it-service@brocent.com
SOC Log Management
Log source coverage, ingestion volume, detection and triage performance, incident outcomes and retention position for the August 2026 reporting period.
No security incident this period; two blind spots remain in log coverage
The platform ingested 41.2 GB from fourteen log sources and raised 63 alerts, of which 11 were escalated for analyst investigation. All eleven were resolved as benign or as expected administrative activity; no security incident was declared and no client escalation was required. Mean time to detect was 7 minutes and mean time to triage 34 minutes, both inside their targets.
Two log sources are still not integrated: the two access switches, which lack a syslog destination, and three macOS endpoints whose agent predates the current log schema. Together these leave the Shenzhen access layer and part of the research fleet outside detection. Retention is 90 days hot and 12 months cold, which meets the current requirement but is short of the seven years applied to business records elsewhere in the estate.
Monitoring position for the period
A falling alert count with a stable escalation rate is a tuning result, not a reduction in vigilance: 18 alerts fewer than July came from suppressing three known-benign patterns that were confirmed over two periods.
Four items require action
Evidence. Neither access switch has a syslog destination configured. One is a period behind on firmware and one is out of vendor support, which is also why the Configuration Management report proposes its replacement.
Impact. Port-level changes, authentication failures and configuration edits on those switches produce no record anywhere. An attacker with physical or management access to the Shenzhen access layer would leave no trace.
Recommendation. Configure syslog forwarding on the supported switch this month; include log forwarding in the acceptance criteria for the replacement of the unsupported one.
Evidence. Three research Macs report endpoint protection status but do not forward process, authentication or file-access events. The agent upgrade requires a restart the users have deferred, the same devices flagged in the Configuration Management report.
Impact. Detection on those devices is limited to what the protection product itself reports; behavioural detections built on process and authentication telemetry do not apply.
Recommendation. Upgrade the agent during the September restart window agreed for the patch deferral cap, then confirm event flow for three consecutive days.
Evidence. Security logs are held 90 days searchable and 12 months in cold storage. Mailbox and document records are held seven years. There is no written statement of the required log retention period.
Impact. An investigation into activity older than twelve months — a plausible window for a regulatory query or a departed-employee dispute — would have no log evidence to draw on.
Recommendation. Agree a documented retention period for security logs. BCS recommends 90 days hot and 24 months cold as a proportionate position, and will quote the storage difference.
Evidence. Firewall log delivery stopped for eleven minutes on 2026-08-22 during a scheduled reboot. The gap was found on review rather than raised at the time, because the silence alarm triggers at fifteen minutes.
Recommendation. Reduce the log-silence threshold to five minutes for perimeter sources, keeping fifteen minutes for endpoints to avoid noise from laptops that sleep.
Entra ID sign-in and audit logs were onboarded on 2026-08-05, closing the July finding and adding the detections that identified all three risky sign-ins this period. Three rules producing repeated benign alerts — backup service authentication, scanner SMB access and the nightly patch reboot — were tuned with documented suppression, cutting alert volume 22% without loss of coverage.
Five of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Critical alert acknowledged | ≤ 15 minutes | 6 min worst | MET | 2 critical alerts in period |
| High alert triaged | ≤ 1 hour | 34 min avg | MET | 11 escalations |
| Client notification of incident | ≤ 30 minutes | n/a | MET | No incident declared |
| Log ingestion availability | ≥ 99.5% | 99.97% | MET | One 11-minute gap |
| Monthly report issued | By 5th working day | 3rd working day | MET | Issued 2026-09-03 |
Three-period movement
| Metric | Jun 2026 | Jul 2026 | Aug 2026 | Direction of travel |
|---|---|---|---|---|
| Log sources connected | 12/16 | 13/16 | 14/16 | Improving; remaining two are the access switches. |
| Ingested volume | 34.6 GB | 38.1 GB | 41.2 GB | Rising with new sources, not with noise. |
| Alerts raised | 74 | 81 | 63 | Down after rule tuning; escalation rate steady. |
| True-positive rate | 9% | 12% | 17% | Improving signal quality — fewer, better alerts. |
| Mean time to detect | 12 min | 9 min | 7 min | Improving as identity detections came online. |
| Mean time to triage | 58 min | 45 min | 34 min | Improving; playbooks now cover the top five alert types. |
Bars are scaled to the largest category (24). Identity dominates because sign-in telemetry is the richest source in a cloud-first estate — and because it only came online this period.
