Security Engineer

What happens when the log format changes?

ARRTECH

For security engineers who run the SIEM

Parsers fail, records stay

Vendors change log formats without notice, and a parser that worked yesterday drops fields today. What matters then is that the raw record is kept, and that the parser is something you can read, chain and fix yourself.

Connector counts don’t tell you what breaks.

Every SIEM lists its integrations. Few say what happens when a vendor changes its format, or who fixes the connector when it does.

The questions that matter are about the mechanism: how a custom source is parsed, how fields are mapped and what a search looks like.

Open to code, on servers you control.

ARRTECH builds software engineers can inspect. Search takes a pipeline of functions, playbooks accept Python, and every product has a REST API.

The stack runs on Linux servers you size and patch, and nothing in it acts without a playbook your team built.

Build one custom source first. Replace nothing.

Start with the source no connector covers. A helper builds a parser from a sample log, and ARRTECH writes one at no charge under support.

You see the parsed fields, the mapping and the query before anything else changes.

Build

How do we onboard a source no connector covers?

The ARRTECH SIEM agent reads databases, WMI, Kafka and Microsoft 365 on remote systems without installing anything there. A helper builds a parser from a sample log, and ARRTECH writes one at no charge under support.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.