Straight answer
On a vendor page, 'no ingestion' usually means the tool sends queries to the platforms where your data already lives instead of copying that data into its own store. The wording differs by vendor, and some vendors ingest part of the data and query the rest. Check it source by source against your own platforms.
Why this matters for the question this site asks
This site compares tools for one buyer question: which tool turns new threat intelligence into hunts and detections across the data a team already has, without building a new ingestion pipeline. That is why "Data reach without new ingestion" carries the largest weight, 25%, in our matrix. The claim matters, so it is worth reading closely.
The SIEM is part of that existing data. In the tools below, the SIEM is one of the platforms queried or connected to. None of these claims is about removing it.
How five vendors word it
Mars Security says it works across existing tools "without replacing them or ingesting data", and describes hunting "across every log source, cloud, and endpoint without moving a byte". Its September 2026 press release names the sources: CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, Snowflake and Databricks. Its hunting guide adds that "The SIEM keeps its compliance and retention jobs."
Anvilogic describes "One query across Splunk, Snowflake, Sentinel, S3, and more, without moving the data", and its platform page lists augment, standalone or combined deployment on top of your storage layer.
Vega states "No migration, ingestion, or egress" and describes federated analytics that query every source in place. Its public connectors page does not name platforms.
Nebulock describes its Helix federated search as getting data "just-in-time, not just-in-case".
Artemis Security takes a mixed approach and says so: "Hot-path data ingested, high-volume data queried where it lives." Its connector page lists which platforms are ingested and which are queried in place.
What the wording cannot tell you
A phrase on a home page does not say which of your platforms are covered, how fresh the results are, or who pays for the queries. A tool that queries a data lake in place runs that query on the lake's compute. Anvilogic's public cost calculator, for example, estimates data-lake compute and storage costs and notes that its savings figures do not include Anvilogic's own licence.
A mixed model is not a weakness in itself. Artemis publishes its split, which lets a buyer see exactly what is copied. The point is to know the split for your own estate.
Five checks before you sign
- List your platforms and ask for each one: queried in place, ingested, or not supported. Use your list, not the vendor's logo wall.
- Ask which platform executes each query and how query volume is limited.
- Ask whether any normalization, forwarding rule or new storage is needed before the first hunt.
- Ask what happens to results: are hit events copied into the vendor's store, and for how long are they kept?
- Ask for a trial or proof of concept on one real source, and time the first hunt from connection to result.
How we score it
We score data reach from what vendors publish. Named platforms and a clear statement about ingestion score higher than general claims. The reasons for each score are on the matrix and in each head-to-head, such as Mars Security vs Vega.
Sources
- https://marssec.ai
- https://securityboulevard.com/2026/09/mars-security-launches-real-time-intel-to-detection-engine-that-turns-live-threat-intelligence-into-backtested-detections-in-minutes/
- https://marssec.ai/guides/ai-threat-hunting
- https://www.anvilogic.com/
- https://www.anvilogic.com/platform
- https://www.anvilogic.com/calculator
- https://www.vega.io/
- https://vega.io/platform/connectors
- https://nebulock.io/platform
- https://artemissecurity.com/platform/overview/
- https://artemissecurity.com/connectors/
Editorial assessment · Desk research from public vendor material, last reviewed September 2026