Log source coverage
| Source | Type | Volume | Events | Status | Latency | Note |
|---|---|---|---|---|---|---|
| Entra ID sign-in | Identity | 6.4 GB | 1.9 M | OK | < 2 min | Onboarded 2026-08-05 |
| Entra ID audit | Identity | 1.1 GB | 0.3 M | OK | < 2 min | Onboarded 2026-08-05 |
| Endpoint protection | Endpoint | 9.3 GB | 4.2 M | PARTIAL | < 5 min | 32 of 35 devices |
| Windows security log | Endpoint | 7.2 GB | 3.1 M | OK | < 5 min | 30 of 30 Windows |
| Firewall HA pair | Perimeter | 8.9 GB | 6.7 M | OK | < 1 min | One 11-min gap 08-22 |
| Core switches | Network | 1.4 GB | 0.8 M | OK | < 1 min | Both core switches |
| Access switches | Network | — | 0 | MISSING | — | No syslog destination |
| Wireless controller | Network | 0.9 GB | 0.5 M | OK | < 2 min | All 6 access points |
| Exchange Online | 2.6 GB | 1.1 M | OK | < 10 min | Message trace and audit | |
| SharePoint / OneDrive | Collab | 1.3 GB | 0.6 M | OK | < 10 min | File and sharing events |
| File server | Server | 0.8 GB | 0.4 M | OK | < 5 min | Object access auditing on |
| Application server | Server | 0.4 GB | 0.2 M | OK | < 5 min | Security log only |
| Cloud infrastructure | Cloud | 0.3 GB | 0.1 M | OK | < 5 min | Control-plane audit |
| Backup platform | Platform | 0.1 GB | 0.05 M | OK | < 5 min | Job and deletion events |
| NAS | Storage | — | 0 | MISSING | — | Syslog available; to schedule |
| VPN gateway | Perimeter | 0.5 GB | 0.2 M | OK | < 1 min | Authentication and session |
Fourteen of sixteen sources are connected. The two missing are the access switches and the NAS; the NAS supports syslog and is scheduled for September, which will bring coverage to 15 of 16 before the switch replacement.
Escalated alerts and outcomes
| Ref | Date | Detection | Severity | Triage | Outcome |
|---|---|---|---|---|---|
| AL-2211 | 2026-08-03 | Impossible travel sign-in | HIGH | 21 min | Benign — staff travel to Singapore, confirmed with the user. |
| AL-2218 | 2026-08-07 | Password spray from one ASN | CRITICAL | 6 min | Blocked by legacy-auth policy; no account affected. Source range blocked. |
| AL-2224 | 2026-08-11 | Mass file access on share | HIGH | 33 min | Benign — scheduled research data migration by the SZ team. |
| AL-2231 | 2026-08-14 | Suspicious PowerShell chain | HIGH | 28 min | Benign — BCS patch script; signature added to the allow list. |
| AL-2237 | 2026-08-17 | New inbox forwarding rule | HIGH | 17 min | Benign — internal rule to a colleague; user confirmed intent. |
| AL-2242 | 2026-08-19 | Privileged role activation | MEDIUM | 44 min | Expected — matched a change record for the account review. |
| AL-2249 | 2026-08-22 | Log source silent | MEDIUM | On review | Firewall reboot; 11-minute gap below the alarm threshold — see finding. |
| AL-2253 | 2026-08-24 | Impossible travel sign-in | HIGH | 19 min | Benign — VPN exit node change, corroborated by device telemetry. |
| AL-2258 | 2026-08-26 | Credential-harvest link clicked | CRITICAL | 5 min | Link blocked at click; no credential entered. User briefed; mail purged tenant-wide. |
| AL-2263 | 2026-08-28 | USB mass storage attached | MEDIUM | 51 min | Research Mac on the stale USB exception — see Configuration report. |
| AL-2269 | 2026-08-31 | Failed MFA burst, one user | HIGH | 26 min | Benign — handset replacement; user re-enrolled with the authenticator app. |
Open items carried between periods
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| SOC-R01 | Network access layer unmonitored — 2 switches send no logs | HIGH | BCS Support Center | 2026-09-30 | In progress | Configure syslog on the supported switch; require it for the replacement. |
| SOC-R02 | Three endpoints without behavioural telemetry — agent predates the schema | MEDIUM | BCS Support Center | 2026-09-30 | In progress | Upgrade during the September restart window; verify 3 days of events. |
| SOC-R03 | No documented log retention requirement — 12 months versus 7-year records | MEDIUM | Client COO | 2026-10-31 | Open | Agree the retention period; BCS to quote 24-month cold storage. |
