MetisShield
MenuClose

Log monitoring

The firewall, the VPN, and any other feed worth keeping.

Managed SIEM is log monitoring we operate. Endpoints are covered by Managed EDR. Identity is covered by Managed ITDR. SIEM is for the other records, and for keeping those records long enough to investigate. Each distinct feed is a log source with a proposed price.

Bundles
Complete. Available beside Essentials or Pro at the per-source price.
Coverage
Continuous automated monitoring, with on-call response
Price status
Proposed — pending validation of hosting and staffing cost

What we watch

  • Sources named in the order: a firewall, a VPN, a line-of-business server, a backup console.
  • Whether a source has gone quiet. A feed that stops sending is itself an alert.
  • Links between a source and an identity alert, when both exist. A suspicious sign-in plus a VPN session is more useful than either alone.

What runs it

  • Wazuh and its OpenSearch-based index. Vector is the pipeline for feeds that are not the endpoint agent.
  • Sigma detections on those logs.
  • Falco where the firm runs Linux or cloud workloads. A Windows-only office is not sold a Falco story.
  • CrowdSec, AdGuard Home, and Coraza with the OWASP core rule set only on paths we actually sit on: our edge, the firm’s DNS if it points at us, or a web path placed in front of us.

What a person does

  • Parses the feed, quiets what is noise, and reviews what is left during published hours.
  • Writes the monthly letter from real cases, not from a dashboard screenshot.
  • Tells you when volume is about to change the price, before the invoice does.

What you decide

  • Name the sources. A source you hope we are watching, but never connected, is not in scope.
  • Keep clocks in sync and logs flowing. We will document the shipper.
  • Accept that retention costs money. The planning figure is 90 days searchable. Longer retention is a written change.

Limits

  • Log monitoring is not a backup, and it is not a compliance certification.
  • We do not charge a SIEM source fee for the tenant already covered by Managed ITDR, unless you want that tenant retained as its own SIEM feed beyond the identity watch. The default proposal does not double-charge it.
  • Endpoint agents are not also billed as SIEM sources.
  • A noisy device can move the hosting cost. The proposed per-source price assumes a modest feed, and we will re-price a loud one before you are stuck with it.

We are not affiliated with or endorsed by the open-source projects named on this page.

The other services

Tell us how the firm is set up.

An assessment is a conversation and a short written note. It is not a penetration test, and it is not a contract. Nothing on this site takes payment.

Book an assessment