Cyber operations SIEM

Security Information and Event Management (SIEM) System

A platform that collects, normalises and correlates logs from across the entire information system, turning millions of discrete events into a small number of alerts worth human review.

Highlights

What sets it apart.

01

Collects logs from network devices, servers, applications and security devices

02

Normalises data into a common format for cross-correlation between sources

03

Detection rules customised to the specific systems of each organisation

04

Log retention for post-incident investigation and compliance requirements

Overview

Security Information and Event Management (SIEM) System

The problem SIEM solves

Every device in a system keeps its own logs, in its own format. A real attack rarely leaves a complete trail on a single device — the traces are scattered across firewalls, authentication servers, workstations and applications. SIEM gathers these scattered fragments, normalises them into a common language, and then finds the connections between them.

What determines effectiveness

  • Log source coverage — if a device does not send logs, SIEM cannot see it
  • Quality of detection rules — default rules rarely suit the specifics of each system
  • Handling of false alerts — a poorly configured SIEM generates so many alerts that the operations team can no longer tell genuine alerts apart

Deployment notes

Choosing log sources requires balancing coverage against storage costs. NST surveys the existing system architecture to set the order of priority for integrating data sources.

Specifications

Technical specifications.

Supported log sources
To be updated
Event ingestion rate
To be updated
Retention period
To be updated
Correlation mechanism
To be updated
Deployment model
To be updated
Scalability
To be updated

Detailed specifications are provided in the official technical documentation. Call +84 912 211 467 for the full version.

Use cases

Where it is deployed.

  1. Detecting attacks through traces left across multiple different systems
  2. Post-incident forensic investigation based on long-term log storage
  3. Meeting regulatory requirements for log recording and retention

Contact

Need a solution for your organisation?

NST’s engineering team is ready to discuss your operational requirements, integration approach and deployment conditions.

Email · [email protected] Monday – Friday, 08:00 – 17:30 (GMT+7)