The challenge
For a hospital, security monitoring has to cover a large, mixed IT network without drowning the team in noise. Deciding which metrics matter, and which information is worth storing and archiving, is a real challenge in its own right. Log everything and the signal disappears; log too little and an incident slips through the gaps.
Baselland Cantonal Hospital needed a monitoring foundation built on a clear answer to one question: where is the gain in visibility and security actually greatest, and what should be captured to get it.
The approach
We worked from that question outwards: first deciding what to capture, then proving the tooling, then building the system that would run in production.
-
Decide what is worth logging
Before any platform decision, we evaluated the real need: which systems, which events and which metrics carry security value, and which information should be saved and archived rather than simply collected.
-
Prove the tooling
Two logging frameworks, Elastic and Graylog, were implemented and evaluated side by side in a proof of concept, so the platform choice rested on evidence rather than assumption.
-
Build a central system on Elastic
A central logging and monitoring system was then set up on Elastic, the open-source option, giving a single uniform view of the data from and about the hospital's critical systems. The system is highly available and fail-safe.
What the platform sees
For a SOC or security team, the value is in the unified view: one place where signals from across the network line up against each other:
- Windows client and server logs, alongside Exchange and Active Directory logs, as the backbone of host and identity visibility.
- DNS infrastructure monitoring, making it possible to see, for example, who has reached out to a known malware domain.
- Service-level telemetry, not just service logs. Instead of the Microsoft DNS system log, Elastic's Packetbeat is used, so meta-information about the service itself, such as DNS response times, is available too.
Background: narrowin's approach to Windows event logging on Elastic is documented in a guest post on the Elastic blog, "The essentials of Windows event logging".
The result
When a warning fires, security-relevant questions can be answered quickly and precisely, and that answer becomes the basis for deciding what to do next. The hospital's monitoring system turns logs into a basis for deciding what to do, rather than just storing them.