Frequently Asked Questions
License Policy & Common
How is the license fee calculated?
- A. It is calculated based on the daily log collection volume (GB/day). (e.g., 2GB, 5GB, 10GB per day)
It can be flexibly expanded by adding servers when needed.
💡 While other products charge based on data volume, leading to skyrocketing costs as usage increases,
SecuLayer is designed to match the initial scale and allows for easy cost prediction by expanding as needed.
Is it a perpetual license or an annual subscription?
- We offer a perpetual license policy.
There are no annual renewal costs, resulting in a lower total cost of ownership (TCO) in the long term.
You can receive technical support for minor upgrades through a maintenance (technical support) contract.
Do you support both on-premises and cloud?
- We support both On-Premises and Cloud (MS Azure·AWS) environments, and hybrid configurations are also possible.
We offer optimized configurations for public institutions and financial organizations that require network separation.
Is POC (Proof of Concept) support or a separate demo available?
- Yes, it is available. We provide POC and demo tailored to the client's environment, and our dedicated sales and technical engineers will assist throughout the process.
Please contact us to discuss the schedule and scope.
📞 (contact@seculayer.com / TEL 1800-6713)
Is it possible to purchase through the Korea Procurement Service's G2B system?
Yes, it is registered with the Korea Procurement Service's G2B system.
As the number one solution in the public market for SIEM·SOAR, public institutions can conveniently purchase through procurement contracts.
https://digitalmall.g2b.go.kr/ > Search for SecureLayer
What OS and DBMS do you use?
- The operating system used is Oracle Linux. Data management operates in two structures.
① Log data storage — A proprietary file index-based search engine is used, and the security layer does not store logs in a separate commercial database.
Logs are stored and processed using a file indexing structure through a high-speed search engine based on Lucene, allowing for fast real-time search and analysis of large volumes of logs.
② Auxiliary data management — MariaDB is used for managing auxiliary operational data such as statistical data and configuration information.
Is it possible to integrate with cloud services (AWS, Azure, GCP)?
- We provide integration with various types of cloud services.
- Collection of logs stored in AWS S3 storage
- Integration with CloudWatch information API for log collection
- Support for collecting logs from security devices such as our own firewall and WAF
- Registration completed on KT Cloud and NHN Marketplace / Future plans for multi-cloud registration both domestically and internationally.
Are there measures to prevent log loss?
- A. We provide three safety mechanisms at the system level.
① Alarm function for uncollected data
② File storage and processing after communication in each module segment - allows for normal collection even in case of system failure
③ Automatic retransmission function after network momentary disconnection or recovery from failure
Is it possible to view the original logs without decompressing them?
- Indexed compressed area: Can be viewed immediately without any separate decompression process (no speed degradation)
- Long-term storage original log area: Decompression → re-indexing required for viewing (additional processing needed)
How is the report provided?
- Statistics are provided in the form of top statistics and lists, and the content of the data can be customized.
Changes to the format and layout can be made through separate customization development.
What are the criteria for determining the hardware (HDD) for 1-year original log storage?
- The hardware is determined based on the capacity required for collecting original logs. We design and configure hardware to suit various scales, ranging from 2GB to over 100GB.
How do you analyze MITRE ATT&CK?
- By classifying detected events within the MITRE ATT&CK framework, it provides insights that can help prevent potential future attacks based on scenarios.