Skip to content
esc

Type to search across the entire site.

Tenzir Documentation

Tenzir is the data pipeline engine for security teams. Collect, transform, enrich, and route your telemetry—all in one place.

The docs serve different jobs. Find yours.

Pick your role

Security architects

  1. Try the quickstart

    Deploy a demo node with a few clicks and explore live security data.

  2. Understand pipelines

    The execution model behind everything: operators, dataflow, and storage.

  3. See the platform architecture

    How nodes, the platform, and the app relate, and what runs where.

  4. Pick a deployment model

    Cloud-hosted, on-premises, or air-gapped: choose what fits your constraints.

  5. Browse the solutions

    SIEM cost optimization, OCSF normalization, security data lakes, and more.

Data engineers

  1. Learn the data lifecycle

    One log line through all thirteen stages, from collection to replay.

  2. Learn idiomatic TQL

    Write pipelines that read like the data flows.

  3. Collect from anywhere

    Files, network streams, APIs, data stores, and message brokers.

  4. Reshape events

    Flatten, nest, rename, and restructure records on the fly.

  5. Route to Splunk, S3, and your lakehouse

    Split-route one stream to multiple destinations, each in its native format.

Detection engineers

  1. Map events to OCSF

    Normalize first so detections write once and run everywhere.

  2. Match events with TQL

    Write detections in TQL and turn matches into OCSF Detection Findings.

  3. Enrich with threat intelligence

    Correlate events against indicator feeds as they stream through.

  4. Plot data with charts

    Turn any pipeline into a bar, line, area, or pie chart.

  5. Build a dashboard

    Pin your charts into shared dashboards for the whole team.

Platform operators

  1. Install a node

    Docker, Linux packages, or cloud images: get a node running anywhere.

  2. Configure and size a node

    Configuration files, TLS, and sizing guidance for production workloads.

  3. Run the platform yourself

    Self-host the platform with your own storage, database, and identity provider.

  4. Treat configuration as code

    How settings, secrets, and pipelines stay declarative and reviewable.

  5. Onboard a data source

    Take one log line to an installable package of operators and tests.

The documentation follows the Diataxis framework, with four entry points by material type.