0333 032 8979 info@norsoc.com

Advanced  SIEM

Logging and IDS

Retain your endpoint, and network logs for compliance and threat detection

Need advice on network monitoring and why you need log retention?   Click here to book a free security chat with us now!   

Powered By

Keep Your Network Secure

Logging is an important part of your security posture, allowing you to see exactly what is happening on your endpoints, syslog devices and even your network itself.

 

For More Information

Full Network Log Visibility

Logs ingested from endpoints, syslog compatible devices, Office 365 and your network.

Z

Log Retention for Compliance

Standards such as PCI DSS require log retention and monitoring as part of their certification.

No Data Usage Fees

There is only one fixed fee per user! No extra charges for the amount of ingested data.

U

SOC Threat Monitoring

27\7 Security operations threat monitoring alerts you to any anomalies in your network.

g

Intrusion Detection System

Network sensors act as an intrusion detection system, looking out for suspicious network behaviour. 

Can I check my own logs?

Yes you can, but to check logs on all your devices you would need to access each computer manually to search the event logs. You would also need to log into office 365 logging to check this, as well as all your network devices. 

A SIEM collates logs from all of these sources allowing you to view them all in one window. It also analyses the logs to check for any suspect behaviour

Why does it monitor Office 365

Like any system Office 365 logs all events. With a SIEM Rules can be set to monitor for any behavour you may deem odd. For example; a non UK login to a 365 account may be a cause for concern if you have no employees abroad working or on holiday and may be worth checking this out. 

Do I keep control of my 365 account?

Yes, you only authorise our software to access the log data in your account and bring that log data back into our system. At any time you can de authorise the software from your account which stops any further access.

How do I monitor my network traffic

To run the network intrusion detection system (NIDS) you will need a perch sensor. These are a one off extra charge but will be updated and even replaced free of charge once in place. If you have over 10 users licenced with us we will provide a sensor free of charge for the duration of your subscription.

This sits in your network and collects network traffic stats (NOT any actual data) for analysis, and will detect threats moving traffic over your network. 

Is there a cost for the amount of data I use?

No, unlike many other systems that bill you per endpoint, and then bill you again for the amount of logs you ingest per day, perch is licenced per user. There are no extra data fees or charges.