La Banque Postale unified log collection and met national regulations with one autonomous pipeline
With NXLog, La Banque Postale replaced its native Splunk forwarders, brought Windows, Linux, AIX, and network appliances into a single pipeline, and met strict national and international regulations.
Business Demand
Centralize log collection across critical banking systems to strengthen security posture and meet domestic and international regulations.
Key Challenges
Gather events from Windows, Linux, AIX, and network appliances in one pipeline, and overcome the limitations of native Splunk forwarders.
Results
A unified, autonomous log collection pipeline with broader coverage, simpler event source integration, and compliance goals achieved.
We really appreciate versatility of NXLog. It’s ultimately lightweight in regard to CPU/RAM consumption, while still extremely powerful to process a solid event stream flawlessly. Also, as NXLog provides a lot of integration options, it allows us to collect a wide variety of assets’ logs and be flexible with log collection architecture
— Yann Chanel, Systems and Networks
The Challenge
As a critical infrastructure operator, La Banque Postale is subject to security requirements imposed by domestic and international regulations. Every critical system must stay resilient, and log collection and centralization is a key part of proving it. The bank’s security team relies on centralized events to detect, prevent, and remediate threats across vital banking systems in time.
The goal of the project was to collect and centralize logs from all data center systems into a Splunk data store for operational and threat analysis. The native Splunk forwarders in place held the team back on ingestion speed, filtering, and the range of sources it could integrate.
Compliance also asks for more than endpoint logs. The team needed events from key network, security, and storage services across the data center — appliances from Blue Coat, Cisco, CyberArk, F5, IBM, Hitachi, and others — most of which transmit events over syslog.
The Solution
The first stage replaced the native Splunk forwarders with NXLog agents on Windows, Linux, and AIX endpoints. As a dedicated log collection agent, NXLog gave the team faster ingestion, richer filtering, and more integration options than the forwarders it replaced.
The agent’s embedded log file rotation was one of the reasons for the switch: engineers manage log files directly, without relying on each system’s own rotation features. That autonomy carried into daily operations: the team now integrates new log sources on its own.
The next stage brought in the appliances. The team set up a load-balanced cluster of NXLog collectors to receive syslog from network, security, and storage services, with failover and load balancing options keeping collection highly available.
Once collected, events are filtered and processed centrally, forwarded to an Apache Kafka broker cluster, and delivered to the Splunk SIEM, where security engineers monitor, detect, and remediate threats.
The capabilities behind this deployment — the lightweight agent, its filtering and integration options, and centralized agent management — are available today as part of NXLog Platform.
Why it Worked
A lightweight agent with low CPU and RAM use under heavy event streams
Built-in log file rotation, independent of each system’s own tools
High-availability options, including failover and load balancing
Integration options spanning endpoints, syslog appliances, Kafka, and Splunk
Results
A unified, autonomous log collection pipeline — powered by NXLog — now covers La Banque Postale’s data center systems, from operating system endpoints to network, security, and storage appliances. It complies with government regulations and gives the security team one consistent stream of events.
The autonomy is the part the team feels daily: engineers integrate new data sources quickly, without forwarder limitations or outside help. Broader collection coverage across critical systems has strengthened the bank’s security posture.
Filtered, centralized events reach the Splunk SIEM through the Kafka cluster in a consistent form, so the security team can respond proactively to emerging threats based on what the pipeline collects.
Autonomous operations
The team adds and manages event sources itself, free of forwarder limitations
One unified pipeline
Endpoints and appliances across the data center feed a single collection layer
Stronger security posture
Broader log coverage across the systems that matter most
Compliance achieved
Log collection and centralization requirements met, from domestic rules to international standards
About La Banque Postale
La Banque Postale is a multi-partner, international bancassurance group serving 64 million customers in 19 countries across Europe and Latin America, with business line net banking income of €9,516 million as of 2022. Established as a universal bank in 2006 as a subsidiary of France’s national postal service, La Poste, it supports over 20 million customers with a full range of financial products and services through a network of 17,000 points of contact, including 7,600 post offices, community branches, and relay shops.