University of East Anglia met PCI DSS logging requirements and cut the cost of changing SIEMs

With NXLog, UEA collects security events from hundreds of Windows and Linux servers and network appliances, forwards what its SIEM needs, keeps everything else on its own long-term storage, and changed monitoring platforms without rebuilding the pipeline.

Nxlog uea case study hero 722x429
Group 25926

Business Demand

Improve the university's security posture and satisfy PCI DSS requirements for logging and monitoring.

Group 25926

Key Challenges

Collect security logs from hundreds of Windows and Linux servers plus routers and firewalls, each with its own log format and output method.

Group 25926

Results

Centralized collection, PCI DSS compliance, long-term retention on the university's own storage, and a lower-cost SIEM migration.

NXLog has been chosen among competitors due to its wide integration list, flexible deployment schema, and a solid reputation across the log management market.

— Andrew Dixon, Operational IT Security Manager, University of East Anglia

Local police

The Challenge

UEA takes card payments, which puts it in scope for PCI DSS. Requirement 10 — Log and Monitor All Access to System Components and Cardholder Data — meant the university needed centralized log collection, ongoing security monitoring, and long-term retention of security events.

That is harder on a campus than in a corporate estate. Universities run open, collaborative IT environments with thousands of users and widely adopted BYOD practices, and they hold large volumes of personal and research data, which makes them attractive to attackers. UEA's estate spans hundreds of Windows and Linux servers alongside network appliances such as routers and firewalls — each with its own log format and output method.

The IT team also aims to keep the campus network available 24 hours a day, seven days a week, across offices, student residences, and teaching spaces, with links to an on-site data center, cloud services, and the wider internet. Any collection layer had to fit that estate without adding work for a security team already running university-wide policy, endpoint protection, multi-factor authentication, security monitoring, and threat hunting.

Emoji objects

The Solution

UEA chose agent-based collection and rolled out NXLog Agent across its infrastructure.

NXLog Platform manages that agent fleet centrally. The team runs ongoing performance health checks and configures installed agents through visual tools, instead of editing files host by host.

The pipeline forwards to two destinations. The first filters security events from critical systems and sends them to the SIEM, so the team indexes only what it actively monitors. The second writes the full, unfiltered stream to network-attached storage as cold storage, which covers the long-term retention side of Requirement 10.

NXLog Professional Services worked with the UEA team through planning and deployment.

NXLog supports agentless collection as well as agents, with high-availability and failover options. UEA's security team plans to add agentless configurations to the pipeline for better scalability and reliability.

Why it Worked

Group 26093

A wide integration list covering Windows, Linux, and network appliances

Group 25927

One pipeline, two destinations — filtered to the SIEM, everything to cold storage

Group 25928

Central agent fleet management with health checks and visual configuration

Group 25929

A vendor-neutral pipeline that survives a change of SIEM

Results

Centralized collection gave UEA one view of security events from across the estate, and the evidence trail Requirement 10 asks for.

Splitting the stream keeps SIEM ingest down to the events the team actually monitors, while the full record lands on storage the university already owns. UEA gets its retention window without paying SIEM rates for cold data.

The payoff the team had not planned for came later. When UEA needed to move from one SIEM to another, the pipeline stayed where it was. Because collection, filtering, and routing live in NXLog rather than in a SIEM vendor's own agents, changing platforms meant changing a destination — not re-instrumenting hundreds of hosts.

Check circle FILL1 wght400 GRAD0 opsz24 12

Centralized log collection

Security events from Windows, Linux, and network appliances flow through one pipeline

Check circle FILL1 wght400 GRAD0 opsz24 12

PCI DSS compliance

Logging, monitoring, and retention evidence for Requirement 10

Check circle FILL1 wght400 GRAD0 opsz24 12

Lower SIEM migration costs

Changing security monitoring platforms took little reconfiguration

Check circle FILL1 wght400 GRAD0 opsz24 12

Retention on its own storage

The full unfiltered log stream goes to network-attached cold storage

About the University of East Anglia

The University of East Anglia is a public research university in Norwich, England. Established in 1963, it teaches around 17,000 students across four faculties and twenty-six schools of study, and is a member of Norwich Research Park. UEA's alumni, faculty, and researchers include three Nobel laureates.

Nxlog uea case study about logo