SOC / SOC-03
Log collection and SIEM deployment
Centralise useful security events and make them usable for searching, alerting and investigations. The project addresses quality, timestamps, retention and cost as much as platform installation.

WHEN IT HELPS
A focused response
to a defined need.
Scattered or lost logs, need for post-incident investigation, SOC preparation or an expensive platform ingesting too much low-value data.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Sources and objectives
- reliable collection
- timestamps
- parsing
- normalisation
- access control
- retention
- search
- priority alerts
- volume
- recovery and operations
Deliverables
- Collection architecture
- source catalogue
- retention rules
- quality dashboards
- initial searches and alerts
- documentation
- measured capacity and cost model
Acceptance evidence
An end-to-end event is searchable with correct time; source loss or silence is detected; access is restricted; retention follows the contract; baseline volume and cost are measured.
DELIVERY
How the work is structured.
Approach
Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.
Prerequisites & responsibilities
Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.
Scope factors
Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.
Questions to clarify
Which questions must logs answer? What are actual volumes? What retention, access rules and operating budget apply?
IMPORTANT BOUNDARIES
A SIEM is not a SOC team and syslog is not automatically a SIEM. Licenses, retention, performance and storage/transfer charges require separate pricing.
Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company cannot reconstruct suspicious access. Project: centralise identity, firewall and critical-server events. Target outcome: usable chronology for covered systems without claiming to reconstruct events never collected.
Scenario 02
A SOC ingests high-volume, low-use logs. Project: measure sources and select events required by detection use cases. Target outcome: better-controlled costs; removals are assessed to avoid losing useful evidence.
Technology and reference context
Example: Splunk Enterprise Security or another suitable SIEM; syslog/API/agent collection depending on sources and available permissions.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
