Alpaca

Alpaca

Log-source governance beside your SIEM

Your SIEM handles the events. Alpaca answers who owns each log source, how critical it is, and which assets send nothing at all.

Get in Touch
Where the blind spots come from
CMDB The assets of record
Log sources What actually reports
SIEM Rules and configuration, read-only
Alpaca registry

One governed record per source: owner, criticality, retention.

Covered Asset reports, source owned, retention set
Blind spot An asset in the CMDB with nothing reporting

The single source of truth for your log sources

Alpaca gives security and operations teams one trusted, governed registry of every log source. It does not replace your SIEM, it completes it. While QRadar, Splunk, Sentinel, or Elastic handle the events, Alpaca answers what they leave unsaid: who owns each source, how critical it is, how long its data is retained, and, above all, which assets are escaping security coverage entirely.

The challenge

The inventory of log sources rarely lives in one place. It is scattered across spreadsheets, the memory of whoever has been around longest, and configuration buried inside each SIEM.

Without a single view, the gaps pile up unnoticed: critical assets sending nothing to security, contradictory CMDB records, sources left active long after they should have been retired, and onboarding that leaves no trail when the auditors arrive.

The solution

Alpaca brings everything into one living, governed registry. It does not replace your SIEM, it completes it: the SIEM handles the events, while Alpaca answers what those tools leave unsaid.

Run it on-site or in your private cloud, connect it to the systems you already have, and give every team the visibility, the coverage, and the audit trail they have always lacked.

Security coverage

Which assets have logs, and which are exposed?

Alpaca correlates your asset inventory, whether CMDB, ServiceNow, or another source, with the log sources that actually exist, and shows in one place where you have coverage and where you have gaps. Every uncovered asset is a blind spot on your attack surface, where an incident would go unnoticed. Finding them stops being a matter of luck and becomes a process.

Intelligent assistant

Ask questions in plain language, such as "which critical assets have no coverage?", and get answers drawn from the platform's real data, never inferred, always respecting each user's permissions and access.

It runs 100% offline with local models, so your data never leaves the infrastructure, which matters in regulated environments. When you want more depth, it can also draw on external models. The choice is always yours.

SIEM visibility & lifecycle

Alpaca reads your SIEM configuration, from settings to detection rules and custom properties, and presents it in one readable place, with a record of who changed what and when. It is always read-only, so you get visibility and an audit trail without ever touching what the SIEM protects.

Each source is governed from entry to update to decommission, by step-by-step assistant or by API, behind a simple approval workflow with role-based access tied to Active Directory and Entra ID.

Key features

Live registry

Admin-defined properties on every log source, maintained without technical intervention.

Coverage blind spots

Correlates CMDB assets with log sources so the assets sending nothing surface by name.

Read-only SIEM visibility

Configuration and detection rules visible with change history, never modified.

Built-in assistant

Natural-language answers from real registry data, fully offline or online.

Lifecycle governance

Entry, update, and decommission by assistant or API, always under approval.

Role-based access

Tied to your Active Directory and Entra ID groups.

Searchable audit trail

Every change on record, with duplicate and inconsistency detection.

Integrates with what you already have

If it exposes an API, Alpaca can integrate it.

What Alpaca gets you

See your real coverage

Correlate assets with log sources and surface the blind spots before they become incidents, not after.

Read-only by design

Full visibility and a searchable audit trail across log sources and SIEM config, without ever touching what the SIEM protects.

Your data stays yours

Built for critical, heavily-regulated environments, with a fully offline assistant and local models for data sovereignty.

How it works

1
Connect & collect

Plug Alpaca into the systems you already run, from CMDB to your SIEM, over their APIs.

2
Enrich & govern

Define your own properties and manage each source through an approval workflow.

3
Correlate coverage

Cross assets with log sources to reveal exactly what is covered and what is exposed.

4
Ask & act

Query in plain language and push decisions into Jira or your existing workflows.

Ready to see Alpaca in action?

Tell us about your SIEM estate and we will walk you through Alpaca on real data.