The bank’s SIEM environment had become difficult to scale as its infrastructure expanded across on-premises, cloud, and Microsoft platforms.
- High alert volumes were increasing analyst fatigue
- False positives and unmanaged alerts were consuming SOC time.
- New applications, web services, and log sources were difficult to onboard
- Microsoft 365, Intune, SharePoint, compliance portal, and Event Hub, Kubernetes, container integrations were limited
- Hybrid visibility across on-premises and cloud systems was inconsistent.
- Log parsing and normalisation were slow across several applications
- Reports lacked the clarity needed for SOC review, governance, and audit-readiness activities.
- The existing SIEM model did not provide enough flexibility for future use cases and integrations


The Challenge
The Solution
The Impact