SIEM

Every event, with the network context it happened in.

Collect and correlate logs from routers, firewalls, OLTs and identity systems, then resolve each alert to the port, circuit and customer it affects.

Topology/ North West ring1 critical3 degraded
RTR-MAN-01AGG-LDS-02AGG-PRE-01OLT-SAL-04DWDM-BRAOLT-BOL-02AGG-WIG-03SE 38 97 · 142 nodes · 318 links
CRIT · 14:02:11Brute-force SSH on core router412 auth.fail from 185.220.101.7
RESOLVED TO
Device
RTR-MAN-01
Port
xe-1/0/3
Circuit
CCT-LL-00419
Service
L2 Ethernet 1G
Customers
3 business · 1,284 FTTP
Open ticketIsolate port
Illustrative screen. Sample data.
01 · LOG COLLECTION AND MANAGEMENT

One UK endpoint for every source

Syslog, CEF, NetFlow, agents and cloud APIs land in one searchable store. Sources are recognised against the inventory as they arrive, so a log line already knows which device and site it came from.

  • Syslog, CEF, NetFlow and IPFIX, agents and APIs
  • Parsing for major network and security vendors
  • Retention per plan, hot search throughout
  • Source health and heartbeat monitoring
SIEM · Event timeline · RTR-MAN-01last 15 min · 5 correlated
14:02:11CRITsshd: 412 failed logins from 185.220.101.7xe-1/0/3 · CCT-LL-00419
14:01:58HIGHThreat intel match: Tor exit node185.220.101.7
13:58:40WARNConfig change outside change windowCHG-2231 · not approved
13:52:07INFOBGP session flap, recovered in 4sAS[X] · xe-1/0/0
13:49:12OKLog source heartbeatRTR-MAN-01
02 · CORRELATION AND THREAT DETECTION

Rules that understand topology

Correlate across sources and time, enrich with threat intelligence, and write rules that reference the network: the same source hitting two sites, or a change made on a device outside its change window.

  • Cross-source correlation with tunable windows
  • Threat intelligence matching on IPs, domains and hashes
  • Rules that reference inventory attributes
  • Test new rules against historical data
CCT-LL-00419 · L2 Ethernet 1GMAN ⇄ LDS
SERVICE
[CUSTOMER] HQL2 1G[CUSTOMER] DR
IP/ETH
RTR-MAN-01 xe-1/0/3VLAN 419RTR-LDS-02 xe-0/1/7
DWDM
MUX-MAN-01λ12 1550.12MUX-LDS-02
FIBRE
ODF-MAN-02 T3/F07C-4471 F13ODF-LDS-01 T1/F13
4 layers · 11 resources · 1 customer
03 · ALERTING AND RESPONSE

From alert to ticket to action in one screen

Every alert opens with the affected services and customers already listed. Raise the ticket, notify on-call and isolate a port without leaving the page.

  • Impact list on every alert
  • Teams, Slack, PagerDuty and email notifications
  • One click to a service-desk ticket
  • Runbook actions with approval where needed
CRIT
Loss of signal · C-4471 fibres 13–2414:07:42 · OTDR event at 2.84 km from ODF-MAN-02
SERVICES14
BUSINESS3
PREMISES312
L2 Ethernet 1G · [CUSTOMER A]SLA 4h · breach 17:07
L3 IP transit 1G · [CUSTOMER B]SLA 4h
Backhaul OLT-SAL-04 · 312 FTTP premisesRerouted · protected
L2 Ethernet 100M · [CUSTOMER C]SLA 8h
04 · COMPLIANCE REPORTING

Evidence collected as part of normal operations

Reports mapped to Cyber Essentials, ISO 27001 and UK GDPR are generated from the same log store and the same change history, so audit preparation is a download rather than a project.

  • Cyber Essentials and ISO 27001 control packs
  • Access, change and incident reports
  • Scheduled exports for auditors
  • Retention and deletion evidence
SIEM · Event timeline · RTR-MAN-01last 15 min · 5 correlated
14:02:11CRITsshd: 412 failed logins from 185.220.101.7xe-1/0/3 · CCT-LL-00419
14:01:58HIGHThreat intel match: Tor exit node185.220.101.7
13:58:40WARNConfig change outside change windowCHG-2231 · not approved
13:52:07INFOBGP session flap, recovered in 4sAS[X] · xe-1/0/0
13:49:12OKLog source heartbeatRTR-MAN-01
HOW IT CONNECTS

An alert that already knows who it affects

Correlated events are matched by IP, hostname or interface to the inventory record, then followed through the dependency graph to the services and customers behind them. No lookups, no second tool.

01 · EVENTThreat intel matchTor exit node 185.220.101.7
02 · CORRELATE412 auth.fail in 90sSame source, same target
03 · DEVICERTR-MAN-01Matched on 10.24.8.17
04 · CIRCUITCCT-LL-00419Port xe-1/0/3
05 · IMPACT3 business · 1,284 FTTPFrom the dependency graph
06 · RESPONSEINC-4472 · isolate portTicket and action in one click
SIEM · Event timeline · RTR-MAN-01last 15 min · 5 correlated
14:02:11CRITsshd: 412 failed logins from 185.220.101.7xe-1/0/3 · CCT-LL-00419
14:01:58HIGHThreat intel match: Tor exit node185.220.101.7
13:58:40WARNConfig change outside change windowCHG-2231 · not approved
13:52:07INFOBGP session flap, recovered in 4sAS[X] · xe-1/0/0
13:49:12OKLog source heartbeatRTR-MAN-01

Integrations

[PLACEHOLDER: confirm supported list]
Firewalls and securityFortinet, Palo AltoSyslog · CEFCisco ASA, FirepowerSyslogCrowdStrike, DefenderAPIThreat intel feedsSTIX · TAXII
Network devicesCisco, Juniper, NokiaSyslog · SNMP trapsOLTs and ONTsSyslogNetFlow and IPFIXCollectorsFlowCollector
Identity and endpointsMicrosoft Entra IDAPIActive DirectoryAgentLinux and WindowsAgentOktaAPI
ResponseMicrosoft Teams, SlackAlertsPagerDuty, OpsgenieOn-callJira, ServiceNowTicketsREST API and webhooksOpenAPI 3

Questions SOC teams ask

How do we get logs to Netcosm?

Point syslog at a UK endpoint, or run a lightweight forwarder where you need buffering or TLS. Cloud sources connect over their APIs. Nothing is installed on your network devices.

How long are logs retained?

Thirty days on Essentials, twelve months on Operator, and custom retention on Enterprise. Hot search covers the whole period. [PLACEHOLDER: confirm retention tiers]

Can we use the SIEM without the inventory?

Yes. SIEM-only plans are available on request. Events are still enriched with whatever inventory you choose to record.

Which frameworks do the compliance packs cover?

Cyber Essentials and Cyber Essentials Plus, ISO/IEC 27001 Annex A logging and monitoring controls, and UK GDPR breach evidence. [PLACEHOLDER: confirm list]

Where is the data processed?

All log data is ingested, stored and searched in UK regions. [PLACEHOLDER: confirm provider and region]

Can our SOC write their own rules?

Yes. Correlation rules are editable, versioned and testable against historical data before they go live.

Send us a day of logs

We load a sample into a demo tenant and show you what correlates, and who it would have affected.