Live data from Hacker News

Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

news.ycombinator.com

21–30 of 55 posts

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#22
post #21

Anyone aware of a similar solution for Google Cloud / GCP?

We are working on a solution for GCP and Azure :) GCP recently announced Iceberg support with BigLake and support for federation across multi-cloud lakes so it would be perfect use cases.

If you are interested in using Matano for GCP, feel free to reach out and join our Discord community! We are FOSS so would love to collaborate on a solution.

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#23

This issue exists to the right of your solution and is (for now) out of scope, but the biggest issue I have with security data lakes is the need to (easily) get both row-based data and visualizations. Back when I had access to a well-built and cared for Splunk environment, I would constantly run queries, build visualizations, go back to the results index, tweak the query, go back to viz, etc. This feedback loop is im…

The biggest issue I have with data lakes is they always without fail turn into a data cesspool. The more you add the less ROI you get out. And yes using Splunk as an example it becomes an organisational cost problem. I have spent way too many hours arguing with them over billing.

The only viable solution is design metrics into your platform properly from the ground up rather than trying to suck them out of a noisy datasource for megabucks.

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#24

This issue exists to the right of your solution and is (for now) out of scope, but the biggest issue I have with security data lakes is the need to (easily) get both row-based data and visualizations. Back when I had access to a well-built and cared for Splunk environment, I would constantly run queries, build visualizations, go back to the results index, tweak the query, go back to viz, etc. This feedback loop is im…

I completely agree with you and the need for a fully integrated solution with great visualizations without hosting additional tools that aren't purpose built! Unfortunately there are very few SIEMs that get this right today.. Here's how we are thinking of it. We think it's important for a successful security program to first have high quality data and this is why we want help every organization build structured secur…

For sure. Pull a dbt and get everybody hooked on your tool, then slap a SaaS platform ecosystem to the farthest right and watch the revenue flow.

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#25

This is awesome. Nice work open-sourcing it! I used Splunk at Expedia and it was super expensive and slow. While I wasn't using it for security purposes, it could take 15-30 min for us to detect error logs, and I can imagine that's not okay for security purposes. Good luck guys!

Wowsa. Somebody didn't do their job right if it took anywhere near that amount of time to get logs back. Sorry it was so painful.

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#26
Excited to give this a try and follow your progress!

In case anybody else is wondering how Matano compares to Panther (my first thought reading this launch post) there's a comparison on the Matano website[0].

Quick note to the Matano team, the "Elastic Common Schema (ECS)" link in the readme[1] seems to be broken.

[0] https://www.matano.dev/alternative-to/panther

[1] https://github.com/matanolabs/matano#-log-transformation--da...

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#27

Hi Shaeq and Samrose - congrats on the launch! Matano looks great. Out of curiosity, at some point I believe you were working on a predecessor called AppTrail whic tackled (customer-facing) audit logs, it was something I was interested in at the time (and still am! I would've loved to use that). Would you perhaps be willing to share your learnings from that product, and (I assume) why it evolved into Matano?

Thank you! Yes with AppTrail we wanted to solve the pain points around SaaS audit logs but since it was a product that needed to be sold and integrated into B2B startups rather than the enterprises that felt the pain points and needed audit logs in their SIEM, we couldn't find a big enough market to sell it.

We realized that the big problem was that most SIEM out there today did a poor job with pulling and handling the data from the multitude of SaaS and Cloud log sources that orgs have today, and decided to build Matano as a cloud-native SIEM alternative :)

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#28

Excited to give this a try and follow your progress! In case anybody else is wondering how Matano compares to Panther (my first thought reading this launch post) there's a comparison on the Matano website[0]. Quick note to the Matano team, the "Elastic Common Schema (ECS)" link in the readme[1] seems to be broken. [0] https://www.matano.dev/alternative-to/panther [1] https://github.com/matanolabs/matano#-log-transfor…

Thank you, fixed the link!

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#29
I loaded the GitHub link, bracing myself for yet another AGPL license, but no, it's Apache 2! So I wanted to say thank you for that and I hope to take a deeper look when I'm back at my desk because trying to keep Splunk alive and happy is a monster pain point. There are so many data sources we'd love to throw at it but we don't have the emotional energy to put up with Splunk crying about it

Re: Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

#30

Earlier quoted context omitted.

I completely agree with you and the need for a fully integrated solution with great visualizations without hosting additional tools that aren't purpose built! Unfortunately there are very few SIEMs that get this right today.. Here's how we are thinking of it. We think it's important for a successful security program to first have high quality data and this is why we want help every organization build structured secur…

For sure. Pull a dbt and get everybody hooked on your tool, then slap a SaaS platform ecosystem to the farthest right and watch the revenue flow.

Splunk is HEAVILY pushing their SaaS offering at the moment. They are the most obnoxious vendor we currently deal with.

We are fine on prem, pay big $$ license fees, but not enough. They want that sweet SaaS revenue.

I would be wary of pushing this, being a non-SaaS platform could be an advantage here.

Post reply on HN