Also known as: SIEM Data Pipeline, Telemetry Pipeline
The controlled flow that collects, parses, normalizes, enriches, filters, and routes security telemetry before a SIEM stores or analyzes it.
A security data pipeline is the sequence of work between a source and the SIEM. It collects events, parses their structure, normalizes fields, adds context, filters low-value records, and routes the resulting telemetry to the right security or storage system.
The pipeline determines whether a detection or AI investigation receives complete, timely, and understandable data. A listed connector is not enough if parsing fails, timestamps drift, identity fields disappear, or a source stops sending without an alert.
Pipeline health is part of security coverage. A detection platform cannot analyze data it never received or could not interpret.