Start here
How this site fits together.
There's a lot of research here, and it isn't obvious on a first visit where to begin or how the pieces connect, so this page is the reading order. The short version is that the site makes one argument, backs it with evidence you can check, and then goes deep in whichever direction your question points — and claims are labeled by how strong their evidence is, because separating what's measured from what's claimed is most of the point.
If you only have ten minutes, read the thesis and skim one benchmark on the lab page. Everything else is depth on demand.
The map: claim, evidence, depth.
The core sections play one of three roles. The thesis states the claim; the matrix, the lab, and the research notebook carry the evidence for and against it; and the writing catalog plus the reference architecture are the depth, where the argument gets worked out topic by topic. Engagements sits apart, because it isn't research: it's the same method applied to your environment.
A first visit in three moves.
- 1
Read the thesis, the argument that security at scale uses modern data architecture, and the three properties it holds every platform to: trustworthy, well-connected, and performant. It's a short read, and the rest of the site hangs off it.
- 2
Check the evidence: first-party benchmarks with methods and raw results posted, plus a cost model you can run against your own numbers. The Matrix is the scoring instrument behind the platform evaluations, and the research notebook keeps the open questions and the contradictions on the record, because an argument you can't check is just marketing.
- 3
Go deep where your question lives, in the essay catalog, which is organized as ten pillars in dependency order, from storage formats up through detection engineering and economics, and each pillar marks its own "start here" essay so you can enter mid-stack without reading everything above it.
If you came with a specific question.
Four three-essay reading paths, each built to answer one question a security data team actually asks, so you can read three pieces instead of eighty.
Leaving Splunk without breaking detections
The cost case, the migration trap most teams walk into, and what the timeline actually costs.
Whether you can trust your data
The quietest failures in security data — the parsing layer, and the measurement problem underneath it.
Picking the query engine
Where each engine wins, from petabyte-scale detection down to an analyst's laptop.
When hunting becomes data science
The path threat hunters are already on, made reproducible.
Start where your question is.
The full case, and the three properties it holds every platform to, trustworthy, well-connected, and performant.
The scoring method and the scored tables behind the evaluations, both public, with the applied per-environment read the part you hire me for.
First-party benchmarks I ran myself, with the methods and raw results posted so you can check them.
Working hypotheses and the contradictions against them, tracked in the open while the questions are still live.
Longer pieces sorted by topic, for when you would rather read the thinking in full.
If you want to put this to work, start here, from a scoped assessment through a full build.