Straight answer

Hunts read five kinds of data most teams already collect: SIEM data, endpoint telemetry, identity provider logs, cloud logs, and data lakes or object storage. For a buyer the question is which of these a tool can query where they sit, and which it needs copied first.

Where does the data already live?

Most security teams already store the data a hunt needs. It usually sits in five kinds of platform, each with its own owner and budget:

  1. The SIEM: the central store many teams use for security logs, alerting, compliance and retention. Splunk, Microsoft Sentinel, Google SecOps, Elastic and CrowdStrike NG-SIEM are examples named on the vendor pages we reviewed. In every tool on this site the SIEM is one of the platforms read or connected to.
  2. Endpoint telemetry: process, file and network activity from laptops and servers, collected by EDR products such as CrowdStrike Falcon, Microsoft Defender and SentinelOne.
  3. Identity provider logs: sign-ins, MFA prompts, and group and privilege changes from services such as Okta and Microsoft Entra. Many hunts for credential theft start here.
  4. Cloud logs: audit and control-plane records from cloud providers, such as AWS CloudTrail.
  5. Data lakes and object storage: large volumes of raw data in platforms such as Snowflake and Databricks, or in object stores such as S3.

Query in place, or copy first?

A hunting tool can reach that data in two ways. It can send queries to each platform where the data already sits and combine the results, which vendors call federated search or querying data where it lives. Or it can copy the data into its own store first, through an ingestion pipeline: forwarding, parsing and storage work that someone has to build and run.

Both are legitimate designs, and some vendors mix them. Artemis Security states that hot-path data is ingested while high-volume data is queried where it lives, and its connector page says which is which. Mars Security, Anvilogic and Vega describe querying data in place without ingestion. Nebulock describes fetching data just in time through federated search.

Why does this site weight data reach highest?

This site answers one buyer question: Which tool turns new threat intelligence into hunts and detections across the data you already have, without building a new ingestion pipeline? For that question, how much of your existing data a tool can reach in place matters most, so data reach without new ingestion carries 25% of the weighted figure. A tool that names the platforms it queries scores higher than one that states the idea in general terms, because a buyer can check a named list against their own.

What does querying in place change, and what does it not?

Querying in place means no second copy of the data and no second retention period to manage. It does not make queries free: they run on the compute of the platform that holds the data. It also leaves each platform doing its existing job. Mars Security's hunting guide puts it this way: "The SIEM keeps its compliance and retention jobs."

When you compare tools, list your own platforms and ask each vendor, platform by platform, whether it is queried in place, ingested or not supported. Reading a vendor connector page, in the Buying track, shows how.

Related

Editorial assessment · Desk research from public vendor material, last reviewed September 2026