B BROCENT
Brocent — Your Asia IT Team
BCS Support Center · Hong Kong
it-service@brocent.com
Monthly client report · 08 of 09

SOC Log Management

Log source coverage, ingestion volume, detection and triage performance, incident outcomes and retention position for the August 2026 reporting period.

Client
Acme Capital Limited
Reporting period
2026-08-01 → 08-31
Issued
2026-09-03
Reference
SOC-2026-08
Scope
14 of 16 log sources
Monitoring
24×7 · HK follow-the-sun
Prepared by
BCS Support Center
Classification
Confidential
01 · Executive summary

No security incident this period; two blind spots remain in log coverage

The platform ingested 41.2 GB from fourteen log sources and raised 63 alerts, of which 11 were escalated for analyst investigation. All eleven were resolved as benign or as expected administrative activity; no security incident was declared and no client escalation was required. Mean time to detect was 7 minutes and mean time to triage 34 minutes, both inside their targets.

Two log sources are still not integrated: the two access switches, which lack a syslog destination, and three macOS endpoints whose agent predates the current log schema. Together these leave the Shenzhen access layer and part of the research fleet outside detection. Retention is 90 days hot and 12 months cold, which meets the current requirement but is short of the seven years applied to business records elsewhere in the estate.

Service verdict
On track
All five monitoring service levels were met. No missed alert, no ingestion outage over fifteen minutes, and no unacknowledged escalation. Coverage and retention are tracked as SOC-R01 and SOC-R03.
02 · Key indicators

Monitoring position for the period

Log source coverage
14 /16
▲ +1 vs Jul
Ingested volume
41.2 GB
▲ +3.1 GB
Mean time to detect
7 min
▲ −2 min
Mean time to triage
34 min
▲ −11 min
Alerts raised
63
▼ −18 vs Jul
Escalated to analyst
11
— 17% of alerts
Incidents declared
0
— unchanged
Hot retention
90 d
— +12 mo cold

A falling alert count with a stable escalation rate is a tuning result, not a reduction in vigilance: 18 alerts fewer than July came from suppressing three known-benign patterns that were confirmed over two periods.

03 · Key findings

Four items require action

Two access switches send no logs, leaving the Shenzhen access layer unmonitored · carried forward (2 periods)
HIGH

Evidence. Neither access switch has a syslog destination configured. One is a period behind on firmware and one is out of vendor support, which is also why the Configuration Management report proposes its replacement.

Impact. Port-level changes, authentication failures and configuration edits on those switches produce no record anywhere. An attacker with physical or management access to the Shenzhen access layer would leave no trace.

Recommendation. Configure syslog forwarding on the supported switch this month; include log forwarding in the acceptance criteria for the replacement of the unsupported one.

Owner BCS Support Center Target 2026-09-30 Ref SOC-2026-07-01
Three macOS endpoints run an agent that cannot forward the current log schema
MEDIUM

Evidence. Three research Macs report endpoint protection status but do not forward process, authentication or file-access events. The agent upgrade requires a restart the users have deferred, the same devices flagged in the Configuration Management report.

Impact. Detection on those devices is limited to what the protection product itself reports; behavioural detections built on process and authentication telemetry do not apply.

Recommendation. Upgrade the agent during the September restart window agreed for the patch deferral cap, then confirm event flow for three consecutive days.

Owner BCS Support Center Target 2026-09-30 Ref SOC-2026-08-02
Log retention is shorter than the firm's records retention
MEDIUM

Evidence. Security logs are held 90 days searchable and 12 months in cold storage. Mailbox and document records are held seven years. There is no written statement of the required log retention period.

Impact. An investigation into activity older than twelve months — a plausible window for a regulatory query or a departed-employee dispute — would have no log evidence to draw on.

Recommendation. Agree a documented retention period for security logs. BCS recommends 90 days hot and 24 months cold as a proportionate position, and will quote the storage difference.

Owner Client COO Target 2026-10-31 Ref SOC-2026-08-03
One ingestion gap of eleven minutes was not alerted
LOW

Evidence. Firewall log delivery stopped for eleven minutes on 2026-08-22 during a scheduled reboot. The gap was found on review rather than raised at the time, because the silence alarm triggers at fifteen minutes.

Recommendation. Reduce the log-silence threshold to five minutes for perimeter sources, keeping fifteen minutes for endpoints to avoid noise from laptops that sleep.

