A global mining company closed the visibility gap across its ICS/OT networks
With NXLog Platform, the company pulled fragmented logs from PLCs, SCADA software, and HMI servers into one pipeline, captured industrial protocol traffic that had no oversight before, and delivered audit-ready OT telemetry to Microsoft Sentinel alongside its IT logs.
Business Demand
Gain security visibility across OT networks, detect threats and respond faster, support ISA/IEC 62443 audit requirements, and cut SIEM log volume and cost.
Key Challenges
Fragmented logging across PLCs, SCADA software, and HMI servers; little detection of anomalous ICS traffic; slow, manual compliance audits; and weak collaboration between IT and OT teams.
Results
Centralized, audit-ready OT logging, early detection of anomalous OT traffic, lower SIEM cost, and a shared view of security and system health for IT and OT.
NXLog closed the visibility gap in our OT networks. Now, we detect threats faster, respond sooner, and meet compliance requirements with ease — all while lowering SIEM costs and streamlining operations.
— Chief Information Security Officer, global mining and commodities company
The Challenge
A global leader in mining and commodities, this company runs mines and processing facilities worldwide. Those sites depend on Industrial Control Systems (ICS) and Operational Technology (OT) to automate heavy equipment, processing plants, and safety systems — including SCADA software and the programmable logic controllers (PLCs) that run conveyors and ventilation.
That estate grew over time into a mix of modern and legacy systems across many locations, and as IT and OT converged it became harder to secure. A compromised ICS can mean operational disruption, financial loss, and safety hazards, so the company made OT security a priority. The core problem was that its OT infrastructure had no centralized logging. Every mine and processing plant generated logs — SCADA alarms, Windows-based HMI event logs, PLC status messages — but they sat siloed on local systems in different formats and locations. Some SCADA components wrote to text files, others to proprietary databases, and many critical events were only visible on the local operator station.
The company could still operate this way, but it could not aggregate or analyze OT security events centrally, which left it without a clear view of the plant floor and made real-time threat detection close to impossible. Compliance was the second pressure point: standards like ISA/IEC 62443 call for a centrally managed, system-wide audit trail with reliable timestamps, and this setup could not produce system-wide, time-correlated logs. Audit preparation meant collecting evidence by hand — slow, and easy to get wrong.
The Solution
The company deployed NXLog Platform across its mining operations as a single logging and monitoring layer, rolling it out in the heterogeneous OT environment during planned maintenance windows to avoid disruption.
NXLog Agent was installed on the Windows-based SCADA and HMI servers to read native Windows Event Logs, capturing PLC communications, operator actions, and system alerts. Where systems produced log files or proprietary text output, the im_file input module was configured to tail, read, and process those files in real time, and NXLog Agent’s database inputs covered the SCADA components that logged to proprietary databases instead of files.
NXLog Agent could also collect telemetry from industrial devices and protocols that previously had no oversight at all. Using passive network capture through the im_pcap module, it listened to OT network traffic and decoded common ICS protocols including Modbus, DNP3, BACnet, and Siemens S7. That meant even PLC-to-PLC communications and sensor data crossing the network could be logged and analyzed, giving the company much deeper insight into its process control communications.
The deployment was tailored to the company’s distributed and air-gapped sites. NXLog Platform is vendor-agnostic and runs across hybrid, on-premises, and air-gapped environments, so agents at remote mines worked without internet access or extra dependencies, and OT data stayed inside each site’s security perimeter. Where bandwidth was constrained, NXLog Agent forwarded events in compressed batches to keep network impact low — useful for remote sites backhauling to a central data center over cellular links. Built-in buffering and failover handled connection loss: if the link to the central repository or SIEM went down, logs queued locally and forwarded automatically once it came back, so audit data was not lost. Collected OT logs were normalized (converting proprietary ICS events into JSON or syslog) and routed to Microsoft Sentinel alongside critical IT logs, so analysts could see OT and IT events in the same dashboards and correlate threats across the enterprise. Custom parsing let the team write rules for OT-specific anomalies — for example, flagging rarely used control commands appearing on the network.
Why it Worked
One pipeline across PLCs, SCADA software, and HMI servers
Passive network capture that decodes ICS protocols
Runs in air-gapped sites, with compressed batches over thin links
Buffering and failover, so audit data survives a dropped connection
Results
With NXLog Platform, the company gained visibility and security monitoring across its OT environment. Critical ICS/OT events — logins, configuration changes, alarms, network anomalies — now reach the SIEM in near real time, closing the IT/OT visibility gap. The SOC can catch malware and advanced persistent threats early, including activity that shows up as unusual Modbus communications, and respond straight away rather than hours or days later. Incident response times have come down, and data from every site is correlated centrally for faster detection with less noise.
Compliance and audit work improved too. Centralized, time-synced logs give a clear record of who did what and when, which is what ISA/IEC 62443 asks for in its audit-trail requirements. Audit preparation that used to take weeks of manual work can now be handled with a few queries.
Operationally, filtering noise in the telemetry pipeline reduced SIEM log volume and security cost, while giving OT engineers visibility into equipment faults for proactive maintenance and fewer outages. IT and OT teams now work from a shared view of security and system health across the company’s industrial operations.
Centralized, audit-ready OT logging
Time-correlated records across every site, ready to query for an audit
Early detection of anomalous OT traffic
Unusual control commands and protocol activity surfaced in near real time
Lower SIEM cost
Noise filtered out of the pipeline before it reaches the SIEM
IT and OT working from one view
The same dashboards, the same events, for both teams
About the customer
The customer is a global mining and commodities company focused on the safe, reliable, and compliant production of metals and minerals. It runs extensive industrial control systems and operational technology across multiple mining sites worldwide.