A top automotive financial services company strengthened cybersecurity and achieved compliance with one unified log pipeline

With NXLog Platform, the company replaced an obsolete log collection solution, unified collection across its global multi-vendor infrastructure — including air-gapped nodes — and met SEC, SOX, PCI DSS, and GLBA requirements for log retention and analysis.

Nxlog afs case study hero 722x429
Group 25926

Business Demand

Improve security posture and meet SEC, SOX, PCI DSS, and GLBA requirements, plus national and corporate regulations for log retention and analysis.

Group 25926

Key Challenges

Replace an obsolete log collection solution with a secure, time- and cost-effective pipeline across multi-vendor infrastructure, including air-gapped nodes.

Group 25926

Results

A unified, autonomous log collection pipeline, simplified event source integration, broader collection coverage, and compliance achieved.

We are very pleased working with NXLog and really appreciate all the advanced features of the product. We were looking for a lightweight log collection tool, that allows to flexibly filter and transform events, while keeping it easy to deploy agents across Microsoft infrastructure. We considered NXLog as the most versatile product that completely fulfill all the needs for us.

— CISO, Automotive Financial Services Company

Local police

The Challenge

Financial services companies operate under regulations such as GDPR, PCI DSS, SOX, and GLBA that mandate safeguarding infrastructure and customer financial data. Successful attacks on financial firms are lucrative for cybercriminals, so a detailed, up-to-date view of all network activity is essential to defend against them.

The company’s existing log collection solution had become obsolete, ineffective, and difficult to manage. A solid log management process needed a reliable pipeline across the entire network infrastructure — including air-gapped nodes.

The main challenge was the variety of target systems from different vendors, each with its own logging capabilities and technologies. To solve it, the company set out to implement a vendor-agnostic log collection pipeline that allows fast, easy integration of old and new network endpoints and applications.

Emoji objects

The Solution

The company chose NXLog Platform to build a unified, autonomous log collection pipeline for event retention and ongoing threat analysis.

The NXLog Agent collects from a wide range of log sources, including Windows event logs, and can process volumes of more than 100,000 events per second. It supports all standard network protocols, collects logs from files and databases, and handles common log formats out of the box, with more than 120 built-in extensions for collection, processing, and routing. Deployment across the company’s Microsoft Windows infrastructure was quick: agents roll out via Windows Group Policy with a signed package.

Log collection is never a one-time task. Agents and forwarders need ongoing monitoring and management while new endpoints join the pipeline. Rich data filtering and transformation were also key requirements: pick only the events that matter for a specific job — such as security — skip high-volume diagnostics, and reshape messages to match the central store, whether that is a SIEM or an APM system.

The NXLog Agent performs advanced processing on log messages, including rewriting, correlation, alerting, pattern matching, scheduling, and log file rotation. It prioritizes specific messages and buffers data on disk or in memory to work around input latency and network congestion. After processing, it stores or forwards events in many supported formats, including to SIEM solutions such as Microsoft Sentinel, Google Security Operations (formerly Google Chronicle), OpenText ArcSight, and IBM QRadar.

The new unified log collection pipeline now helps the company meet both corporate and national regulations.

Why it Worked

Group 26093

Lightweight agent, deployed across Windows infrastructure via Group Policy

Group 25927

Rich event filtering and transformation before data leaves the source

Group 25928

Vendor-agnostic forwarding to SIEM and APM destinations

Group 25929

Disk and memory buffering for reliable delivery across the pipeline

Results

A unified and autonomous log collection pipeline now runs across the company’s global infrastructure. Ongoing event source integration is simpler: new endpoints and applications join the pipeline without vendor-specific rework.

Broader log collection coverage improved the company’s security posture, giving engineering and security teams a detailed, current view of network activity for threat analysis and faster resolution of production and security issues. Filtering out extraneous data at the source also cut data retention expenses.

Most importantly, the company achieved compliance: the pipeline meets SEC, SOX, PCI DSS, and GLBA requirements, plus national and corporate regulations for log retention and analysis.

Check circle FILL1 wght400 GRAD0 opsz24 12

Unified pipeline

One autonomous log collection pipeline across the entire infrastructure

Check circle FILL1 wght400 GRAD0 opsz24 12

Simplified integration

New event sources join the pipeline quickly, old and new alike

Check circle FILL1 wght400 GRAD0 opsz24 12

Stronger security posture

Broader collection coverage and a current view of network activity

Check circle FILL1 wght400 GRAD0 opsz24 12

Compliance achieved

SEC, SOX, PCI DSS, and GLBA, plus national and corporate retention rules

About the customer

The customer is a business division of one of the world’s top-tier automotive groups, with thousands of employees working at dozens of branches across the globe. Its services span automotive financial services, direct banking, financing, leasing and insurance, fleet management, and payment and rental solutions.

Nxlog afs case study about 560x420