SOLUTIONS·WHAT XERJ REPLACES

ONE PLATFORM.
SEVEN WORKLOADS.

XERJ ships one binary. Different teams use it differently — SIEM analysts run one query surface, RAG platform teams run another, observability SREs run a third. Same engine, same API, same bill.

SEVEN SOLUTIONS·PICK THE ONE THAT FITS
01 · SECURITY ANALYTICS SIEM AT
AI SPEED.
SIEM queries run in milliseconds instead of seconds. Exact, pre-computed terms aggregations over millions of events. Agents triage tier-1 without budget-burn. MTTD drops. FOR CISO · SOC LEAD
SUB-SECOND SIEM TOP-N OVER MILLIONS OF EVENTS
AGGREGATIONS OFTEN 10×+ FASTER vs LIVE ES 8.13.4 · REPRODUCIBLE
EXPLORE SECURITY ANALYTICS →
02 · AI SEARCH & RAG HYBRID.
ONE QUERY.
BM25 + kNN in one process. SQ8 gives int8 scoring precision. Native RRF · no orchestrator · LangChain and LlamaIndex work unchanged. FOR CDO · CAIO · AI PLATFORM
HYBRID BM25 + kNN · NATIVE RRF
INT8 SCORING PRECISION · SQ8 OPT-IN
EXPLORE AI SEARCH & RAG →
03 · UNIFIED OBSERVABILITY 6 → 1
SYSTEMS.
Logs, metrics, traces on one data plane. OTLP in · Prometheus out · ES Bulk in. Replaces Splunk + Prometheus + Tempo + Loki + Mimir. FOR SRE · PLATFORM · OBSERVABILITY LEAD
80 K DOCS/S SUSTAINED INGEST
3 QUERY LANGUAGES → 1
EXPLORE UNIFIED OBSERVABILITY →
04 · ELASTICSEARCH REPLACEMENT DROP-IN.
MODERN RUNTIME.
Same clients, same DSL, same _bulk API. 1.72× faster bulk ingest, 1.61× smaller on disk, sub-second start, ~36 MB binary. Migration is a config change, not a rewrite. FOR VP ENG · CTO · PLATFORM
1.72× FASTER BULK INGEST · 1.61× SMALLER ON DISK
~36 MB STATIC BINARY (NO JVM) vs ~620 MB JAR+JRE
vs LIVE ES 8.13.4 · REPRODUCIBLE SCORECARD
EXPLORE ES REPLACEMENT →
05 · OPERATIONAL INTELLIGENCE INGEST +
QUERY.
80 K events/sec sustained ingest AND millisecond terms aggregations on the same node. Lock-free readers mean flush never blocks your on-call agent. FOR SRE · DEVOPS · PLATFORM
LINE-RATE INGEST · MS TERMS AGGS ON ONE NODE
~1.2× SMALLER ON DISK THAN ES (MEASURED) · 85 MB PER 1 M EVENTS
EXPLORE OPS INTELLIGENCE →
06 · AI SECURITY REVIEW AUDIT CODE
TOO BIG TO READ.
An AI agent indexes a codebase as queryable facts — call sites, call graph, sanitizer order — then reads only the survivors. WordPress core: the structured audit summed to ~26K tokens vs ~5.2M just to load the tree once. FOR CISO · APPSEC · SECURITY RESEARCH
619K LINES INDEXED IN ≈3.6 S · 100% PARSE RATE
SINK-CENSUS COVERAGE PROVEN · UNEXPLAINED RESIDUAL 0
EXPLORE AI SECURITY REVIEW →
ONE PLATFORM·SEVEN WORKLOADS

SAME ENGINE.
DIFFERENT LENSES.

The seven solutions above are not separate products. They are lenses onto one platform. Most enterprise customers run two or three of the deployed lenses simultaneously on the same binary, the same segment cache, and the same audit trail. (Semantic analytics is the exception on that list: it is a query-shape demonstration on a generated corpus, not a deployment.)

XERJ one binary one segment cache one WAL one audit trail FTS INDEX SIEM · keyword search · ES replacement VECTOR INDEX RAG · agent memory · recommendations COLUMNAR LOGS observability · operational intelligence AGENT MEMORY session-scoped retrieval · time-decay · token-aware EXPLAIN-PLAN audit · capacity · cost · model-risk evidence CODE FACTS AI security review · call sites · call graph · invariant fingerprints SEMANTIC SLICE semantic analytics · aggregations over the retrieved top-k · exact buckets ONE CONTRACT · ONE ON-CALL · ONE SOC 2 SCOPE · ONE RBAC MODEL every lens above runs on the same binary, same audit trail, same RBAC
BROWSE BY INDUSTRY