Owner BCS Support Center Target 2026-09-30 Ref SOC-2026-08-04
Closed this period · identity logs onboarded and three false-positive rules tuned
RESOLVED

Entra ID sign-in and audit logs were onboarded on 2026-08-05, closing the July finding and adding the detections that identified all three risky sign-ins this period. Three rules producing repeated benign alerts — backup service authentication, scanner SMB access and the nightly patch reboot — were tuned with documented suppression, cutting alert volume 22% without loss of coverage.

04 · Service level attainment

Five of five service levels met

Committed service levelTargetActualStatusNote
Critical alert acknowledged ≤ 15 minutes 6 min worst MET 2 critical alerts in period
High alert triaged ≤ 1 hour 34 min avg MET 11 escalations
Client notification of incident ≤ 30 minutes n/a MET No incident declared
Log ingestion availability ≥ 99.5% 99.97% MET One 11-minute gap
Monthly report issued By 5th working day 3rd working day MET Issued 2026-09-03
05 · Trend

Three-period movement

MetricJun 2026Jul 2026Aug 2026Direction of travel
Log sources connected 12/16 13/16 14/16 Improving; remaining two are the access switches.
Ingested volume 34.6 GB 38.1 GB 41.2 GB Rising with new sources, not with noise.
Alerts raised 74 81 63 Down after rule tuning; escalation rate steady.
True-positive rate 9% 12% 17% Improving signal quality — fewer, better alerts.
Mean time to detect 12 min 9 min 7 min Improving as identity detections came online.
Mean time to triage 58 min 45 min 34 min Improving; playbooks now cover the top five alert types.
Alerts by detection category · 63 in period
Identity & sign-in
24
Endpoint behaviour
15
Perimeter & network
11
Email & collaboration
8
Cloud & SaaS
4
Platform health
1

Bars are scaled to the largest category (24). Identity dominates because sign-in telemetry is the richest source in a cloud-first estate — and because it only came online this period.

06 · Detail data

Log source coverage

SourceTypeVolumeEventsStatusLatencyNote
Entra ID sign-inIdentity6.4 GB1.9 MOK< 2 minOnboarded 2026-08-05
Entra ID auditIdentity1.1 GB0.3 MOK< 2 minOnboarded 2026-08-05
Endpoint protectionEndpoint9.3 GB4.2 MPARTIAL< 5 min32 of 35 devices
Windows security logEndpoint7.2 GB3.1 MOK< 5 min30 of 30 Windows
Firewall HA pairPerimeter8.9 GB6.7 MOK< 1 minOne 11-min gap 08-22
Core switchesNetwork1.4 GB0.8 MOK< 1 minBoth core switches
Access switchesNetwork0MISSINGNo syslog destination
Wireless controllerNetwork0.9 GB0.5 MOK< 2 minAll 6 access points
Exchange OnlineEmail2.6 GB1.1 MOK< 10 minMessage trace and audit
SharePoint / OneDriveCollab1.3 GB0.6 MOK< 10 minFile and sharing events
File serverServer0.8 GB0.4 MOK< 5 minObject access auditing on
Application serverServer0.4 GB0.2 MOK< 5 minSecurity log only
Cloud infrastructureCloud0.3 GB0.1 MOK< 5 minControl-plane audit
Backup platformPlatform0.1 GB0.05 MOK< 5 minJob and deletion events
NASStorage0MISSINGSyslog available; to schedule
VPN gatewayPerimeter0.5 GB0.2 MOK< 1 minAuthentication and session

Fourteen of sixteen sources are connected. The two missing are the access switches and the NAS; the NAS supports syslog and is scheduled for September, which will bring coverage to 15 of 16 before the switch replacement.

Escalated alerts and outcomes

RefDateDetectionSeverityTriageOutcome
AL-22112026-08-03Impossible travel sign-inHIGH21 minBenign — staff travel to Singapore, confirmed with the user.
AL-22182026-08-07Password spray from one ASNCRITICAL6 minBlocked by legacy-auth policy; no account affected. Source range blocked.
AL-22242026-08-11Mass file access on shareHIGH33 minBenign — scheduled research data migration by the SZ team.
AL-22312026-08-14Suspicious PowerShell chainHIGH28 minBenign — BCS patch script; signature added to the allow list.
AL-22372026-08-17New inbox forwarding ruleHIGH17 minBenign — internal rule to a colleague; user confirmed intent.
AL-22422026-08-19Privileged role activationMEDIUM44 minExpected — matched a change record for the account review.
AL-22492026-08-22Log source silentMEDIUMOn reviewFirewall reboot; 11-minute gap below the alarm threshold — see finding.
AL-22532026-08-24Impossible travel sign-inHIGH19 minBenign — VPN exit node change, corroborated by device telemetry.
AL-22582026-08-26Credential-harvest link clickedCRITICAL5 minLink blocked at click; no credential entered. User briefed; mail purged tenant-wide.
AL-22632026-08-28USB mass storage attachedMEDIUM51 minResearch Mac on the stale USB exception — see Configuration report.
AL-22692026-08-31Failed MFA burst, one userHIGH26 minBenign — handset replacement; user re-enrolled with the authenticator app.
07 · Risk register

