Lumi Loglake is now generally available in Imply Lumi

Sep 13, 2026
Matt Morrissey

Search unstructured logs in place in your data lake

 

Today we’re announcing the general availability of Lumi Loglake, which lets Lumi search unstructured logs directly in data lakes via SPL and SQL without needing any schema management, data catalogs, or rehydration. 

Loglake versus alternatives

For a deeper look at how Loglake differs from other approaches, please see:

Point Lumi at your logs.  Start querying.

Loglake is designed to work with all popular data lakes including  Amazon S3, Google Cloud Storage, Azure Cloud Storage, and more. Logs can be fully unstructured, or organized in data catalogs such as Apache Iceberg or Delta Lake. Logs can also be in any format such as text, Parquet, JSON, and GZIP.

It’s really as simple as pointing Lumi at your logs and querying your data.  For the first time, security teams are not forced to first rehydrate, index, catalog, and model the data.  Loglake fully supports schema-on-read, so there’s no need for predefined schemas, separate data catalogs, or data pipelines before an investigation can kick off.

For Splunk teams specifically, SOC analysts can search their data lake with standard SPL, and results come back as native Splunk events.  Existing dashboards, alerts, detections, and applications, including Splunk Enterprise Security and Splunk SOAR, continue to work whether the data is indexed in Lumi or queried directly in object storage.

Historical and investigative searches also run on separate, on-demand compute pools. So a burst of investigative activity doesn’t eat into the resources real-time monitoring depends on.  This means analysts can dig through months or years of data without slowing down the detections that are critical for protecting the business.

Put simply: you keep more telemetry in a cost-efficient data lake, and you search it right where it sits instead of moving or prepping it first. Your team keeps using the tools and workflows it already knows. And because compute scales independently, real-time monitoring, investigations, and AI workloads can all run at their own pace without competing for the same resources.

Loglake: query first.  Optimize later.

Logs aren’t static business data. Formats shift, fields evolve, and new sources show up whether you planned for them or not.  During an investigation, you rarely know ahead of time which fields are going to matter.

Loglake takes the opposite approach from “prepare, then search.” Lumi applies schema at query time, so teams can search first, reconstruct context on the fly, and optimize later only if a workload actually calls for it. A log format changing doesn’t have to trigger another round of schema maintenance or pipeline rework.

That same access layer spans indexed data and data sitting in object storage. Splunk teams can use SPL across both, and the underlying data can also support Grafana, Databricks, SQL-based tools, and AI applications. (For more, see A First Look at Lumi Loglake: Query Logs Where They Live.)

Keep more data.  Make it all useful.

A security data lake shouldn’t turn into just another archive. Its value comes from making more data available to analysts, detections, and AI agents without forcing anyone to move it, prepare it in advance, or give up the tools they already rely on.

With Loglake, Lumi queries security data where it actually lives and returns results through the interfaces your team already uses. Your logs stay economical to retain without becoming second-class data.

Headed to Splunk .conf this year? Stop by the Imply Lumi Lounge on September 15 to see Loglake in action, catch live Lumi demos, and talk with Imply’s technical experts. You’ll also hear how BTG Pactual cut security data costs by more than 70% without replacing Splunk. Food and drinks are on us!  We’re set up directly across from the Colorado Convention Center.

RSVP for the Imply Lumi Lounge

Other blogs you might find interesting

No records found...
Jul 24, 2026

Why You Shouldn’t Have to Delete Your VPC Flow Logs

When a security incident happens, investigators almost always start with the same questions: Which systems communicated? Where did the traffic originate? What changed before the incident? Was data exfiltrated?...

Learn More

Ready to decouple your observability stack?
No workflow changes. No migrations. More data, less spend.

Request a Demo