Sigma Capability
Its sigma operator evaluates Sigma v2.1 detection rules and global filters over structured events. Correlation rules are explicitly unsupported.
An independent tool index
for incident response teams
Feed automation EU-developed
Collects, parses, transforms, enriches and routes security telemetry through programmable pipelines for detection, investigation and downstream security tools.
By Tenzir GmbH · Germany
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Tenzir GmbH says it developed the current software and operates from Hamburg. Its preceding VAST research began at UC Berkeley; the German claim concerns the current company-led Tenzir product, not every historical contributor.
The fully open-source Node can run locally; the Community and Enterprise App/Platform are proprietary and vendor-hosted, while their nodes also include closed-source parts. The free Community edition has a 1 TB/day ingress limit. Do not infer all prebuilt binaries are solely BSD-licensed; documentation says they may contain proprietary plugins.
identity / capabilities
Upstream describes a security-data pipeline engine for collecting, parsing, normalizing, aggregating, storing, querying and routing telemetry, including in-stream detections.
Read sourcelicense
The actual root license grants redistribution in source and binary forms with the three BSD conditions and disclaims warranties.
Read sourceorigin / license / deployment
June 2026 terms identify Tenzir GmbH as developer, define an exclusively BSD-3-Clause Open-Source Edition, and separate proprietary hosted App/Platform and closed-source Node components. Community access is free under terms, with a 1 TB/day ingress limit.
Read sourcecountry
Tenzir GmbH is registered in Hamburg and lists a Hamburg, Germany address.
Read sourceorigin
The vendor traces VAST to research at UC Berkeley, shows its team in Hamburg in 2022, and says VAST was later renamed to Tenzir; this limits any claim of wholly German historical origin.
Read sourcedeployment
Official documentation supports Docker or a native static binary for a persistent node. Installation documentation separately offers CLI container and source builds, warning prebuilt packages can include proprietary plugins.
Read sourcemaintenance
Official upstream release list includes Tenzir Node v6.8.1 dated 24 July 2026; this is release activity, not an uptime or support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Its sigma operator evaluates Sigma v2.1 detection rules and global filters over structured events. Correlation rules are explicitly unsupported.
Its yara operator runs YARA-X rules over finite byte input. It compiles source rules, does not accept precompiled rules, and documents module and input-size limits.
The to_splunk operator sends JSON or raw events to a configured Splunk HTTP Event Collector using a HEC token.
The to_opensearch operator, also exposed as to_elasticsearch, sends batched events to an Elasticsearch-compatible Bulk API.
The read_suricata operator parses Suricata EVE JSON from files or streams into structured events. This is log ingestion, not execution of Suricata detection rules.
Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.
Automate security feeds without losing context