Cost-Effective Log Management
Scanner has transformed Lemonade's approach to log management by making long-term data retention financially viable. Unlike their previous solution which charged prohibitive fees for accessing historical data, Scanner enables them to retain logs for over a year while maintaining quick access to all historical data.
This has eliminated the need for expensive rehydration fees and provided more predictable cost structures. With Scanner's architecture, Lemonade keeps full data custody in their own S3 buckets, helping them to avoid vendor lock-in.
Enhanced Security Operations
The Lemonade team now uses Scanner daily for both security and operational tasks, leveraging its fast search capabilities to conduct investigations quickly. During security incidents, such as vendor breach notifications, the team can rapidly validate potential threats by checking indicators of compromise against their historical data.
They're also in the process of building a custom detection and response engine that integrates with Scanner, giving them more control over their security infrastructure.
Simplifying Technical Security Work
Due to its search speed, Scanner enables Lemonade's security team to develop deep familiarity with their security data. The platform makes it easier to perform sophisticated investigations and build custom detection rules. Rather than relying on third-party detections, the team can now craft and maintain their own detection libraries based on their unique understanding of their environment.
This hands-on approach helps team members develop intimate knowledge of their systems and data, making them more effective at identifying and troubleshooting complex security issues.
Historical Logs: From Archived to Actionable
Scanner transformed how Lemonade uses their historical log data. While compliance was one key driver for maintaining 12+ months of logs, teams also wanted to leverage this historical data for security insights.
However, the difficulty of rehydrating archived logs into analysis tools meant this valuable data often went unused. With Scanner, Lemonade can now quickly search and analyze over 12 months of logs, making it practical to extract insights that were previously out of reach.
By enabling rapid historical analysis alongside retention requirements, Scanner helps Lemonade realize substantially more value from their archived logs beyond just compliance.
Integration and Implementation
The integration of Scanner into Lemonade's existing infrastructure has been straightforward, with flexible options for log ingestion including Cribl, log forwarding, and Beacon.
The team is currently developing a custom automation engine that integrates with Scanner, demonstrating the platform's adaptability to custom solutions and workflows. Scanner's schemaless search makes Lemonade's security data lake easy to operate.