Open items carried between periods

RefRiskSeverityOwnerDueStatusNext action
SOC-R01 Network access layer unmonitored — 2 switches send no logs HIGH BCS Support Center 2026-09-30 In progress Configure syslog on the supported switch; require it for the replacement.
SOC-R02 Three endpoints without behavioural telemetry — agent predates the schema MEDIUM BCS Support Center 2026-09-30 In progress Upgrade during the September restart window; verify 3 days of events.
SOC-R03 No documented log retention requirement — 12 months versus 7-year records MEDIUM Client COO 2026-10-31 Open Agree the retention period; BCS to quote 24-month cold storage.
SOC-R04 NAS not forwarding logs — storage access not monitored MEDIUM BCS Support Center 2026-09-30 Open Enable syslog forwarding and build a share-access detection.
SOC-R05 Log-silence threshold too permissive — gaps under 15 minutes unnoticed LOW BCS Support Center 2026-09-30 Open Reduce to 5 minutes for perimeter sources.
SOC-R06 No incident response exercise in 12 months — playbooks untested with the client MEDIUM Client COO + BCS 2026-12-31 Open Run a tabletop exercise alongside the Q4 disaster-recovery test.

Next period commitments

BCS Support Center willClient is asked to
Onboard the NAS and the supported access switch, taking coverage to 15 of 16. Agree the security log retention period.
Upgrade the three macOS agents and confirm behavioural event flow. Approve the September restart window for the research Macs.
Reduce the perimeter log-silence threshold to five minutes. Nominate participants for the Q4 incident response tabletop.
Report true-positive rate and triage time by alert category each period. Confirm the out-of-hours escalation contact list remains current.
Appendix · Method and definitions

How this report was produced

SourceExtractedRecordsUsed for
SIEM ingestion metrics 2026-09-01 01:00 HKT 16 sources Volume, event count, latency, silence gaps per source.
Alert and case records 2026-09-01 01:20 HKT 63 alerts Severity, detection category, triage time, outcome.
Detection rule inventory 2026-09-01 96 rules Tuning changes, suppressions, coverage by category.
Retention configuration 2026-09-01 2 tiers Hot and cold retention verification.
Service desk escalations 2026-08-31 11 cases Client-facing communication and closure evidence.

Method and definitions

Mean time to detect is measured from the event timestamp at the source to alert creation in the platform, so it includes ingestion latency. It is not measured from the analyst opening the case, which would flatter the figure.

True-positive rate is the share of alerts that described real, unexpected activity requiring action or a decision. Alerts confirmed as expected administrative activity count as false positives even though the detection worked correctly, because from the client's perspective they are noise.

Incident is declared when confirmed unauthorised access, data loss or service disruption from a security cause is established. No incident was declared this period; the two critical alerts were blocked before impact and are reported as alerts, not incidents.

Exclusions. Vulnerability and patch state are reported in the Patch Management report; endpoint configuration in the Configuration Management report. Application-level audit logs inside the accounting and market-data systems are not forwarded and are outside the monitoring scope.

Anonymisation notice

This copy is an anonymised sample prepared for illustration. The client name, hostnames, user identifiers, alert references and source network addresses have been replaced with fictitious or generic values; volumes, ratios, dates and findings reflect a representative monitored estate. No real client data appears in this document.

Questions on this report
BCS Support Center · it-service@brocent.com
Brocent — Your Asia IT Team
Frequently asked

Questions clients ask about this report

What does 24x7 monitoring actually deliver each month?

Coverage of every log source with volume and latency, every alert with its severity and outcome, and mean time to detect and triage measured from the source event timestamp — not from the moment an analyst opened the case, which would flatter the figure.

Why report log sources that are missing?

Because a blind spot is the finding. The sample report names two unmonitored access switches and three endpoints without behavioural telemetry, with owners and dates, rather than presenting coverage as complete.

How long are security logs retained?

Ninety days searchable and twelve months in cold storage by default. Where a firm's records policy is longer we recommend and quote a longer cold tier, and report the gap until it is decided.

Next step

See what your own SOC Log Management report would say

A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.

Book a free IT health check Contact BCS Support Center