| SOC-R04 | NAS not forwarding logs — storage access not monitored | MEDIUM | BCS Support Center | 2026-09-30 | Open | Enable syslog forwarding and build a share-access detection. |
| SOC-R05 | Log-silence threshold too permissive — gaps under 15 minutes unnoticed | LOW | BCS Support Center | 2026-09-30 | Open | Reduce to 5 minutes for perimeter sources. |
| SOC-R06 | No incident response exercise in 12 months — playbooks untested with the client | MEDIUM | Client COO + BCS | 2026-12-31 | Open | Run a tabletop exercise alongside the Q4 disaster-recovery test. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Onboard the NAS and the supported access switch, taking coverage to 15 of 16. | Agree the security log retention period. |
| Upgrade the three macOS agents and confirm behavioural event flow. | Approve the September restart window for the research Macs. |
| Reduce the perimeter log-silence threshold to five minutes. | Nominate participants for the Q4 incident response tabletop. |
| Report true-positive rate and triage time by alert category each period. | Confirm the out-of-hours escalation contact list remains current. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| SIEM ingestion metrics | 2026-09-01 01:00 HKT | 16 sources | Volume, event count, latency, silence gaps per source. |
| Alert and case records | 2026-09-01 01:20 HKT | 63 alerts | Severity, detection category, triage time, outcome. |
| Detection rule inventory | 2026-09-01 | 96 rules | Tuning changes, suppressions, coverage by category. |
| Retention configuration | 2026-09-01 | 2 tiers | Hot and cold retention verification. |
| Service desk escalations | 2026-08-31 | 11 cases | Client-facing communication and closure evidence. |
Method and definitions
Mean time to detect is measured from the event timestamp at the source to alert creation in the platform, so it includes ingestion latency. It is not measured from the analyst opening the case, which would flatter the figure.
True-positive rate is the share of alerts that described real, unexpected activity requiring action or a decision. Alerts confirmed as expected administrative activity count as false positives even though the detection worked correctly, because from the client's perspective they are noise.
Incident is declared when confirmed unauthorised access, data loss or service disruption from a security cause is established. No incident was declared this period; the two critical alerts were blocked before impact and are reported as alerts, not incidents.
Exclusions. Vulnerability and patch state are reported in the Patch Management report; endpoint configuration in the Configuration Management report. Application-level audit logs inside the accounting and market-data systems are not forwarded and are outside the monitoring scope.
This copy is an anonymised sample prepared for illustration. The client name, hostnames, user identifiers, alert references and source network addresses have been replaced with fictitious or generic values; volumes, ratios, dates and findings reflect a representative monitored estate. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
Questions clients ask about this report
Coverage of every log source with volume and latency, every alert with its severity and outcome, and mean time to detect and triage measured from the source event timestamp — not from the moment an analyst opened the case, which would flatter the figure.
Because a blind spot is the finding. The sample report names two unmonitored access switches and three endpoints without behavioural telemetry, with owners and dates, rather than presenting coverage as complete.
Ninety days searchable and twelve months in cold storage by default. Where a firm's records policy is longer we recommend and quote a longer cold tier, and report the gap until it is decided.
See what your own SOC Log Management report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.