Teams have tried for a decade to escape per-gigabyte SIEM pricing by building on a data lake. A lake alone gives analysts no search bar, no detections, no cases. A SIEM without a programmable pipeline still inherits dirty data and runaway ingest. It takes both halves at once — and now both exist, meeting in ClickHouse.
Tenzir collects your telemetry, normalizes it to OCSF, and streams it into nano's ClickHouse over the native protocol. nano is the SIEM on top of those same tables: sub-second search, detections as code, and AI-led triage from alert to closed case.
fig 01 — Tenzir pipelines feeding nano's ClickHouse in real time.
Tenzir owns everything upstream of storage: collection, parsing, OCSF normalization, in-stream enrichment, and volume reduction. nano owns everything on top: search, detections, alert queues, triage, and cases. No duplicate copy, no second pipeline to operate — they compose on the same OCSF tables in ClickHouse.
Tenzir streams structured, columnar data into ClickHouse over the native protocol — never row-by-row JSON, never through a second ingestion layer. The tables it writes are the tables nano searches and detects on.
fig 02 — One path. Source-specific parsing stays out of the database; ClickHouse stays fast.
Per-gigabyte SIEM pricing punishes you for collecting more of what you should be collecting. This stack replaces the meter with two independent controls on cost.
Tenzir deduplicates, filters, and routes low-value logs to object storage before the write. Daily hot-path volume drops; nothing is lost — the full-fidelity copy stays in the lake, in open formats.
nano prices by flat capacity tier, AI and infrastructure included. Upstream reduction compounds: a leaner hot path can move the whole deployment into a smaller tier.
Both halves are open-source at the core. Start with open-source nano and Tenzir pipelines, prove the model, then move to hosted capacity on dedicated infrastructure.
Because Tenzir keeps the data model stable upstream, nano's rules do not break when sources change. Detections graduate from staging to live to alerting, earning trust on real data before they page anyone. Risk scoring per user, host, or IP means analysts triage accumulated risk, not raw alert volume.
And retention stops being an archive: retro-hunts over months of lake telemetry feel like searching yesterday's logs.
Read the full solution brief →Land one high-volume source as OCSF in ClickHouse with Tenzir, point nano at it, and measure search speed, detection coverage, and monthly cost against what you run today.
Open-source editions of both · native ClickHouse protocol · no second ingestion path