What is Affinity
RoleAnalyst | AdministratorRead6 min
Affinity takes your security logs from raw ingestion to incident response in a single platform: ingestion, normalization, detection, alerting, and investigation.
What it's for
Affinity is a managed security operations (SIEM) platform. It centralizes the logs from your cloud infrastructure and applications, normalizes them to a common schema, and lets you detect threats, investigate with SQL, and respond to incidents from a single console. The infrastructure is operated by Solidarity Labs, so your team focuses on detecting and responding instead of maintaining servers.
Value proposition
| Benefit | What you get |
|---|---|
| Unified visibility | Logs from AWS, Google Workspace, GitHub, and Azure normalized in one investigation workspace. |
| SQL search | Query millions of events with Presto SQL, with an editor and a visual query builder. |
| Continuous detection | Scheduled SQL rules that generate actionable alerts with severity and context. |
| Alerts and triage | Manage alerts with statuses, owners, and end-to-end traceability. |
| Incident response | Extract and enrich IOCs, and query them directly in your logs. |
| Notifications | Automatic alerts to Slack, Discord, Telegram, or Jira when a rule fires. |
How Affinity works
- 1. Connect your sources. Create integrations over S3 or API and Affinity ingests the logs continuously.
- 2. Normalize to OCSF. Each event is mapped to the OCSF schema (Open Cybersecurity Schema Framework), so fields like
actor_user_name,src_endpoint_ip, oractivity_namemean the same thing across all your sources. - 3. Store and query. Data is stored in a columnar format (parquet) and queried with Presto SQL.
- 4. Detect threats. Your detection rules evaluate the data on defined intervals and raise alerts when there are matches.
- 5. Investigate and respond. Alerts are sent to the channel you choose and are investigated in Logs or in Incident Response.
Data sources you can connect
- AWS: CloudTrail, VPC Flow, WAF, ALB, GuardDuty, and RDS audit, among others.
- Google Workspace: Login, Drive, Token, Admin, and Alert Center.
- GitHub: organization and enterprise audit logs.
- Azure: Log Analytics queries.
- Your own sources: any S3 origin through a custom integration.
Who Affinity is for
- Analysts: investigate alerts and logs, and coordinate incident response.
- Administrators: manage integrations, detection rules, notifications, and users.
- Built for teams that need modern SIEM capabilities without operating the infrastructure themselves.
- After signing in you land on Security Alerts (
/alerts-view), your daily starting point.