Altice Portugal improved SOC performance with an agentless telemetry pipeline

With NXLog Platform, Altice Portugal reached the security log sources its previous tools could not, cut event noise before it hit the SIEM, and centralized log retention for every critical system in scope.

Altice hero 722x429
Group 25926

Business Demand

Improve the security posture of internal infrastructure by raising SOC performance and reliability.

Group 25926

Key Challenges

Centralize security events from a wide range of sources, pre-filter them so the SIEM stays fast, and keep complete log retention for every critical system.

Group 25926

Results

Higher SOC performance and reliability, broader log collection coverage, and centralized retention — delivered on a cost-efficient agentless pipeline.

We were limited in getting some security logs to our SOC platforms. However, with the migration to the NXLog telemetry pipeline, we are now able to get all security events for analysis in a fast, resilient, and reliable way.

— Jorge Silva, Manager of Cybersecurity Architecture & Engineering, Altice Portugal

Local police

The Challenge

Telecom operators run some of the most complex IT estates in any industry, and that complexity makes them a high-value target. The attacks they see range from assaults on mobile infrastructure and customer account takeovers to data theft, DDoS, and ransomware. For Altice Portugal, the largest telecommunications operator in the country, customer data is a critical business asset — and it needs protection to match.

Altice Portugal's enterprise security policy requires its Security Operations Center to monitor events without interruption across critical systems and technologies, including the DMZ, security devices, and network elements. The previous log collection tools could not meet that requirement. They failed to retrieve data from several key sources, which left gaps in exactly the places the policy was written to cover.

Performance was the second problem. High-volume sources such as domain controllers pushed more events into the SIEM than it could process efficiently, which slowed the analysis the SOC depends on. Altice Portugal needed a pipeline that could reach every source, reduce noise before it hit the SIEM, and still guarantee that every captured log arrived at the security platforms.

Emoji objects

The Solution

Altice Portugal chose NXLog over other options to build a new event collection pipeline. The deciding factors were its light footprint, the range of event sources it supports, its integrations, and its event parsing.

NXLog Platform provides a flexible telemetry pipeline architecture, including agentless collectors that retrieve events from sources such as Windows endpoints and network appliances. Those events had to reach more than one destination — one path for real-time analysis, another for long-term retention. NXLog handles both. It forwards to SIEM platforms including Google Security Operations, Microsoft Sentinel, Elastic, Graylog, IBM QRadar, and OpenText ArcSight, and to retention targets including its own embedded storage and search engine, AWS, Azure, and Snowflake.

Pre-filtering was the other half of the problem: cut the volume enough to keep the SIEM fast, without losing anything the security platforms needed. NXLog's parsing capabilities handle this by filtering and normalizing events before forwarding them. The engineering team also used the local caching feature of the NXLog agent, so logs reached the security systems reliably and without delay. NXLog Professional Services worked alongside the Altice Portugal team on the implementation.

Why it Worked

Group 26093

Agentless collectors reach sources the previous tools could not

Group 25927

Pre-filtering and normalization keep the SIEM fast

Group 25928

Parallel forwarding to real-time analysis and long-term retention

Group 25929

Local agent caching for reliable delivery

Results

NXLog Platform became the collection layer for Altice Portugal's SOC. Replacing the previous tools with an agentless pipeline closed the coverage gaps that had left critical systems unmonitored, and the SOC now receives security events from across the estate.

Pre-filtering changed how the SIEM performs. Filtering and normalizing events before forwarding them reduced the volume reaching the platform, which supports faster real-time threat detection — without dropping events the SOC needs.

Retention improved alongside detection. Forwarding the same telemetry to long-term storage gives Altice Portugal a centralized record for the critical systems its security policy and audit obligations cover.

The agentless approach kept the cost of that coverage down. Because collectors retrieve events remotely rather than needing an install on every endpoint and appliance, Altice Portugal widened its collection coverage without a matching increase in deployment and maintenance work.

Check circle FILL1 wght400 GRAD0 opsz24 12

Higher SOC performance

Pre-filtered event streams support faster real-time threat detection

Check circle FILL1 wght400 GRAD0 opsz24 12

Broader collection coverage

Agentless collectors reach sources the previous tools could not retrieve data from

Check circle FILL1 wght400 GRAD0 opsz24 12

Complete log retention

Centralized retention across every critical system in scope

Check circle FILL1 wght400 GRAD0 opsz24 12

Cost-efficient deployment

Wider coverage without a per-device agent rollout

About Altice Portugal

Altice Portugal, formerly Portugal Telecom, is the largest telecommunications operator in Portugal. Its services span fixed line, 4G and 5G mobile communications, and media, entertainment, and advertising. It is a subsidiary of Altice Group, a multinational cable and telecommunications company headquartered in Luxembourg, with a presence in France, Israel, Belgium and Luxembourg, Portugal, the French West Indies and Indian Ocean area, and the Dominican Republic.

Altice about 131x148