
3/16/2026 · William LaForest
What this post added
This post details how Confluent's data streaming platform, including Freight clusters, WarpStream, and Tableflow, enables the creation of 'Open Security Lakes' using Apache Iceberg. It explains the architectural shift from traditional SIEMs to a decoupled model where data streaming handles ingestion and routing, and Iceberg manages storage for forensic data. The post highlights the cost-effectiveness of Freight clusters for high-throughput logging and WarpStream's BYOC model. It also discusses the integration with Apache Flink for real-time threat detection and the use of Tableflow to convert Kafka topics into Iceberg tables with minimal friction.