A multinational oil and gas operator built one telemetry pipeline across its OT and IT networks
With NXLog Platform, the operator collects events from Windows and Linux systems, PLCs, SCADA and HMI stations, firewalls, and data historians, filters them where they are produced, and relays them across every Purdue layer into two SIEMs — without opening up its network segmentation.
Business Demand
Meet NIS2, IEC 62443, and ISO 27001 obligations, and see what is happening across both OT and IT.
Key Challenges
Move logs out of isolated OT zones without weakening segmentation, cover legacy field devices that produce little or no logging, and hold down SIEM volume.
Results
Visibility across every Purdue layer, evidence for regulators, a lighter SIEM, and an architecture that grows site by site.
“Implementing NXLog Platform fundamentally changed how we monitor and secure our industrial operations. For the first time, we have real-time visibility across every layer of our OT and IT environments, without overloading our SIEM or compromising network segmentation and operations. Having a unified telemetry pipeline not only helped us meet strict regulatory requirements but also empowered our teams to detect and respond to threats faster than ever before.
— Chief Information Security Officer, multinational oil and gas operator
The Challenge
Real-time industrial process control leaves little room for error, and this operator runs it across production sites in several countries. Each site is segmented according to the Purdue Model, with firewalls between layers and cross-zone communication deliberately restricted. That design protects the process. It also makes getting logs out of the protected OT zones difficult.
The sources were varied. Windows and Linux systems, PLCs, SCADA and HMI stations, firewalls, and data historians all produced telemetry in different shapes. A large number of legacy field devices produced almost no log data, or emitted events in non-standard formats, or could not run an agent at all.
Regulation added a deadline to the work. The operator has to satisfy the EU NIS2 directive along with IEC 62443 and ISO 27001, which means demonstrating consistent collection and retention rather than describing an intention to collect.
Volume was the fourth constraint. Sending everything from every site to a central SIEM would have driven ingest costs up and buried the events the security team actually needed. The team had to collect and centralize more, while sending less.
The Solution
The operator deployed NXLog Platform in a tiered agent-and-relay architecture that follows the site's existing segmentation instead of cutting across it.
• At the edge. NXLog agents run in the OT field and control layers (Purdue Levels 0–2), reading Windows Event Log with im_msvistalog and local application logs with im_file. Where legacy controllers and PLCs could not host an agent or generate logs at all, im_pcap captures the industrial traffic passively — including Siemens S7, Modbus, and DNP3.
• Filtering at the source. Agents apply regular-expression filtering and parsing before anything leaves the site, discarding noise and irrelevant events. Whatever survives is compressed and sent onward in encrypted batches with om_batchcompress.
• A controlled crossing point. Relay servers in the industrial DMZ — the tier often called Layer 3.5 — receive those batches with im_batchcompress, decompress and inspect them, then route in two directions at once: one stream to a local ELK stack for on-site monitoring, one copy to local storage as a forensic archive. If the link upward drops, the site keeps its own record and the retention obligation still holds.
• Into the SIEMs. From the DMZ, a further relay forwards consolidated logs to the enterprise IT and cloud layer (Purdue Levels 4–5), normalizing them into JSON, XML, or CSV with xm_json, xm_xml, and xm_csv on the way. Both SIEMs — IBM QRadar on premises and Microsoft Sentinel in the cloud — receive data in the shape they expect.
NXLog Platform manages the whole estate from one place: uniform configuration pushed to every agent, health monitoring on each agent and relay, and an audit trail of collection activity. For a network spread across countries and split into zones, that central control is what makes the architecture administrable rather than just technically possible.
Why it Worked
Telemetry from devices that cannot be instrumented
Filtering where the data is produced
A relay tier that respects segmentation
One place to configure and check every agent
Results
The operator now sees activity at every layer of its environment, including OT devices that cannot host a logging agent, because im_pcap covers them passively. That closed the visibility gap that mattered most in monitoring industrial control systems.
Filtering at the source and compressing at the edge cut the events per second reaching the SIEM platforms by up to 80%. That lowered SIEM licensing cost and made analysis faster, because what arrives is the relevant traffic rather than all of it.
Logs are collected consistently from every critical system and retained in an auditable form, which gives the operator documentation to put in front of an auditor for NIS2, IEC 62443, and ISO 27001. The local forensic copy in each site's DMZ means a network interruption does not create a gap in the record.
The local ELK stack lets the operations security team investigate inside the industrial network without waiting for data to reach central systems, working on parsed OT log data for threat hunting and forensics.
Because the architecture is relay-based and layered, new sites, devices, and sources are added by deploying another agent or relay at the appropriate tier. Nothing has to be redesigned to take on a new industrial protocol or a new IT integration.
OT and IT visibility
Every Purdue layer covered, including devices that cannot run an agent
Up to 80% less SIEM ingest
Source-side filtering and edge compression cut events per second reaching the SIEM platforms
Evidence for regulators
Consistent collection and auditable retention across NIS2, IEC 62443, and ISO 27001
Faster on-site investigation
Parsed OT data available locally, without waiting for central systems
About the customer
The customer is a multinational oil and gas operator responsible for real-time industrial process control across production facilities in several countries and regions. As a critical infrastructure operator, it works to the EU NIS2 directive alongside IEC 62443 and ISO 27001.