Every SOC team knows the trade-off. Send everything to the SIEM platform and pay for it. Or filter aggressively and risk missing something. Filter lists are written once, during onboarding. Detection content keeps moving after that.
Smart Engine, the new core of the VirtualMetric DataStream pipeline, takes the guesswork out of that decision. It reduces SIEM ingest using your registered detection rules. An event that no registered detection could match is dropped. An event that survives keeps only the fields the applicable detections read or return.
The problem with traditional filtering
Many log reduction tools work on guesswork. They drop events based on source type, severity labels, or static rules that someone configured once and rarely revisits. The risk is obvious: filter too little and ingest costs stay high, filter too much and a detection silently breaks.
Your detections decide what the SIEM receives
Smart Engine flips the logic. Instead of guessing what might be useful, it reads your actual SIEM detection rules, the ones already running in Microsoft Sentinel, Sigma, or YARA, and asks a simple question for every event: could any of my registered detections ever need this?
If no rule could possibly use an event, it’s dropped. If an event survives, only the fields that the matching detections actually read or return are kept. Everything else is stripped before it ever reaches the SIEM.
This means the filtering logic isn’t invented by VirtualMetric. It’s derived directly from the customer’s own detection content, so coverage never drifts from what the SOC actually monitors for. Through a native Git integration, any changes made to those detection rules are picked up and applied automatically, so the filtering logic stays in sync without manual re-configuration.
Ingest drops over 90%, and detections stay intact
Across production deployments, this approach is routinely delivering more than 90% reduction in the volume of data reaching the SIEM. That translates directly into lower ingest costs, faster query performance, and a lighter operational footprint, without asking a SOC team to gamble on which logs are safe to drop.
Because the engine is built to fail-safe, it never discards an event due to uncertainty. If it encounters a detection rule it cannot fully interpret, it keeps every event that rule could apply to and simply skips reduction for that slice of traffic. The bias is always toward over-keeping, never under-keeping.
Dry-run mode proves the number before you enforce it
Teams don’t have to take the reduction number on faith. Smart Engine can run in a dry-run mode first, marking exactly what it would have dropped or kept without touching a single event. That gives security teams a clear, evidence-based view of the expected savings before enforcing anything in production.
Why this matters beyond cost
SIEM ingest costs are the visible line item. The deeper value is what a clean, detection-aligned data pipeline unlocks next. New log sources onboard faster. Analysts sift through less noise. The normalized data foundation is ready to support agentic AI in the SOC.
Reducing volume while holding detection coverage is what Smart Engine is built to do.
Curious what this looks like against your own detection rules? Get in touch to see Smart Engine applied to your environment.
See VirtualMetric DataStream in action
Start your free trial to experience safer, smarter data routing with full visibility and control.