Kafka Broker and Streams Enhancements
Why CISOs Are Building Open Security Lakes with Iceberg

Why CISOs Are Building Open Security Lakes with Iceberg

3/16/2026 · William LaForest

What this post added

This post details how Confluent's data streaming platform, including Freight clusters, WarpStream, and Tableflow, enables the creation of 'Open Security Lakes' using Apache Iceberg. It explains the architectural shift from traditional SIEMs to a decoupled model where data streaming handles ingestion and routing, and Iceberg manages storage for forensic data. The post highlights the cost-effectiveness of Freight clusters for high-throughput logging and WarpStream's BYOC model. It also discusses the integration with Apache Flink for real-time threat detection and the use of Tableflow to convert Kafka topics into Iceberg tables with minimal friction.

Read the original post ↗