Sometimes you need to store data.
That shouldn’t put it out of reach.
Accelerated Connectors make your highest-volume logs fast to query and kept as long as you need them, right alongside every other source on the mesh.
Search, investigate, hunt, and detect on your data anywhere.
Storing it was never the problem.
Using it is.
An alert fires. To run it down you need last quarter’s authentication logs, the endpoint history you archived, and the DNS logs you stopped ingesting to save money. It’s all in Amazon S3, but none of it is one query away.
So the investigation stops at the edge of what you kept live, and the answer sits in a bucket you pay for every month and struggle to use.
There is a better way. It’s not another pipeline.
A connector. Not a pipeline.
Most Query connectors reach out to your tools and query them where they live. An Accelerated Connector does the opposite. It holds your data in a fast columnar store built and optimized for security operations. It’s connected to the same mesh, with the same capabilities and same console as the rest of your sources.
Because that store is columnar and typed, the questions that time out over raw logs in S3 come back in seconds: high-cardinality searches across hundreds of accounts, aggregations, the analytical work object storage was never built for.
Point us at a bucket.
Give Query an Amazon S3 bucket and a cross-account IAM role. Whatever lands data there, via Cribl, Firehose, or native exports, keeps running.
We index, normalize & maintain.
Query stands up the columnar store, backfills the history you choose, and maintains it as new data lands. No pipeline to build or maintain.
Use it in minutes.
The data joins the mesh, ready for investigations, threat hunting, detections, and AI agents. Query keeps it current.
A new connected source.
Nothing new to learn.
Accelerated Connectors show up like any other source on the mesh, so the data you stored and the tools you run live answer the same query.
Give your team access to the data you used to leave behind.
Pivot into your accelerated connector data mid-investigation, from the Query console or inside Splunk, without waiting on a scan that times out.
Sweep a year of history as easily as the last hour. Run retroactive hunts across everything you’ve stored.
Run scheduled detections on high-volume data you could never afford to ingest into your SIEM.
Give AI agents (yours or ours) the structured, normalized data they need to be efficient and accurate, not confidently incomplete.
Your budget finally stops setting the coverage map.
Accelerated Connectors are priced on storage volume, per day, for what you choose to keep. Search is included.
Keeping a year of data connected costs a fraction of holding it in a SIEM, and none of the engineering time of building a pipeline into a data platform. You set retention per connector, and forecast the cost from a number you already track. Coverage becomes a security decision, not a budget line.
The Query Amazon S3 connector searches a bucket where it is. For ad hoc searches at modest volume, that’s all you need.
When a source has to be fast at scale, across hundreds of accounts and a year of history, or kept for a set retention period.
Security operations. Run on the mesh.
Store what earns it. Reach the rest where it lives. Most sources on the mesh are searched live, where they are. Accelerated Connectors cover the ones that need speed at scale or a set retention period. Federated Search, Federated Detections and Query Workers reach both in the same query.
Connect your data, wherever it lives.
Query puts your security data to work. 50+ connectors. Centralized insights from decentralized data.
Mission-specific agents. Verifiable work.
AI agents for triage, investigation, threat hunting, ITDR and more. Engineered to earn trust.
Detect on data you can’t afford to ingest.
1,000+ FSQL recipes. SPL / KQL / Sigma translation. Coverage everywhere your data lives.
Every connected source. One query interface.
Search 50+ sources simultaneously. OCSF-normalized at query time. One query, every source.
