siftd

query engine (SQE)

app for splunk

Build real-time connections between your Splunk deployment and other data sources

SiftD Query Engine App Icon

federate query across a variety of connected data providers

Better manage and use an increasingly broad spectrum of data platform tools across the observability and security domains. It facilitates federating query operations across a variety of connected data providers and offers APIs optimized for AI and automation driven querying, as well as support for extracting a holistic view of your observability data and its relationships with your underlying infrastructure and services.

Cost Effective

No Impact on Splunk License

Easy to Deploy & Manage

Install App on Search Head Tier

features

Maximum Flexibility Icon

Maximum Flexibility

Focusing on time series data, SQE is engineered to function seamlessly in customer-managed environments and as a cloud-hosted Software as a Service.

Integrate with Ease Icon

Integrate With Ease

SQE supports a wide array of downstream data providers and is natively searchable with platforms that allow query time connections to external APIs.

Speaks Natively Icon

Speaks Natively

Multi-language support covering SQL-based languages, SPL for Splunk, LogQL for Grafana Loki, and PromQL for metrics.

Robust Management & Control

Robust Management & Control

Advanced data connection management with robust Role-Based Access Control (RBAC) to ensure data access is properly scoped to end user roles.

Maximize Interoperability Icon

Maximize Interoperability

Field normalization and semantic mappings to enhance data interoperability across different systems.

Built For Speed Icon

Built for Speed

Built-in caching to optimize query processing speed.

Own Your Data Icon

Own your Data

SQE does not store your data, it facilitates federating query operations across connected data providers.

Monitor & Optimize Icon

Monitor & Optimize

Usage analytics to monitor and optimize aggregate query performance.

SQE integrations

Build real-time connections between your Splunk deployment and other tooling and data sources

Azure Monitor Integration
Azure Monitor
Amazon Cloud Watch Integration
Amazon Cloud Watch
Data Dog Integration
Datadog
Google Cloud Logging Integration
Google Cloud Logging
Prometheus PromQL Integration
Prometheus PromQL
Kubernetes Integration
Kubernetes
Grafana Loki Integration
Grafana Loki
Jenkins Integration
Jenkins
GitHub Integration
Github
Circle CL Integration Coming Soon
CircleCL
Elastic Search Integration Coming Soon
ElasticSearch
Launch Darkly Integration Coming Soon
Launch Darkly
Contact Us for SQE Custom Integrations
Custom Integrations