SIEM & security monitoring with real-time correlation
Reference client: Logistics and trading group in Tyrol, Austria · ~100 employees · 4 sites
Customer data in copy and images has been neutralised.
Starting point
Firewall, email gateway, Microsoft 365, endpoint protection, phone system, cameras, servers, switches — every system diligently generates logs. But no one ever read them: scattered across a dozen consoles, each with its own login, its own interface, and its own alert behavior.
Anomalies were noticed when something was broken — not when it was starting to break. And a group of around 100 employees is simply too small for a dedicated security team.
Solution
A central SIEM was set up on the company's own infrastructure: a lean log pipeline accepts syslog, GELF and API data from around 30 systems — from Microsoft 365 and endpoint security through Proxmox clusters, switches and UPS units to the phone system.
On top of it sits a custom-built monitoring layer: around 60 monitors and real-time correlation rules check every 30 seconds for patterns such as brute-force attempts, impossible sign-in locations or expiring certificates. Scoring, deduplication and prioritization are rule-based — only what requires action gets delivered; a local language model is on call for deep analysis of individual incidents.
Relevant alerts go out immediately as push and email to the people responsible; everything lower-priority is collected into a digest twice a day.
Outcome
Around seven million events per day now flow through the pipeline — read by machines, not by people. Seconds, not chance, separate an event from an alert.
Security incidents, failed backups or storage filling up are noticed before they become a problem — without additional staff and without licence costs for a cloud SIEM.



Similar problem?
Tell us what you're planning — a short call clarifies whether it pays off.
senn-tech