Every event, with the network context it happened in.
Collect and correlate logs from routers, firewalls, OLTs and identity systems, then resolve each alert to the port, circuit and customer it affects.
- Device
- RTR-MAN-01
- Port
- xe-1/0/3
- Circuit
- CCT-LL-00419
- Service
- L2 Ethernet 1G
- Customers
- 3 business · 1,284 FTTP
One UK endpoint for every source
Syslog, CEF, NetFlow, agents and cloud APIs land in one searchable store. Sources are recognised against the inventory as they arrive, so a log line already knows which device and site it came from.
- Syslog, CEF, NetFlow and IPFIX, agents and APIs
- Parsing for major network and security vendors
- Retention per plan, hot search throughout
- Source health and heartbeat monitoring
Rules that understand topology
Correlate across sources and time, enrich with threat intelligence, and write rules that reference the network: the same source hitting two sites, or a change made on a device outside its change window.
- Cross-source correlation with tunable windows
- Threat intelligence matching on IPs, domains and hashes
- Rules that reference inventory attributes
- Test new rules against historical data
From alert to ticket to action in one screen
Every alert opens with the affected services and customers already listed. Raise the ticket, notify on-call and isolate a port without leaving the page.
- Impact list on every alert
- Teams, Slack, PagerDuty and email notifications
- One click to a service-desk ticket
- Runbook actions with approval where needed
Evidence collected as part of normal operations
Reports mapped to Cyber Essentials, ISO 27001 and UK GDPR are generated from the same log store and the same change history, so audit preparation is a download rather than a project.
- Cyber Essentials and ISO 27001 control packs
- Access, change and incident reports
- Scheduled exports for auditors
- Retention and deletion evidence
An alert that already knows who it affects
Correlated events are matched by IP, hostname or interface to the inventory record, then followed through the dependency graph to the services and customers behind them. No lookups, no second tool.
Integrations
[PLACEHOLDER: confirm supported list]Questions SOC teams ask
How do we get logs to Netcosm?
Point syslog at a UK endpoint, or run a lightweight forwarder where you need buffering or TLS. Cloud sources connect over their APIs. Nothing is installed on your network devices.
How long are logs retained?
Thirty days on Essentials, twelve months on Operator, and custom retention on Enterprise. Hot search covers the whole period. [PLACEHOLDER: confirm retention tiers]
Can we use the SIEM without the inventory?
Yes. SIEM-only plans are available on request. Events are still enriched with whatever inventory you choose to record.
Which frameworks do the compliance packs cover?
Cyber Essentials and Cyber Essentials Plus, ISO/IEC 27001 Annex A logging and monitoring controls, and UK GDPR breach evidence. [PLACEHOLDER: confirm list]
Where is the data processed?
All log data is ingested, stored and searched in UK regions. [PLACEHOLDER: confirm provider and region]
Can our SOC write their own rules?
Yes. Correlation rules are editable, versioned and testable against historical data before they go live.
Send us a day of logs
We load a sample into a demo tenant and show you what correlates, and who it would have affected.