raw, OCSF-normalized data directly. Because the platform charges based on ingestion rather than query volume, security teams can investigate incidents without the fear of escalating costs or vendor lock-in. Realm executives plan to demonstrate these capabilities at Black Hat in Las Vegas this August.





Comments (0)
No comments yet. Be the first!