Ports of Auckland cut SIEM costs with one filtered telemetry pipeline across IT and OT
With NXLog Platform, Ports of Auckland replaced the log collection tools it had outgrown, moved event filtering out to the agent before anything reached the SIEM, and took over day-to-day management of the pipeline with its own team.
Business Demand
Improve the security posture of a port network that runs around the clock, and bring down recurring SIEM costs.
Key Challenges
Collect events from a wide range of IT and OT sources, work within a SIEM priced by events per second, and replace log aggregation tools that had reached their limits.
Results
One log collection pipeline spanning IT and OT, far less noise reaching the SIEM, and a pipeline the in-house team runs itself.
One of the key strengths of NXLog Agent is its granular configuration and advanced filtration capabilities, which allowed us to ingest only valuable events, significantly reducing expenditure on EPS volume.
— Lajos Varga, Head of Digital Technology, Ports of Auckland
The Challenge
A commercial seaport does not get to pause. Ports of Auckland runs an extensive IT and OT estate that has to keep working 24 hours a day, every day of the year, and cybersecurity is part of what keeps cargo moving.
Security event logging and analysis sits at the center of that defense. But a port is a hard place to do it well: a large number of interconnected endpoints, a wide group of stakeholders, and operational technology alongside conventional IT.
Ports of Auckland set out to change its security design, including network segregation and the way security logs were managed, and to put a SIEM in place across the whole infrastructure. Once that SIEM reached the testing stage, the project delivery team ran into the limits of the log aggregation tools already in use.
There was a cost problem underneath the technical one. Only a fraction of the events an endpoint produces is useful for security operations; the rest still lands in the SIEM, where it consumes performance and recurring budget, because SIEM licensing is usually priced by events per second.
The Solution
Ports of Auckland decided to run host logging with NXLog in parallel with the SIEM it had selected, since NXLog's integration list already covered that SIEM.
The tests went well enough that the NXLog telemetry pipeline was promoted from parallel run to replacement. It was rolled out across the infrastructure — hundreds of host agents and collectors forwarding events into the SIEM from both the IT and the OT networks.
Then came the filtering. Ports of Auckland applied an extensive filtration policy at the NXLog agents themselves, using their configuration options, parsing and event transformation to decide what was worth forwarding. Events that added nothing to security operations never left the host, so they never counted against EPS.
NXLog Professional Services supported the work. The pipeline was overseen at first by a dedicated security service provider, then handed over to the Ports of Auckland team, who have run it since.
Why it Worked
· Agent-side filtering that reduces EPS before events reach the SIEM
· Native integration with the SIEM already chosen for the project
· Non-blocking design suited to nonstop port operations
· One pipeline covering both IT and OT networks
Results
NXLog became the log collection layer for security operations across Ports of Auckland's IT and OT networks, replacing the tools the project had outgrown.
Moving filtering out to the agent changed the economics of the SIEM. Instead of shipping everything and paying to store and process it, Ports of Auckland decides at the host what is worth forwarding — which cut both the noise analysts see and the EPS volume the SIEM bills against.
The handover mattered as much as the rollout. What started under a dedicated security service provider is now run day to day by the Ports of Auckland team.
Lower SIEM cost
Filtering at the agent cut the volume of events billed against EPS capacity
IT and OT together
Hundreds of agents and collectors forward events from both networks into one pipeline
Run in-house
The pipeline moved from the security service provider to the in-house team for ongoing management
Cleaner signal
Dropping low-value events reduced noise and eased pressure on SIEM performance
About Ports of Auckland
Ports of Auckland is New Zealand's largest commercial port by value of goods handled and the country's main gateway for imports. Owned by Auckland Council, it operates container terminal handling, cargo handling, marine services and cruise ship facilities on the Waitematā Harbour, around the clock, every day of the year.