All work
Project · Healthcare

SIEM for Baselland Cantonal Hospital

Reliable data is the basis for detecting, investigating and responding to cyber threats. The hard part is not collecting it. It is turning a flood of logs into visibility: into information you can actually act on, through deliberate selection, linking and enrichment.

Customer
Kantonsspital Baselland
Sector
Healthcare
Engagement
Central logging & security monitoring
Platform
Elastic, open source

The challenge

For a hospital, security monitoring has to cover a large, mixed IT network without drowning the team in noise. Deciding which metrics matter, and which information is worth storing and archiving, is a real challenge in its own right. Log everything and the signal disappears; log too little and an incident slips through the gaps.

Baselland Cantonal Hospital needed a monitoring foundation built on a clear answer to one question: where is the gain in visibility and security actually greatest, and what should be captured to get it.

The approach

We worked from that question outwards: first deciding what to capture, then proving the tooling, then building the system that would run in production.

  1. Decide what is worth logging

    Before any platform decision, we evaluated the real need: which systems, which events and which metrics carry security value, and which information should be saved and archived rather than simply collected.

  2. Prove the tooling

    Two logging frameworks, Elastic and Graylog, were implemented and evaluated side by side in a proof of concept, so the platform choice rested on evidence rather than assumption.

  3. Build a central system on Elastic

    A central logging and monitoring system was then set up on Elastic, the open-source option, giving a single uniform view of the data from and about the hospital's critical systems. The system is highly available and fail-safe.

What the platform sees

For a SOC or security team, the value is in the unified view: one place where signals from across the network line up against each other:

Background: narrowin's approach to Windows event logging on Elastic is documented in a guest post on the Elastic blog, "The essentials of Windows event logging".

The result

When a warning fires, security-relevant questions can be answered quickly and precisely, and that answer becomes the basis for deciding what to do next. The hospital's monitoring system turns logs into a basis for deciding what to do, rather than just storing them.

Elastic security monitoring — hosts overview and detection rules
A unified security view: host activity, detections and rules in one place, on an open-source stack
Need visibility across your IT network?
Talk to us