Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
ERBE SIEM & Log Management

ERBE SIEM: A Local, On-Premise SIEM With 27 Modules

Discover ERBE SIEM, a fully local, on-premise SIEM with 27 modules that keeps your logs on site while meeting Turkey's Law No. 5651 requirements.

  • Erbe Bilişim Uzman Ekibi
  • 7 min read
ERBE SIEM & Log Management category cover — a signal trace icon representing an event stream on a dark navy background

An auditor asks a security lead one question: "Can you produce six months of session records, each independently timestamped?" The logs are scattered across firewalls, servers, and endpoints, some already rotated out. Worse, the records that were shipped to an overseas cloud tool now sit outside the organization's control. For any company that must keep sensitive data inside a specific jurisdiction, this is where the case for an on-premise SIEM becomes concrete: compliance and data residency have to hold at once.

This article covers ERBE SIEM in five parts: architecture, modules, regulatory context, log collection, and a live demo. The aim is a clear, practical frame for decision-makers evaluating a security information and event management (SIEM) investment.

A Fully Local, On-Premise Architecture

ERBE SIEM is a security monitoring platform built entirely in-house. The codebase, data model, and interface are produced by a single engineering team, which sets it apart from license models that depend on an external vendor's roadmap.

Its second distinguishing trait is the on-premise architecture. The system runs on the organization's own server, and logs, correlation results, and reports never leave it. Its physical location stays under the organization's control.

This matters most for two groups: public-sector and financial institutions with strict data-sovereignty requirements, and mid-sized businesses that want to avoid cloud costs and outbound data transfer. On-premise processing adds an operational edge too. An internet outage or cloud provider incident does not stop monitoring, and latency disappears because correlation runs where the data already sits. In a live incident, seconds count.

A local stack is only the foundation; it needs a capability set to act on. The ERBE SIEM security monitoring platform brings everything from log collection to behavioral analysis into one console, replacing scattered tools with an integrated whole. Readers new to the category can start with our guide to what a SIEM is.

27 Modules Across Three License Packages

ERBE SIEM splits its functions into discrete modules rather than one monolithic application. Twenty-seven modules cover the layers of a security operation, and 31 dashboard screens make them manageable. Version 1.0.0 is validated against 111 test scenarios.

The modules are grouped to fit an organization's needs and form a coherent whole. Headline areas include:

  1. Log collection and normalization: brings raw records from many sources into a common format.
  2. Correlation engine: links separate events into a meaningful chain.
  3. UEBA module: turns deviations in user and entity behavior into a risk score.
  4. Access-log retention: stores access records with independent timestamps.
  5. Alert and incident management: prioritizes warnings and surfaces them to an analyst.
  6. Reporting: produces ready outputs for audit and management.

Readers who want to go deeper on the behavioral layer can review our user behavior analytics (UEBA) guide. Because the modules share one console, an analyst investigating an alert sees every layer, from the raw record to the behavior score, on the same screen.

How the License Packages Differ

The modules are offered under three license packages, separated by capability rather than price. The table below summarizes the logic.

PackageFocusTypical organization
Çekirdek (Core)Log collection, access-log retention, and basic reportingSMB meeting a baseline compliance obligation
Güvenlik (Security)Correlation, alert management, and extended reportingMid-to-large business running active monitoring
Kurumsal (Enterprise)UEBA, threat intelligence, and the full module setOrganization with a mature security operation

The right package tracks an organization's security maturity, and a team that starts with a compliance requirement can move up later. Package changes do not require a reinstall: modules are activated on the same platform and the existing log history is preserved, giving budget-conscious teams a predictable path forward.

Turkish Regulatory Context: Law No. 5651

Turkish regulatory context: Foreign companies operating in Turkey should know that organizations providing internet access must retain access logs for a defined period under Law No. 5651. The integrity of those records must be secured with a timestamp; otherwise there is no way to prove a log was not altered.

ERBE SIEM meets this obligation natively. Access records are collected, stored, and signed with a timestamp using TÜBİTAK's RFC 3161-based infrastructure, so the exact moment a record was created can be verified independently. Because the architecture is on-premise, these records are retained without ever leaving the organization.

This is not merely a technical checkbox; it is decisive during an audit. The statute text is available through the official Turkish legislation portal, and our Law No. 5651 log-retention guide explains the obligation step by step.

Vendor-Neutral Log Collection

A SIEM is worth as much as the range of sources it can ingest. In enterprise networks, the firewall, servers, endpoints, and application layers often come from different manufacturers, each writing logs in its own format.

ERBE SIEM is built around vendor-neutral collection, not locked to one manufacturer. It takes records from many devices over standard protocols and normalizes them. Typical source types include:

  • Firewall and next-generation firewall records
  • Windows Server and Linux server event logs
  • Endpoint protection and antivirus alerts
  • Network switch and router traffic
  • Web server and application logs

Vendor neutrality also lowers long-term lock-in risk: when you refresh a device or switch manufacturers, the new source joins the same collection logic. This broad coverage reduces blind spots, because even if an attacker leaves no trace on one layer, a record on another completes the picture. Based on data from our own deployments, a single system observed 262 attack attempts in 24 hours, across 104 different IPs, at a peak of 16 attempts per second, all processed on-premise with 0 cloud transfer. That field data is told through a concrete example in the story of an ERBE SIEM hotel deployment.

See It Live: A Free Demo

The soundest way to evaluate a security investment is to see the product in your own context, which is why we present ERBE SIEM through a free live demo. In a session you watch the 31 dashboard screens, the modules working together, and the timestamped log stream directly, and we assess the fit for your scenario.

For organizations that want a running operation rather than software alone, our 24/7 Managed SOC / MDR service adds alert triage and incident response, turning ERBE SIEM into a working security process.

Conclusion

Organizations seeking a local SIEM usually carry the same three needs together: data that stays on site, regulatory compliance, and a single unified console. ERBE SIEM meets all three with 27 modules, an on-premise architecture, and native access-log retention. TÜBİTAK timestamping secures record integrity, and vendor-neutral collection reduces blind spots. To see it running on your own server, plan a free live demo of the ERBE SIEM security monitoring platform and request a discovery call for the package that fits your business.

Frequently Asked Questions

Does ERBE SIEM send my data to the cloud?

No. ERBE SIEM runs entirely on-premise. Logs, correlation results, and reports are kept on the organization's own server, and no record is transferred outside the organization or to the cloud by default. Our field deployments confirm this with 0 cloud transfer, which makes the solution suitable for public-sector and financial institutions with high data-sovereignty requirements.

Is ERBE SIEM enough on its own for Law No. 5651 compliance?

The platform meets the log collection, retention, and timestamping duties under Law No. 5651 with a built-in module, and its TÜBİTAK RFC 3161 timestamp secures record integrity. Compliance, however, is a matter of process as well as technology. Retention periods and access policies must be defined internally. ERBE SIEM supplies the technical foundation, and we shape the policy design together.

Will ERBE SIEM work if my firewall is a different brand?

Yes. ERBE SIEM is designed around vendor-neutral log collection. Over standard protocols it ingests firewall, server, and endpoint records from different manufacturers, with no lock-in to a single brand. Integration is possible without replacing your existing devices, and a short discovery study before rollout confirms the compatibility of your sources together.

Tags

  • local siem
  • erbe siem
  • on-premise security