Skip to main content
Home Migration

Prove It Before You Move

A 14-day validation pilot on your own cluster, then a 30-day migration that runs in parallel with your existing SIEM until detection parity is proven.

Replacing a SIEM is the change most security teams postpone, because the failure mode is invisible: you find out what you lost the next time something gets through. So we do not ask you to switch. We ask you to run both, compare them against your own historic telemetry, and deprecate the incumbent only once the evidence is in.

The 14-Day Sovereignty Validation Pilot

Three steps, no commitment, and every measurement taken against your own data rather than a vendor benchmark.

Step 1

Architecture Review

A 60-minute technical session mapping your current third-party SaaS dependencies against your NIS2 and DORA obligations, so the gaps are named before anything is deployed.

Step 2

Private Sandbox Pilot

We provision an isolated, pre-populated Umbra instance on your private cluster. Your analysts test the 93+ UI views and put your existing detection rules through Sigma translation.

Step 3

Fixed-Scope Live Test

Ingest live telemetry from one isolated network segment, OT or corporate, and measure throughput, query speed, and storage footprint against your real volumes.

Non-Disruptive 30-Day Migration

Your existing platform keeps running throughout. Legacy ingestion is deprecated in the final phase, after parity has been demonstrated, not before.

Days 1 – 7

Phase 1: Dual Ingestion

  • Deploy Umbra via Helm, Docker, or bare metal
  • Mirror syslog and event streams in parallel
  • Zero disruption to active SOC operations
Days 8 – 14

Phase 2: Logic Translation

  • Automated translation of Splunk SPL and Sentinel KQL
  • Ingest 468+ pre-mapped Sigma detection rules
  • Connect LDAP, Active Directory, and identity connectors
Days 15 – 30

Phase 3: Validation & Cutover

  • Verify detection parity across historic telemetry
  • Activate automated containment playbooks
  • Deprecate legacy SaaS ingestion and terminate egress

Your detection content moves with you

Years of tuned SPL and KQL are usually the single biggest reason a SIEM replacement stalls. Umbra imports them directly through native Sigma translation, so the logic your team wrote survives the move. Multi-SIEM federation also means Splunk, QRadar, or Sentinel can remain in place indefinitely alongside Umbra if you would rather not consolidate at all.

What We Migrate From

The common starting points, and what changes on the other side.

Splunk

SPL searches and saved detections translate natively. The variable per-gigabyte bill becomes a fixed annual licence, so you can turn the dropped log sources back on.

Microsoft Sentinel

KQL analytics rules import directly. Ingestion, retention, and Logic App run charges collapse into a single figure, and the CLOUD Act exposure goes with them.

QRadar & Elastic

Federate rather than rip out. Umbra queries an existing deployment in place while you migrate at your own pace, or indefinitely if that suits the estate better.

Migration Questions

Will the migration disrupt our SOC?

No. The first phase mirrors your syslog and event streams so both platforms ingest in parallel. Your existing SIEM keeps running and your analysts keep working in it until detection parity has been verified against historic telemetry. Nothing is deprecated until you have evidence that the replacement catches what the incumbent caught.

What happens to our existing Splunk or Sentinel detection rules?

They are translated automatically. Umbra SIEM includes native Sigma translation and imports legacy Splunk SPL and Microsoft Sentinel KQL rules directly, alongside 468+ pre-mapped Sigma detection rules. Years of tuned detection logic move with you rather than being rewritten from scratch.

How long does a migration actually take?

Thirty days for a standard enterprise estate: seven days of parallel dual ingestion, seven days of detection logic translation and identity integration, then sixteen days of validation before cutover. Larger or more heavily customised estates are scoped individually during the architecture review.

Can we test the platform before committing to a migration?

Yes. The 14-day sovereignty validation pilot provisions a pre-populated, isolated Umbra instance on your own private cluster. You test the interface and Sigma translation, then ingest live telemetry from a bounded network segment and measure throughput, query speed, and storage footprint against your real data.

Do you need access to our environment to run the pilot?

The instance runs on your infrastructure and there is no outbound telemetry channel. Where you want our engineers involved directly, access is scoped, time-bound, and recorded through SinonVPN's identity-aware bastion. Where you would rather run it yourself, we support your team through the deployment instead.

What does the migration cost?

Migration support is scoped alongside the licence and quoted as a fixed figure, not billed by the hour against an open-ended project. The architecture review establishes the scope before any number is put forward. Licence pricing itself is published in full on our pricing page.

Can we run Umbra alongside our existing SIEM permanently?

Yes. Multi-SIEM federation is a supported end state, not just a migration stage. Umbra federates queries across Splunk, QRadar, and Sentinel, which is often the right answer where a business unit or region has a platform commitment that is not yours to unwind.

What if we are air-gapped or running OT/ICS networks?

That is a supported configuration rather than an exception. The platform deploys without WAN access and includes direct OT, ICS, and SCADA network forensics. Threat intelligence updates can be delivered through a controlled one-way import where no network path exists.

Start With Sixty Minutes

The architecture review costs nothing and commits you to nothing. It maps your current dependencies against your obligations and tells you whether a migration is worth your time at all.

Book an Architecture Review Read the Compliance Detail