Important Information from
Regarding Your IT Security
Important Information from
Regarding Your IT Security

Newsletter: Everyone's talking about SIEM—and so are we!

Enterprise-grade security that fits even SME budgets: Our SIEM makes it possible.

What exactly is a SIEM?

All devices connected to a network log all tasks in one or more log files.

A SIEM (Security Information and Event Management) system can process logs from a wide range of device and system categories.

The following structured overview lists typical devices whose logs can be read and analyzed by a SIEM.

All of these devices are potential points of vulnerability in a network:

Safety equipment
  • Firewalls (e.g., Cisco ASA, Palo Alto, Fortinet)
  • Intrusion Detection/Prevention Systems (IDS/IPS) (e.g., Snort, Suricata)
  • VPN gateways
  • Web Application Firewalls (WAFs)
  • Antivirus/antimalware systems
  • Endpoint Detection and Response (EDR)
  • Router
  • Switches
  • Load Balancer
  • Wireless Access Points
  • Network Access Control (NAC)
  • Windows, Linux, and macOS clients
  • Mobile devices (MDM systems)
  • IoT devices (depending on the protocol and logging capabilities)
  • Windows Server (Event Logs)
  • Linux/Unix Servers (Syslog, Auditd)
  • Active Directory / LDAP
  • DNS server
  • DHCP server
  • Mail server
  • Microsoft 365 / Azure
  • AWS CloudTrail / CloudWatch
  • Google Cloud Platform (GCP)
  • Cloud security tools (e.g., Prisma Cloud, Defender for Cloud)
  • Web servers (Apache, Nginx, IIS)
  • Databases (SQL Server, Oracle, MySQL, PostgreSQL)
  • Application servers (Tomcat, JBoss)
  • SIEM-compatible business applications (e.g., SAP, Salesforce)
  • Virtualization platforms (VMware, Hyper-V)
  • Container orchestration (Kubernetes, Docker)
  • Patch management systems
  • Backup and Recovery Systems
  • Threat Intelligence Feeds
  • Security Orchestration, Automation, and Response (SOAR)
  • Vulnerability scanners (e.g., Nessus, Qualys)

All logs are “naturally” stored in various formats on their respective devices, so they must be “normalized” into a uniform format. Once all the normalized logs are stored in a database, the database can be searched for anomalies.

Example: It is certainly not normal for an employee in financial accounting to log in to her computer at 1:00 a.m. -> The user login was logged in the log file, sent to the SIEM, and analyzed. The use case on the SIEM—“send an alert when administrative staff log in to a PC at night (10:00 PM – 5:00 AM)”—will now trigger an alert.

Faster detection - Fewer false alarms

A SIEM transforms the chaos of alerts into correlated and easily understandable information. Fewer false positives and more context enable faster threat detection and mitigation. In the fight against cyber attackers, every minute counts when it comes to protecting critical infrastructure and ensuring business continuity.

Combination of SIEM and NDR

A SIEM covers all devices, so the only thing missing now is monitoring the network traffic.

Network Detection and Response (NDR) refers to security solutions that continuously monitor and analyze network traffic to detect suspicious activity and respond to it automatically. Artificial intelligence (AI) and machine learning (ML) techniques are used to analyze network traffic and detect anomalies.

Example: If a large amount of data is suddenly exchanged between a database server and a computer in the finance department at 1:00 a.m., it can be assumed that this is not normal. In this case, the AI will interrupt the connection, provided that this is specified in the rules.

Top 10 SIEM Use Cases

Below, we have provided a detailed explanation of 10 use cases for our SIEM system to illustrate the benefits of such a system.

Ensure that you have a use case and a workflow in place to detect all attempts to compromise user credentials through brute force, pass-the-hash, golden ticket, or other methods. In the event of a successful compromise, it is important to identify the affected users and systems in order to assess the impact and prevent further damage.

Establish appropriate rules for flagging critical events, such as unauthorized changes to configurations or the deletion of audit trails. These changes should be escalated immediately to prevent damage and minimize further risks, as the manipulation of audit logs, for example, is always a warning sign.

Privileged users, such as system or database administrators, have advanced access privileges. This makes them an attractive target for hackers. With a SIEM solution, analysts can closely monitor all actions taken by these privileged users and look for unusual behavior that could indicate a threat or a compromise.

Cloud computing offers numerous advantages, but it also presents several challenges: meeting new compliance requirements, improving user monitoring and access control, and preventing potential malware infections and data breaches. A SIEM solution should also support cloud-based applications as log data sources—such as Salesforce, Office 365, or AWS—to extend compliance monitoring and threat detection to the cloud environment.

Phishing is an attempt to obtain sensitive information that can be used for identity fraud and identity theft. This includes attempts to obtain personal data such as Social Security numbers, bank account information, PIN codes, or passwords. Companies must ensure under all circumstances that this confidential information is protected throughout the organization. Phishing, particularly spear phishing, is frequently used to gain initial access to a network.

When phishing emails are received, analysts can use SIEM to track who received them, clicked on the links they contained, or replied to the emails, enabling them to take immediate action to minimize the damage.

With a SIEM system, appropriate correlation rules, and alerts, it is possible to continuously monitor the utilization, availability, and response times of various servers and services. This allows for the early detection of disruptions and overloads, thereby preventing downtime and the associated costs.

Ensure that you have a use case and a workflow in place to detect all attempts to compromise user credentials through brute force, pass-the-hash, golden ticket, or other methods. In the event of a successful compromise, it is important to identify the affected users and systems in order to assess the impact and prevent further damage.

Companies are subject to a wide range of compliance regulations, such as GDPR, HIPAA, and PCI. With a SIEM system, you can document when and by whom data was accessed, read, or copied, in order to meet compliance requirements and prevent violations.

The process of actively searching for cyber risks within a company or network is known as “threat hunting.” This search for threats can be conducted in response to a security issue or to detect new and unknown attacks or security breaches. “Threat hunting” requires access to security information from all areas of a company. A SIEM solution can provide this.

A SIEM solution automates threat detection activities and serves as the foundation for an automated response to security incidents. Forwarding security alerts and events to LogPoint SOAR enables an even faster response to security incidents by automating manual tasks. This not only boosts SOC productivity but also reduces costs. Start using LogPoint SOAR for one analyst free of charge as part of your SIEM license today.

What We Offer

Our solution partner, Logpoint, has become one of the largest providers of SIEM and NDR in Europe. As a Danish company, it complies with all European compliance regulations.

We can make it easier for our customers to get started with SIEM technology because we are able to offer individual licenses at €40 per month per device. Since implementing a SIEM is a long-term, ongoing process, this approach allows customers to roll it out one device at a time without having to purchase dozens of licenses that cannot be used right away.

We can also handle the hosting of log data for you, so your company doesn't have to make a significant investment in hardware.

And with our expertise, we’ll quickly help your company become more secure against cyberattacks.

Would you like to receive more information about IT security?

Then why not get in touch with our experts?

csm nicolas roesener e35f74755d
Nikolas Rösener
Security Expert