Skip to content

Home Expertise / Security operations

SOC / SOC-03

Log collection and SIEM deployment

Centralise useful security events and make them usable for searching, alerting and investigations. The project addresses quality, timestamps, retention and cost as much as platform installation.

WHEN IT HELPS

A focused response
to a defined need.

Scattered or lost logs, need for post-incident investigation, SOC preparation or an expensive platform ingesting too much low-value data.

AT A GLANCE

Family
Security operations

Engagement
Service or implementation

Reference
SOC-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Sources and objectives
  • reliable collection
  • timestamps
  • parsing
  • normalisation
  • access control
  • retention
  • search
  • priority alerts
  • volume
  • recovery and operations

Deliverables

  • Collection architecture
  • source catalogue
  • retention rules
  • quality dashboards
  • initial searches and alerts
  • documentation
  • measured capacity and cost model

Acceptance evidence

An end-to-end event is searchable with correct time; source loss or silence is detected; access is restricted; retention follows the contract; baseline volume and cost are measured.

DELIVERY

How the work is structured.

Approach

Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.

Prerequisites & responsibilities

Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.

Scope factors

Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.

Questions to clarify

Which questions must logs answer? What are actual volumes? What retention, access rules and operating budget apply?

IMPORTANT BOUNDARIES

A SIEM is not a SOC team and syslog is not automatically a SIEM. Licenses, retention, performance and storage/transfer charges require separate pricing.

Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company cannot reconstruct suspicious access. Project: centralise identity, firewall and critical-server events. Target outcome: usable chronology for covered systems without claiming to reconstruct events never collected.

Scenario 02

A SOC ingests high-volume, low-use logs. Project: measure sources and select events required by detection use cases. Target outcome: better-controlled costs; removals are assessed to avoid losing useful evidence.

Technology and reference context

Example: Splunk Enterprise Security or another suitable SIEM; syslog/API/agent collection depending on sources and available permissions.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.