QNB Türkiye unified security log collection across 15,000 endpoints and thousands of ATMs
With NXLog Platform, the bank's technology arm IBTech built one pipeline that collects, filters, and normalizes logs from Windows, macOS, and Linux endpoints, servers, network gear, and multi-vendor ATMs — then routes them to the SIEM, UEBA, and the general-purpose data lake.
Business Demand
Strengthen cybersecurity and operations monitoring across the bank's estate, and make its systems more resilient.
Key Challenges
Aggregate events from hundreds of branches and thousands of multi-vendor ATMs, hold down the volume reaching the SIEM, and route the same data to both security systems and a general-purpose data lake.
Results
One autonomous telemetry pipeline in production, wider log collection coverage, and a data lake the operations team now uses for its own analysis.
The entire telemetry pipeline becomes both powerful and easy to maintain with NXLog. We value its high level of configurability and advanced log processing engine, which enables us to filter out up to 80% of events directly at the endpoints. This ensures that only the most relevant data is fed into our security systems, streamlining security operations.
— Ahmet Uygut, Expert Architect, IBTech Security Incident Management and Monitoring
The Challenge
IBTech runs the full cycle of R&D, infrastructure, and cybersecurity operations for QNB Türkiye and its subsidiaries. To hold a consistent defense-in-depth posture, its security team has to collect logs across hundreds of bank branches and a wide range of endpoints — office computers, servers, and network equipment.
Each endpoint produces a different mix of log types: Windows, macOS, and Linux operating system logs, application logs, antivirus events, EDR logs, PowerShell logs, and Sysmon logs, all of them useful for both real-time detection and on-demand investigation.
The ATM estate raised the difficulty. QNB Türkiye runs thousands of cash dispensers from several vendors, and every one of them generates security-relevant log data. Given what ATMs do, none of them could sit outside the collection scope.
The bank's security policy also set out what had to happen to the data once collected: continuous collection, filtering so the network and storage were not overloaded, normalization to specific schemas, and delivery to several destinations at once — security systems including the SIEM and UEBA, plus a general-purpose data lake for operational analysis. Pulling that off with a different tool per source would have meant more moving parts and more places to fail. IBTech wanted a single autonomous pipeline instead.
The Solution
After evaluating several options, IBTech chose NXLog Platform for its range of integrations, its data transformation capabilities, and how much of the processing it could push to the edge.
NXLog Agent was deployed across more than 15,000 endpoints within weeks and integrated with the bank's SIEM.
The team runs a hybrid collection model: NXLog agents installed locally on endpoints, plus agents deployed on the network as remote collectors for sources that cannot take an agent — the ATM fleet among them. A strict filtration policy sits in front of the security tier, so only the events that matter for security operations are ingested into the SIEM and UEBA. Everything else is either dropped or routed to the data lake instead.
NXLog Professional Services supported the rollout.
Why it Worked
One pipeline covering Windows, macOS, Linux, servers, and network devices
Agent-based and agentless collection inside the same architecture
Filtering at the endpoint, before events reach the SIEM
Fan-out to security systems and the data lake from a single collection layer
Results
IBTech now runs one autonomous telemetry pipeline for QNB Türkiye. Branch endpoints and the multi-vendor ATM network are both inside the collection scope, which closed the coverage gaps that a tool-per-source approach had left open.
Filtering at the endpoint keeps the SIEM and UEBA focused on security-relevant events instead of everything the estate emits — the bank puts that reduction at up to 80% of events.
The pipeline also turned out to be useful outside the security team. Because the same collection layer feeds the general-purpose data lake, the operations team now works with log data it previously had no practical route to, and uses it for its own analysis and decisions.
Unified pipeline
One autonomous telemetry pipeline in production across the bank's estate
Wider coverage
Branch endpoints and the multi-vendor ATM network both inside collection scope
Lower SIEM load
Endpoint-side filtering keeps non-relevant events out of the SIEM and UEBA
Value beyond security
The operations team uses the same log data in the data lake for its own analysis
About QNB Türkiye and IBTech
QNB Türkiye — founded in 1987 as Finansbank A.Ş. and known as QNB Finansbank from 2016 until its rebrand in October 2024 — is one of Türkiye's largest private banks, serving consumer, SME, corporate, and private banking customers. It has been part of QNB Group, the largest bank in Qatar, since June 2016.
IBTech is the bank's technology subsidiary. It manages the full cycle of R&D, infrastructure, and cybersecurity operations for QNB Türkiye and its subsidiaries from the TÜBİTAK MAM Technology Free Zone in Gebze.