TL;DR: Security data pipelines are breaking under the weight of logs, alerts, enrichment demands, and SIEM costs, according to TENZIR’s analysis of SecDataOps and open, composable pipeline design. The practical shift is from ingest-everything architectures to dynamic preprocessing, which changes how teams control cost, context, and data ownership.
At a glance
What this is: This is an analysis of SecDataOps, arguing that security teams need DataOps-style pipelines to normalize, enrich, filter, and route security data before it reaches the SIEM.
Why it matters: It matters because SIEM economics, detection fidelity, and operational workload all depend on how well teams govern data flow, especially where identity signals, credentials, and access telemetry intersect with broader security operations.
👉 Read TENZIR's analysis of SecDataOps and security data pipeline design
Context
Security operations often fail at the data layer before they fail at detection. When teams ingest everything into a SIEM and clean it up later, they pay more, investigate slower, and lose flexibility in how security telemetry is shaped for analysis. This article is about that governance gap, not a new detection rule or a better parser.
SecDataOps borrows from DataOps to treat security telemetry as a governed pipeline rather than a storage problem. That has a real identity angle where logs include access events, authentication data, privileged activity, and non-human identity signals, because the quality of those inputs determines whether IAM, PAM, and NHI controls can be analysed at all.
Key questions
Q: How should security teams reduce SIEM costs without creating blind spots?
A: Security teams should move from ingest-everything thinking to governed data routing. Preserve full-fidelity logs for identity, access, and high-risk events, enrich and normalize data before it reaches the SIEM, and keep raw evidence in cheaper storage for audit and replay. The goal is to reduce noise and cost without losing investigative depth.
Q: Why do security graphs matter for IAM and NHI programmes?
A: Security graphs matter because they connect entitlements, behaviours, systems, and data into a single relationship view. That helps teams detect risky access paths, understand blast radius, and automate response decisions with context. Without that relationship layer, identity telemetry stays fragmented and AI has too little structure to make reliable governance decisions.
Q: What breaks when security teams rely on vendor-controlled ingestion models?
A: They usually inherit rigid parsing rules, limited preprocessing options, and higher storage costs. That creates brittle integrations and makes it harder to change how data is enriched or routed as the environment evolves. Over time, the vendor’s ingestion assumptions can become the organisation’s operational constraint.
Q: How can security teams tell whether identity fabric is working?
A: Security teams can tell identity fabric is working when policy intent is enforced consistently, access changes propagate cleanly, and audit evidence can be reconciled across environments. If teams still need manual translation between clouds to understand entitlements or revocation, the fabric is not yet doing its job.
Technical breakdown
Why SIEM-centric ingestion becomes a control problem
A SIEM-centric model assumes the safest option is to collect everything first and decide later what matters. In practice, that pushes normalisation, enrichment, and correlation into expensive post-ingest workflows and creates brittle dependence on vendor-specific parsers. The control problem is not only cost. It is also that critical context arrives too late for efficient triage, and teams cannot easily govern which telemetry is worth retaining, transforming, or forwarding.
Practical implication: move filtering and enrichment upstream so retention, routing, and analytic value are governed before ingestion.
What SecDataOps changes in the security data path
SecDataOps applies pipeline thinking to security telemetry, using modular, as-code workflows to transform data in motion. That means events can be normalised, enriched, correlated, and routed before they land in downstream tools. Open formats such as Apache Arrow also reduce dependence on rigid proprietary ingestion paths. For identity-heavy telemetry, this matters because access, privilege, and service-account signals can be shaped into usable context instead of being flattened into generic log records.
Practical implication: design pipelines that preserve identity context across enrichment, correlation, and forwarding stages.
Why open and interoperable security data matters
Open standards are not just a portability preference. They are a governance mechanism that lets teams move telemetry across analytics, detection, and incident response tools without rebuilding the pipeline each time. Interoperability also reduces the risk that one vendor’s ingestion model becomes the de facto policy boundary for the organisation. For security operations, especially where identity data must support multiple control owners, open pipeline design improves reuse and reduces lock-in.
Practical implication: standardise formats and pipeline interfaces so identity and security telemetry can be reused across tools without re-engineering.
NHI Mgmt Group analysis
SecDataOps is becoming a governance model, not just a tooling pattern. Security teams are no longer deciding only how to ingest more data. They are deciding where to apply control, cost, and context enrichment in the data lifecycle. That shift matters because telemetry quality now influences everything from detection fidelity to identity investigation speed. Practitioners should treat pipeline design as part of security governance, not an engineering afterthought.
