logo

Go jump in a lake: Data storage for the win

ID: a37a53b0-a62f-5a6f-a8eb-90272808345e

STIX ID: report--a37a53b0-a62f-5a6f-a8eb-90272808345e

Feed Name: Red Canary

Date Published: 2026-01-08

Date Updated: 2026-04-29

Author: Brian Davis

...
...

This blog explains how to reduce SIEM costs and improve scalability by using a data lake architecture built on columnar storage (Parquet), Apache Iceberg tables and catalogs, and distributed querying with Apache Spark. It outlines benefits such as compression, faster columnar searches, decoupled storage/compute, and large-scale querying, highlights consumption-based cost risks, and provides a high-level roadmap for building a data lake across ingest, store, process/analyze, and explore/visualize phases, with examples and tooling options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.