Hydrolix launches Splunk app to extend hot telemetry retention
Hydrolix has launched Hydrolix Search for Splunk in the Splunk app store, giving security teams a way to query 15+ months of complete telemetry directly from Splunk. The app targets SIEM retention gaps that can leave analysts blind during active investigations, especially for high-volume CDN and edge logs.
Why it matters: - Security teams often have to choose between retaining enough telemetry for investigations and staying within SIEM budgets. - Hydrolix Search for Splunk is aimed at closing that gap by keeping high-volume data hot and searchable for longer periods. - The app is designed to help analysts investigate credential stuffing, bot activity, token reuse, and reconnaissance that can fall outside short retention windows.
What happened: - Hydrolix announced Hydrolix Search for Splunk on June 16, 2026. - The app is now available in the Splunk app store. - The release lets analysts search complete telemetry directly from the Splunk interface using standard SPL queries. - Hydrolix says the app extends access to 15+ months of unsampled telemetry, including CDN logs and other high-volume sources.
The details: - Hydrolix positions the product as a hot data fabric alongside Splunk, storing high-volume telemetry outside Splunk while executing SPL searches against that data from Splunk. - The platform keeps every event and field stored exactly as it arrived, with no cold storage tier and no rehydration delay. - Queries return in seconds across petabytes of data, whether the data is from yesterday or 15 months ago. - Analysts can keep using the SPL queries, dashboards, and detections already in place. - Hydrolix says organizations can see up to 10x lower total cost of ownership than retaining the same data inside Splunk alone. - The initial release includes HTTP streaming for massive result sets, native summary table integration, and in-app schema discovery with hdxdescribe. - HTTP streaming is designed to progressively return large investigative results and reduce timeouts and memory failures. - Native summary tables support column inference, aggregation, sub-second performance on petabyte-scale datasets, and filtering on pre-aggregated data. - hdxdescribe lets analysts browse tables and schemas inside the Splunk interface without external documentation.
Between the lines: - The launch reflects a broader SIEM pain point: data retention gets treated as a storage problem, but it can become an investigation problem when analysts need older telemetry fast. - Hydrolix is not trying to replace Splunk. The product is built to extend Splunk’s reach by changing where data lives and how quickly it can be queried. - The value proposition is strongest for teams handling CDN, web, network, and infrastructure logs at scale, where ingesting everything into a traditional SIEM is often too expensive.
What's next: - Hydrolix says security teams can connect with a Hydrolix solutions engineer at hydrolix.io to see the app in action. - The company is targeting CISOs, SOC leaders, analysts, and threat hunters who need longer-horizon access to searchable telemetry. - Organizations using Splunk can adopt the app without retraining analysts or rebuilding workflows.
The bottom line: - Hydrolix is trying to make Splunk investigations behave more like a long-retention data platform, without forcing teams to abandon existing workflows.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Journal of Business News
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.