Skip to content

Logging & SIEM

Operations logging

Centralised syslog, application logs, indexing and long-term retention.

Architecture

Architecture

  1. 01Source
    • syslog
    • journald
    • app logs
    • firewall
  2. 02ShipBuffering and durability
    • Vector
    • rsyslog
    • Filebeat
  3. 03ParseSchema and fields
  4. 04Index
    • OpenSearch
    • Loki
    • Graylog
  5. 05RetainPolicy and archive
    • hot / warm / cold
    • S3 archive
The path of a log line from source to audit trail

Capabilities

Capabilities

Every item is marked: verified production experience, or engineering capability.

Centralised syslog

Proven
  • rsyslog
  • Graylog
  • Vector

Indexing and search

Capability
  • OpenSearch
  • Loki

SIEM correlation

Capability

Detection rules, MITRE ATT&CK-aligned content and response playbooks.

  • Wazuh
  • Sigma rules

Retention policy

Capability

Hot / warm / cold tiers and archive — balancing cost against requirement.

Audit trail

Proven

Who changed what and when — a complete change history.

Network device logging

Proven
  • Cisco
  • Juniper
  • MikroTik
  • FortiGate

Technology stack

Technology stack

Collection
VectorrsyslogFilebeatWazuh agent
Index
OpenSearchLokiGraylog
Analysis
GrafanaOpenSearch Dashboards

Engagement model

Engagement model

Project

A one-off scope: audit, migration or implementation with a fixed outcome.

Retainer

Monthly engineering hours — specialist access on demand.

Co-managed

NetWizard and your in-house team together, with split responsibility.

Tell us about your infrastructure