query logo white
  • Query logo
  • Products
    • Query Federated Search
    • Query Federated Search for Splunk
    • AI Agents
    • Security Data Pipelines
  • Platform
    • The Future is Federated
    • Federated Search
    • Connectors
    • Documentation
  • Use Cases
    • Compliance
    • Incident Response
    • Security Investigations
    • SIEM Migration
    • Splunk Cost Reduction
    • Threat Hunting
    • Examples
      • Amazon Security Lake
      • CrowdStrike/S3
      • EDR Data
  • Resources
    • Blogs
    • Datasheets
    • Events
    • Newsroom
    • Videos
    • Webinars
    • White Papers
  • Company
    • About Us
    • Partners
      • Splunk Services Partner Program
    • Leadership
    • Board of Directors
    • Careers
  • Book a Demo

Author: Jonathan Rau

VP/Distinguished Engineer, Query
query security data pipeline availability blog header

Blogs

Product Release: General Availability of Query Security Data Pipelines

October 2, 2025 / October 2, 2025 by Jonathan Rau | Leave a Comment

Introduction The security industry at-large likes to brand data as “the new oil”, or more frequently, as “gravity”. I disagree. Data is mass, like super dense tungsten ore or cobalt-based alloys like Inconel. The only way we can move these large masses of ore is via heavy machinery and heavy logistics, the analogue to that […]

Read more »

security data mesh soc blog header

Blogs

The Data Advantage: Why a Security Data Mesh Is the Foundation for Modern SOCs

September 11, 2025 by Jonathan Rau | Leave a Comment

Introduction AI SOC. Autonomous SOC. LLMs for Security Analysts. You’ve seen it, we’ve seen it, there is something there, but the industry hasn’t nailed it yet. Security lives and dies on data. If your data foundation is weak, no amount of AI will help, and it is beyond a shadow of a doubt that there […]

Read more »

splunk snowflake federated search

Blogs

Federated Search from Splunk to Snowflake (and More)

September 10, 2025 / September 11, 2025 by Jonathan Rau | Leave a Comment

Introduction A core tenet of the Query Security Data Mesh is providing operators access to data, wherever it lives. Whether the relevant data is behind an EDR API, in Azure Data Explorer, or Snowflake, our Mesh allows you to interact with decentralized and distributed data sources as if they were centralized. Another tenet of the […]

Read more »

write data to gold blog header

Blogs

Write to Gold with Query Security Data Pipelines

August 3, 2025 / August 3, 2025 by Jonathan Rau | Leave a Comment

Introduction How do all of these self-congratulating posts start, again? Oh right, “in the ever-changing security threat bad guy landscape, data is the new oil or diamond pickaxe!” Cynicism aside, I will continue to shout from the rooftops: the most important asset and skillset that a security organization needs to develop is data. Data engineering […]

Read more »

query adx integration blog header

Blogs

Product Update: Query Federated Search integrated with Azure Data Explorer

July 29, 2025 / July 29, 2025 by Jonathan Rau | Leave a Comment

Introduction Azure Data Explorer (ADX) in an interactive, fully managed Exploratory Data Analysis (EDA) platform hosted on the Microsoft Azure cloud. ADX enables analysts to onboard datasets natively into ADX, from object storage such as Blob and ADLSv2, select databases, and Delta Lake tables. From there, analysts can further transform data and/or analyze and visualize […]

Read more »

Query Lacework integration blog header

Blogs

Product Update: Query Federated Search integrated with FortiCNAPP

July 29, 2025 / July 30, 2025 by Jonathan Rau | Leave a Comment

Introduction The Cloud Native Application Protection Platform (CNAPP) category represents a consolidation of the cloud security space. Namely, Cloud Security Posture Management (CPSM), Cloud Workload Protection Platform (CWPP), and Cloud Detection & Response (CDR), with some additional capabilities also covered. One of the earliest in the CNAPP category is Lacework, acquired by Fortinet and rebranded […]

Read more »

detection engineering 101 blog header

Blogs

Detection Engineering 101: Proactive Threat Detection for Modern Security Teams

July 8, 2025 / July 8, 2025 by Jonathan Rau | Leave a Comment

Cyber threats are “always on”. No matter what countermeasures you have – be they in the form of environment-specific detection or prevention capabilities – firstline tools are hardly ever enough to counter salient threats to your business. One function quietly powers our most agile defenses, speeds up response times, and slashes false positives: Detection Engineering. […]

Read more »

query snowflake integration

Blogs

Snowflake and Query: Better Together for Security Outcomes

June 24, 2025 / June 24, 2025 by Jonathan Rau | Leave a Comment

Introduction Security teams are building more flexible architectures that prioritize data control, speed, and scale. Snowflake has emerged as a strategic data platform for security use cases, especially when combined with federated capabilities from Query that enable rapid analysis, detections, and investigations directly against Snowflake’s tables and views, without the need for data duplication or […]

Read more »

Blogs

Better Together: Query Federated Security + Cribl

June 3, 2025 / June 3, 2025 by Jonathan Rau | Leave a Comment

Complexity is the enemy of modern Security Operations (SecOps). Everyday, new product categories are born and with it they bring more and more datasets, some of them are very pertinent and some of them are duplicative. Data volumes continue to grow even from incumbent tools, and security teams are stuck holding the bag – often […]

Read more »

multi-tenant data blog header

Blogs

Simplifying Multi-Tenant Data Access with Federated Search

May 27, 2025 / May 27, 2025 by Jonathan Rau | Leave a Comment

Introduction For security leaders at larger enterprises, MSSPs, MDRs, holding companies, and private equity firms, the complexity of multi-tenant security environments can be a back breaker. Whether driven by strategic M&A activity or supporting a diverse portfolio of subsidiaries or customers, organizations grapple with overlapping security tech stacks, siloed data pipelines, and fragmented detection workflows. […]

Read more »

Page navigation
  • Current Page 1
  • Page 2
  • Page 3
  • ›
  • »
COMPANY

Product

About

Careers

Partners

Leadership

Board of Directors

RESOURCES

Documentation

Blogs

Events

Newsroom

Videos

Webinars

White Papers

LEGAL

BETA Terms

Data Processing Agreement

Privacy & Cookie Policy

Security Protocols

Service Level Agreement

Subprocessors

Support Agreement

Terms and Conditions

CONTACT

Book a Demo

Contact Sales

query on linkedinquery on Xquery on youtube


Query

3423 Piedmont Road NE
• Atlanta, GA 30305
©2025 Query, All Rights Reserved.