senn-tech
All references03 · IT

SIEM & security monitoring with real-time correlation

Reference client: Logistics and trading group in Tyrol, Austria · ~100 employees · 4 sites

Customer data in copy and images has been neutralised.

~30integrated systems
~60monitors & correlation rules
~7Mevents per day
30 scorrelation interval

Starting point

Firewall, email gateway, Microsoft 365, endpoint protection, phone system, cameras, servers, switches — every system diligently generates logs. But no one ever read them: scattered across a dozen consoles, each with its own login, its own interface, and its own alert behavior.

Anomalies were noticed when something was broken — not when it was starting to break. And a group of around 100 employees is simply too small for a dedicated security team.

Solution

A central SIEM was set up on the company's own infrastructure: a lean log pipeline accepts syslog, GELF and API data from around 30 systems — from Microsoft 365 and endpoint security through Proxmox clusters, switches and UPS units to the phone system.

On top of it sits a custom-built monitoring layer: around 60 monitors and real-time correlation rules check every 30 seconds for patterns such as brute-force attempts, impossible sign-in locations or expiring certificates. Scoring, deduplication and prioritization are rule-based — only what requires action gets delivered; a local language model is on call for deep analysis of individual incidents.

Relevant alerts go out immediately as push and email to the people responsible; everything lower-priority is collected into a digest twice a day.

VectorVictoriaLogsPostgreSQLRule EnginePush + Mail

Outcome

Around seven million events per day now flow through the pipeline — read by machines, not by people. Seconds, not chance, separate an event from an alert.

Security incidents, failed backups or storage filling up are noticed before they become a problem — without additional staff and without licence costs for a cloud SIEM.

SIEM dashboard with signal cards
Dashboard: all signals and open findings at a glance.
Live log view of the activity center
Activity Center: live logs from all sources with filtering and per-entry analysis.
Analytics with world map and integrity heatmap
Visual analytics: attack origins, security levels and a 30-day integrity heatmap.

Similar problem?

Tell us what you're planning — a short call clarifies whether it pays off.