Spectra
Telemetry & SIEM routing
Collect local OTel and route it to the cloud or your SIEM.
The signal layer. Spectra gathers OpenTelemetry from every Beacon (policy decisions, MCP activity, inventory) and routes it to Observatory or straight into your Elastic/Kibana SIEM.
- OpenTelemetry-native collection from the whole fleet.
- Route to Alyria Cloud or a customer SIEM (Elastic/Kibana), your choice.
- Correlation and trajectory detection feed the ADR pillar.
Agent activity that never reaches your SIEM is activity you can't detect on.
Your SOC runs on the SIEM. But AI-agent decisions, MCP calls, and endpoint inventory live in a tool that doesn't speak to it, so the agent layer is invisible to the detections and correlation rules you already trust. You need agent activity in the same pipeline as everything else you watch.
The questions your reviewers will ask.
“Agent activity isn’t in my SIEM.”
Spectra emits OpenTelemetry from every Beacon: policy decisions, MCP activity, and inventory.
“I don’t want another proprietary agent.”
It is OpenTelemetry-native, so there is no proprietary format and no lock-in.
“I already run Elastic and Kibana.”
Route the signal to Observatory or straight into your own SIEM, your choice.
“I need to catch escalation, not single events.”
Cross-endpoint trajectory and correlation feed detection, not just isolated log lines.
“It has to fit my pipeline.”
Spectra sits beside whatever collector and SIEM you already run.
Evidence, not assurances.
What a security leader walks away able to demonstrate to a board or an auditor.
- Agent-layer signal in the same SIEM your SOC already watches.
- Standard OpenTelemetry your team already knows how to route and retain.
- Correlated trajectories, not just isolated log lines.
- Format
- OpenTelemetry
- Destinations
- Observatory or your SIEM (Elastic / Kibana)
- Signal
- Policy decisions, MCP activity, inventory
- Fit
- Coexists with existing collectors
One module of the Alyria platform.
Spectra works alongside the rest of Alyria — prevention and detection for every AI agent your people run, tied together by one policy engine and one signed audit chain.
Put Spectra to work.
Deploy Beacon read-only and see how Spectra fits at the endpoint, under your keys.