Feed automation EU-developed

Tenzir

Collects, parses, transforms, enriches and routes security telemetry through programmable pipelines for detection, investigation and downstream security tools.

By Tenzir GmbH · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Feed automation
Developer or maintainer
Tenzir GmbH
Recorded country
Germany
Product model
Open core
Deployment
Self-hosted / SaaS
Software license
Mixed: BSD-3-Clause Open-Source Edition and Node code; proprietary App, Platform and Node extensions
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Tenzir GmbH says it developed the current software and operates from Hamburg. Its preceding VAST research began at UC Berkeley; the German claim concerns the current company-led Tenzir product, not every historical contributor.

Reported capabilities

  • Programmable security-data pipelines
  • Self-hosted nodes with CLI/container deployment
  • Hosted control plane for Community and Enterprise editions

Scope and limits

The fully open-source Node can run locally; the Community and Enterprise App/Platform are proprietary and vendor-hosted, while their nodes also include closed-source parts. The free Community edition has a 1 TB/day ingress limit. Do not infer all prebuilt binaries are solely BSD-licensed; documentation says they may contain proprietary plugins.

Inspect the research evidence 7 source observations
  1. identity / capabilities

    Upstream describes a security-data pipeline engine for collecting, parsing, normalizing, aggregating, storing, querying and routing telemetry, including in-stream detections.

    Read source
  2. license

    The actual root license grants redistribution in source and binary forms with the three BSD conditions and disclaims warranties.

    Read source
  3. origin / license / deployment

    June 2026 terms identify Tenzir GmbH as developer, define an exclusively BSD-3-Clause Open-Source Edition, and separate proprietary hosted App/Platform and closed-source Node components. Community access is free under terms, with a 1 TB/day ingress limit.

    Read source
  4. country

    Tenzir GmbH is registered in Hamburg and lists a Hamburg, Germany address.

    Read source
  5. origin

    The vendor traces VAST to research at UC Berkeley, shows its team in Hamburg in 2022, and says VAST was later renamed to Tenzir; this limits any claim of wholly German historical origin.

    Read source
  6. deployment

    Official documentation supports Docker or a native static binary for a persistent node. Installation documentation separately offers CLI container and source builds, warning prebuilt packages can include proprietary plugins.

    Read source
  7. maintenance

    Official upstream release list includes Tenzir Node v6.8.1 dated 24 July 2026; this is release activity, not an uptime or support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

Sigma Capability

Its sigma operator evaluates Sigma v2.1 detection rules and global filters over structured events. Correlation rules are explicitly unsupported.

YARA Capability

Its yara operator runs YARA-X rules over finite byte input. It compiles source rules, does not accept precompiled rules, and documents module and input-size limits.

Elastic Integration

The to_opensearch operator, also exposed as to_elasticsearch, sends batched events to an Elasticsearch-compatible Bulk API.

Suricata Integration

The read_suricata operator parses Suricata EVE JSON from files or streams into structured events. This is log ingestion, not execution of Suricata detection rules.

Put the tool in context.

Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.

Automate security feeds without losing context