La Banque Postale unified log collection and met national regulations with one autonomous pipeline

With NXLog, La Banque Postale replaced its native Splunk forwarders, brought Windows, Linux, AIX, and network appliances into a single pipeline, and met strict national and international regulations.

Nxlog lbp case study hero 722x429
Group 25926

Business Demand

Centralize log collection across critical banking systems to strengthen security posture and meet domestic and international regulations.

Group 25926

Key Challenges

Gather events from Windows, Linux, AIX, and network appliances in one pipeline, and overcome the limitations of native Splunk forwarders.

Group 25926

Results

A unified, autonomous log collection pipeline with broader coverage, simpler event source integration, and compliance goals achieved.

We really appreciate versatility of NXLog. It’s ultimately lightweight in regard to CPU/RAM consumption, while still extremely powerful to process a solid event stream flawlessly. Also, as NXLog provides a lot of integration options, it allows us to collect a wide variety of assets’ logs and be flexible with log collection architecture

— Yann Chanel, Systems and Networks

Local police

The Challenge

As a critical infrastructure operator, La Banque Postale is subject to security requirements imposed by domestic and international regulations. Every critical system must stay resilient, and log collection and centralization is a key part of proving it. The bank’s security team relies on centralized events to detect, prevent, and remediate threats across vital banking systems in time.

The goal of the project was to collect and centralize logs from all data center systems into a Splunk data store for operational and threat analysis. The native Splunk forwarders in place held the team back on ingestion speed, filtering, and the range of sources it could integrate.

Compliance also asks for more than endpoint logs. The team needed events from key network, security, and storage services across the data center — appliances from Blue Coat, Cisco, CyberArk, F5, IBM, Hitachi, and others — most of which transmit events over syslog.

Emoji objects

The Solution

The first stage replaced the native Splunk forwarders with NXLog agents on Windows, Linux, and AIX endpoints. As a dedicated log collection agent, NXLog gave the team faster ingestion, richer filtering, and more integration options than the forwarders it replaced.

The agent’s embedded log file rotation was one of the reasons for the switch: engineers manage log files directly, without relying on each system’s own rotation features. That autonomy carried into daily operations: the team now integrates new log sources on its own.

The next stage brought in the appliances. The team set up a load-balanced cluster of NXLog collectors to receive syslog from network, security, and storage services, with failover and load balancing options keeping collection highly available.

Once collected, events are filtered and processed centrally, forwarded to an Apache Kafka broker cluster, and delivered to the Splunk SIEM, where security engineers monitor, detect, and remediate threats.

The capabilities behind this deployment — the lightweight agent, its filtering and integration options, and centralized agent management — are available today as part of NXLog Platform.

Why it Worked

Group 26093

A lightweight agent with low CPU and RAM use under heavy event streams

Group 25927

Built-in log file rotation, independent of each system’s own tools

Group 25928

High-availability options, including failover and load balancing

Group 25929

Integration options spanning endpoints, syslog appliances, Kafka, and Splunk

Results

A unified, autonomous log collection pipeline — powered by NXLog — now covers La Banque Postale’s data center systems, from operating system endpoints to network, security, and storage appliances. It complies with government regulations and gives the security team one consistent stream of events.

The autonomy is the part the team feels daily: engineers integrate new data sources quickly, without forwarder limitations or outside help. Broader collection coverage across critical systems has strengthened the bank’s security posture.

Filtered, centralized events reach the Splunk SIEM through the Kafka cluster in a consistent form, so the security team can respond proactively to emerging threats based on what the pipeline collects.

Check circle FILL1 wght400 GRAD0 opsz24 12

Autonomous operations

The team adds and manages event sources itself, free of forwarder limitations

Check circle FILL1 wght400 GRAD0 opsz24 12

One unified pipeline

Endpoints and appliances across the data center feed a single collection layer

Check circle FILL1 wght400 GRAD0 opsz24 12

Stronger security posture

Broader log coverage across the systems that matter most

Check circle FILL1 wght400 GRAD0 opsz24 12

Compliance achieved

Log collection and centralization requirements met, from domestic rules to international standards

About La Banque Postale

La Banque Postale is a multi-partner, international bancassurance group serving 64 million customers in 19 countries across Europe and Latin America, with business line net banking income of €9,516 million as of 2022. Established as a universal bank in 2006 as a subsidiary of France’s national postal service, La Poste, it supports over 20 million customers with a full range of financial products and services through a network of 17,000 points of contact, including 7,600 post offices, community branches, and relay shops.

Nxlog lbp case study about logo