Query Accelerated Connectors

Sometimes you need to store data.
That shouldn’t put it out of reach.

Accelerated Connectors make your highest-volume logs fast to query and kept as long as you need them, right alongside every other source on the mesh.
Search, investigate, hunt, and detect on your data anywhere.

The problem

Storing it was never the problem.
Using it is.

An alert fires. To run it down you need last quarter’s authentication logs, the endpoint history you archived, and the DNS logs you stopped ingesting to save money. It’s all in Amazon S3, but none of it is one query away.

So the investigation stops at the edge of what you kept live, and the answer sits in a bucket you pay for every month and struggle to use.

There is a better way. It’s not another pipeline.

The solution

A connector. Not a pipeline.

Most Query connectors reach out to your tools and query them where they live. An Accelerated Connector does the opposite. It holds your data in a fast columnar store built and optimized for security operations. It’s connected to the same mesh, with the same capabilities and same console as the rest of your sources.

Because that store is columnar and typed, the questions that time out over raw logs in S3 come back in seconds: high-cardinality searches across hundreds of accounts, aggregations, the analytical work object storage was never built for.

01 — CONNECT

Point us at a bucket.

Give Query an Amazon S3 bucket and a cross-account IAM role. Whatever lands data there, via Cribl, Firehose, or native exports, keeps running.

02 — ACCELERATE

We index, normalize & maintain.

Query stands up the columnar store, backfills the history you choose, and maintains it as new data lands. No pipeline to build or maintain.

03 — USE

Use it in minutes.

The data joins the mesh, ready for investigations, threat hunting, detections, and AI agents. Query keeps it current.

On the mesh

A new connected source.
Nothing new to learn.

Accelerated Connectors show up like any other source on the mesh, so the data you stored and the tools you run live answer the same query.
Give your team access to the data you used to leave behind.

Investigations

Pivot into your accelerated connector data mid-investigation, from the Query console or inside Splunk, without waiting on a scan that times out.

Threat hunting

Sweep a year of history as easily as the last hour. Run retroactive hunts across everything you’ve stored.

Federated Detections

Run scheduled detections on high-volume data you could never afford to ingest into your SIEM.

Query Workers

Give AI agents (yours or ours) the structured, normalized data they need to be efficient and accurate, not confidently incomplete.

The economics

Your budget finally stops setting the coverage map.

Accelerated Connectors are priced on storage volume, per day, for what you choose to keep. Search is included.

Keeping a year of data connected costs a fraction of holding it in a SIEM, and none of the engineering time of building a pipeline into a data platform. You set retention per connector, and forecast the cost from a number you already track. Coverage becomes a security decision, not a budget line.

Reach it in place

The Query Amazon S3 connector searches a bucket where it is. For ad hoc searches at modest volume, that’s all you need.

Accelerate it

When a source has to be fast at scale, across hundreds of accounts and a year of history, or kept for a set retention period.

Available for Amazon S3 today

Put your data in Amazon S3
to work.

See it in action.

Book a demo →