A global mining company closed the visibility gap across its ICS/OT networks

With NXLog Platform, the company pulled fragmented logs from PLCs, SCADA software, and HMI servers into one pipeline, captured industrial protocol traffic that had no oversight before, and delivered audit-ready OT telemetry to Microsoft Sentinel alongside its IT logs.

Nxlog mining case study hero 722x429
Group 25926

Business Demand

Gain security visibility across OT networks, detect threats and respond faster, support ISA/IEC 62443 audit requirements, and cut SIEM log volume and cost.

Group 25926

Key Challenges

Fragmented logging across PLCs, SCADA software, and HMI servers; little detection of anomalous ICS traffic; slow, manual compliance audits; and weak collaboration between IT and OT teams.

Group 25926

Results

Centralized, audit-ready OT logging, early detection of anomalous OT traffic, lower SIEM cost, and a shared view of security and system health for IT and OT.

NXLog closed the visibility gap in our OT networks. Now, we detect threats faster, respond sooner, and meet compliance requirements with ease — all while lowering SIEM costs and streamlining operations.

— Chief Information Security Officer, global mining and commodities company

Local police

The Challenge

A global leader in mining and commodities, this company runs mines and processing facilities worldwide. Those sites depend on Industrial Control Systems (ICS) and Operational Technology (OT) to automate heavy equipment, processing plants, and safety systems — including SCADA software and the programmable logic controllers (PLCs) that run conveyors and ventilation.

That estate grew over time into a mix of modern and legacy systems across many locations, and as IT and OT converged it became harder to secure. A compromised ICS can mean operational disruption, financial loss, and safety hazards, so the company made OT security a priority. The core problem was that its OT infrastructure had no centralized logging. Every mine and processing plant generated logs — SCADA alarms, Windows-based HMI event logs, PLC status messages — but they sat siloed on local systems in different formats and locations. Some SCADA components wrote to text files, others to proprietary databases, and many critical events were only visible on the local operator station.

The company could still operate this way, but it could not aggregate or analyze OT security events centrally, which left it without a clear view of the plant floor and made real-time threat detection close to impossible. Compliance was the second pressure point: standards like ISA/IEC 62443 call for a centrally managed, system-wide audit trail with reliable timestamps, and this setup could not produce system-wide, time-correlated logs. Audit preparation meant collecting evidence by hand — slow, and easy to get wrong.

Emoji objects

The Solution

The company deployed NXLog Platform across its mining operations as a single logging and monitoring layer, rolling it out in the heterogeneous OT environment during planned maintenance windows to avoid disruption.

NXLog Agent was installed on the Windows-based SCADA and HMI servers to read native Windows Event Logs, capturing PLC communications, operator actions, and system alerts. Where systems produced log files or proprietary text output, the im_file input module was configured to tail, read, and process those files in real time, and NXLog Agent’s database inputs covered the SCADA components that logged to proprietary databases instead of files.

NXLog Agent could also collect telemetry from industrial devices and protocols that previously had no oversight at all. Using passive network capture through the im_pcap module, it listened to OT network traffic and decoded common ICS protocols including Modbus, DNP3, BACnet, and Siemens S7. That meant even PLC-to-PLC communications and sensor data crossing the network could be logged and analyzed, giving the company much deeper insight into its process control communications.

The deployment was tailored to the company’s distributed and air-gapped sites. NXLog Platform is vendor-agnostic and runs across hybrid, on-premises, and air-gapped environments, so agents at remote mines worked without internet access or extra dependencies, and OT data stayed inside each site’s security perimeter. Where bandwidth was constrained, NXLog Agent forwarded events in compressed batches to keep network impact low — useful for remote sites backhauling to a central data center over cellular links. Built-in buffering and failover handled connection loss: if the link to the central repository or SIEM went down, logs queued locally and forwarded automatically once it came back, so audit data was not lost. Collected OT logs were normalized (converting proprietary ICS events into JSON or syslog) and routed to Microsoft Sentinel alongside critical IT logs, so analysts could see OT and IT events in the same dashboards and correlate threats across the enterprise. Custom parsing let the team write rules for OT-specific anomalies — for example, flagging rarely used control commands appearing on the network.

Why it Worked

Group 26093

One pipeline across PLCs, SCADA software, and HMI servers

Group 25927

Passive network capture that decodes ICS protocols

Group 25928

Runs in air-gapped sites, with compressed batches over thin links

Group 25929

Buffering and failover, so audit data survives a dropped connection

Results

With NXLog Platform, the company gained visibility and security monitoring across its OT environment. Critical ICS/OT events — logins, configuration changes, alarms, network anomalies — now reach the SIEM in near real time, closing the IT/OT visibility gap. The SOC can catch malware and advanced persistent threats early, including activity that shows up as unusual Modbus communications, and respond straight away rather than hours or days later. Incident response times have come down, and data from every site is correlated centrally for faster detection with less noise.

Compliance and audit work improved too. Centralized, time-synced logs give a clear record of who did what and when, which is what ISA/IEC 62443 asks for in its audit-trail requirements. Audit preparation that used to take weeks of manual work can now be handled with a few queries.

Operationally, filtering noise in the telemetry pipeline reduced SIEM log volume and security cost, while giving OT engineers visibility into equipment faults for proactive maintenance and fewer outages. IT and OT teams now work from a shared view of security and system health across the company’s industrial operations.

Check circle FILL1 wght400 GRAD0 opsz24 12

Centralized, audit-ready OT logging

Time-correlated records across every site, ready to query for an audit

Check circle FILL1 wght400 GRAD0 opsz24 12

Early detection of anomalous OT traffic

Unusual control commands and protocol activity surfaced in near real time

Check circle FILL1 wght400 GRAD0 opsz24 12

Lower SIEM cost

Noise filtered out of the pipeline before it reaches the SIEM

Check circle FILL1 wght400 GRAD0 opsz24 12

IT and OT working from one view

The same dashboards, the same events, for both teams

About the customer

The customer is a global mining and commodities company focused on the safe, reliable, and compliant production of metals and minerals. It runs extensive industrial control systems and operational technology across multiple mining sites worldwide.

Nxlog mining case study about 560x420