Blogs
November 19, 2025 / November 19, 2025 by Jonathan Rau | Leave a Comment
The Definitive Guide to what Cybersecurity Mesh Architecture (CSMA) should look like. This is part 3 of a 3 part blog series about Data Mesh intended to educate and serve as a decision-making tool for security leaders rethinking their data strategy. You can read more in Part 1 and Part 2. Reimagining CSMA: What Security […]
Read more »
The Definitive Guide to what Cybersecurity Mesh Architecture (CSMA) should look like. This is part 2 of a 3 part blog series about Data Mesh intended to educate and serve as a decision-making tool for security leaders rethinking their data strategy. You can read more in Part 1 and Part 3. Dissecting Cybersecurity Mesh Architecture […]
The Definitive Guide to what Cybersecurity Mesh Architecture (CSMA) should look like. This is Part 1 of a 3-part blog series about Data Mesh intended to educate and serve as a decision-making tool for security leaders rethinking their data strategy. You can read more in Part 2 and Part 3. Introduction Our compatriots on the […]
November 17, 2025 / November 18, 2025 by Jonathan Rau | Leave a Comment
Introduction It’s not a surprise that out of all of our core features, the most popular one is the Splunk App for Query. A majority of our customers are users of Splunk, with cost pressures pushing them out of Splunk, and the decentralization-first nature of Query providing an easy offramp. A popular SIEM that these […]
November 12, 2025 / November 12, 2025 by Jonathan Rau | Leave a Comment
Introduction To continue pushing our mission of providing security and IT teams the ability to treat decentralized or distributed datasets as a central source, the team here at Query is always looking to onboard and update Connectors into the Query Security Data Mesh. Some of these Connectors have existed for a few months, but we […]
October 23, 2025 / October 23, 2025 by Jonathan Rau | Leave a Comment
Introduction It’s a well known fact that Query uses the Open Cybersecurity Schema Framework (OCSF) as our lingua franca. It is our chosen data model to normalize and standardize the disparate security and IT data we provide access to through our Security Data Mesh, and also how users express their search intent, configure pipelines, and […]
October 2, 2025 / October 2, 2025 by Jonathan Rau | Leave a Comment
Introduction The security industry at-large likes to brand data as “the new oil”, or more frequently, as “gravity”. I disagree. Data is mass, like super dense tungsten ore or cobalt-based alloys like Inconel. The only way we can move these large masses of ore is via heavy machinery and heavy logistics, the analogue to that […]
September 11, 2025 by Jonathan Rau | Leave a Comment
Introduction AI SOC. Autonomous SOC. LLMs for Security Analysts. You’ve seen it, we’ve seen it, there is something there, but the industry hasn’t nailed it yet. Security lives and dies on data. If your data foundation is weak, no amount of AI will help, and it is beyond a shadow of a doubt that there […]
September 10, 2025 / September 11, 2025 by Jonathan Rau | Leave a Comment
Introduction A core tenet of the Query Security Data Mesh is providing operators access to data, wherever it lives. Whether the relevant data is behind an EDR API, in Azure Data Explorer, or Snowflake, our Mesh allows you to interact with decentralized and distributed data sources as if they were centralized. Another tenet of the […]
August 3, 2025 / August 3, 2025 by Jonathan Rau | Leave a Comment
Introduction How do all of these self-congratulating posts start, again? Oh right, “in the ever-changing security threat bad guy landscape, data is the new oil or diamond pickaxe!” Cynicism aside, I will continue to shout from the rooftops: the most important asset and skillset that a security organization needs to develop is data. Data engineering […]