Identity telemetry loses value when it is flattened too late in the pipeline. Access logs, authentication records, and privileged activity all lose analytical value when enrichment happens after storage rather than in motion. That is a real issue for IAM and NHI programmes because the most useful signals are often contextual, not raw. Teams that cannot preserve that context will struggle to connect authentication, privilege, and workload behaviour in a defensible way.
Open data fabrics reduce the risk of vendor-controlled analytical blind spots. When one ingestion model dictates how telemetry is shaped, the organisation inherits that vendor’s assumptions about filtering, parsing, and routing. Open and composable pipelines give security teams more control over what data is retained, how it is transformed, and where it is sent. The practical conclusion is simple: control the pipeline, or accept someone else’s policy for your telemetry.
SecDataOps introduces a useful named concept: security data pipeline sprawl. This is the fragmentation that appears when logs, enrichers, parsers, and downstream tools all apply their own transformations independently. The result is duplicated effort, inconsistent context, and a higher chance that identity or threat signals are lost between systems. Practitioners should consolidate transformation logic into governed pipelines with clear ownership.
For identity security, the question is not whether telemetry exists, but whether it remains actionable. A high-volume SIEM feed can still fail IAM and PAM teams if access, privilege, and non-human identity events are not enriched consistently. That makes pipeline governance part of identity governance. Teams should evaluate whether their data path supports investigation, correlation, and auditability before assuming their controls are visible.
What this signals
Security teams should expect more scrutiny of where data is transformed, not just where it is stored. As SecDataOps matures, programme owners will be judged on whether telemetry is usable for investigation and governance before it ever reaches the SIEM, especially where identity and privilege signals must be correlated across tools.
Security data pipeline sprawl: when parsers, enrichers, and routing rules are scattered across multiple systems, identity context degrades and operational cost rises. Teams that want reliable IAM and NHI analysis will need to reduce transformation duplication and make the pipeline auditable end to end.
For practitioners
- Move enrichment upstream Normalize, enrich, and correlate security events before they reach the SIEM so you reduce storage cost and preserve context for downstream identity and threat analysis.
- Define pipeline ownership for identity telemetry Assign clear ownership for authentication, privilege, and non-human identity data flows so the organisation can govern retention, routing, and transformation decisions consistently.
- Standardise on open data formats Use open and interoperable formats such as Apache Arrow where possible so security telemetry can move between analytics, detection, and response tools without re-parsing.
- Reduce transformation sprawl Consolidate custom parsers, ad hoc enrichers, and duplicated routing logic into a small set of governed pipelines that can be tested and audited like code.
Key takeaways
- Security data becomes harder and more expensive to use when teams ingest everything first and govern it later.
- SecDataOps shifts the control point upstream, where normalisation, enrichment, and routing can be managed before telemetry reaches the SIEM.
- Identity programmes benefit when access and privilege signals remain contextual across the full data path, not flattened into generic logs.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.AE-1 | Security data pipeline design affects anomaly detection and event analysis. |
| NIST SP 800-53 Rev 5 | AU-6 | AU-6 aligns with log review and analysis after enrichment and correlation. |
| CIS Controls v8 | CIS-8 , Audit Log Management | This article is about governing log flow, enrichment, and retention. |
| ISO/IEC 27001:2022 | A.8.15 | Logging and monitoring controls apply to pipeline-managed security data. |
Map telemetry pipelines to DE.AE-1 so events stay analyzable before and after ingestion.
Key terms
- SecDataOps: SecDataOps is the application of DataOps principles to security telemetry. It treats logs, alerts, and related event data as a managed pipeline, where enrichment, filtering, correlation, and routing happen in controlled stages rather than after everything lands in a SIEM.
- Security data pipeline: A security data pipeline is the chain that ingests, filters, enriches, normalises, and routes telemetry before it reaches storage or analytics. In practice, it determines which evidence survives into detection, investigation, and compliance workflows, so it is part of the control environment, not just infrastructure plumbing.
- Telemetry Enrichment: Telemetry enrichment is the process of adding context to raw security data so it is more useful for investigation and response. That can include asset, identity, geolocation, or threat intelligence context, but enrichment must be controlled so it does not distort the original evidence record.
- Open Security Data Format: An open security data format is a standardised way to represent and move telemetry without locking it to one vendor’s ingestion model. It helps teams reuse data across tools, preserve interoperability, and reduce the operational friction caused by proprietary parsing and storage layers.
What's in the full article
TENZIR's full article covers the operational detail this post intentionally leaves for the source:
- How TQL is used to compose security data pipelines as code for real operational workflows
- The specific enrichment, filtering, and correlation operators the vendor describes for stream processing
- Examples of how open standards and Apache Arrow are positioned for security data interoperability
- The practical mechanics of routing telemetry to downstream tools while reducing SIEM ingestion volume
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader operational and audit challenges that shape secure programmes.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org