A major U.S. bank unified log collection across 500,000 sources
With NXLog, one of the ten largest banks in the United States standardized collection across Windows, Linux, and macOS, reduced the volume of data reaching its Elastic SIEM, and kept a local copy of every event for audit.
Business Demand
Meet strict financial-sector audit and reporting requirements while improving security posture across a large, mixed estate.
Key Challenges
Collect from around 500,000 sources on Windows, Amazon Linux, Red Hat, Ubuntu, and macOS, cut SIEM noise, and keep endpoint overhead low.
Results
Collection coverage across every source, lower SIEM ingest volume, local retention for audit, and faster SOC response.
The Challenge
The bank runs retail, commercial, and investment banking for millions of customer accounts, moving billions of dollars every day. That activity spreads across numerous data centers and cloud environments, and the estate behind it is large: around 500,000 log sources running Windows, Amazon Linux, Red Hat 8 and 9, Ubuntu 20.04 and 22.04, and macOS.
Getting one consistent view of that estate meant collecting several different kinds of data — plain-text application logs, Windows Event Log channels, and Linux system logs — and normalizing them into a single format. The bank's existing tooling struggled on both counts. It pushed more data into the Security Information and Event Management (SIEM) system than analysts could use, and it took performance away from endpoints the business depends on.
Financial regulation raised the stakes. The bank needed collection it could stand behind in an audit: complete, traceable, and still available if the SIEM itself went offline. That ruled out any approach treating the SIEM as the only destination for log data.
The Solution
The bank chose NXLog and deployed agents across the estate to collect application log files, Windows Event Logs, and Linux system logs. The agent-based approach gave the security team collection coverage across all 500,000 sources rather than a sample of them.
Because NXLog Platform supports Windows, Linux, and macOS natively, one collection approach worked everywhere — no separate tooling per platform, and a single configuration model for the team to maintain. The agents are light enough to run on business-critical endpoints without the overhead the bank's previous tooling introduced.
Two design choices did most of the work. First, agents filter events at the source, so only data the SOC can act on travels onward. Second, every event follows two paths: forwarded to the bank's Elastic SIEM for real-time detection and analytics, and written to local storage for redundancy and compliance audits. If the SIEM is unavailable, the audit trail survives.
Why it Worked
Native collection on Windows, Linux, and macOS
Source-side filtering that cuts SIEM ingest
Lightweight agents on business-critical endpoints
Parallel routing to the SIEM and to local storage
Results
All 500,000 sources now report into one pipeline, which closed the gaps that used to sit between platforms and gave the bank a consistent view of its estate.
Forwarding into Elastic improved threat detection and incident response, helping the Security Operations Center act on threats sooner. Sending less data also eased the ingest bottlenecks that had been slowing the SIEM down.
Local retention gave the bank event traceability and auditability it can demonstrate to regulators, and a copy of the record that does not depend on the SIEM being up.
The result is one collection approach the bank can scale: consistent across platforms, defensible in an audit, and light enough to run on the endpoints that matter most.
Full collection coverage
All 500,000 sources reporting into a single pipeline
Lower SIEM load
Less data forwarded to Elastic, easing ingest bottlenecks
Audit-ready retention
Local copies give event traceability and auditability under financial regulation
Faster SOC response
Normalized, pre-filtered data helps analysts detect and respond sooner
About the customer
The client is one of the ten largest banks in the United States, offering retail, commercial, and investment banking services. It handles millions of customer accounts and facilitates billions of dollars in transactions each day, across an IT estate spread over numerous data centers and cloud environments.