Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
Our own product

ERBE SIEM

See what is happening on your network, in plain language.

ERBE SIEM is vendor-independent: it collects logs from every next-generation firewall that speaks syslog, from your Windows servers and from Active Directory, correlates them into something meaningful, and separates a real attack from the noise. Your data stays on your own server — nothing goes to the cloud.

  • Built in Türkiye
  • On-Premise
  • Compliant with Law No. 5651
  • Vendor-Independent

By the numbers

working modules
0
panel screens
0
unit tests
0
Problem and solution

Your firewall is writing logs. But who is reading them?

In a typical organisation the firewall, the servers and the wireless network produce millions of log lines every day. Those records pile up somewhere — and when something goes wrong, nobody is left to go back and look at them.

Without a SIEM

  • Logs stay on the device's own disk; when it fills up, the oldest records are deleted.
  • An attack is noticed only once something slows down or stops working.
  • After an incident, nobody can answer which user did what.
  • Alerts accumulate in English-language consoles that no one checks regularly.
  • Records from different vendors cannot be compared on a single timeline.

With ERBE SIEM

  • Every source is collected into one pool; you decide how long records are kept.
  • The rule and correlation engine surfaces a suspicious chain the moment it forms.
  • Click an IP address or a user and the entire history appears on one screen.
  • The panel, the alert emails and the reports are all in Turkish.
  • It runs on your own server; your records never leave your organisation.
Capabilities

Everything a security team needs, in one box

The whole chain, from log collection to automated response, is inside the product. No additional licence, no additional server, no additional agent software.

Vendor-independent log collection

syslog 514 · RFC 3164/5424 · REST API

Palo Alto, Sophos, Check Point, Cisco, SonicWall, WatchGuard, pfSense, MikroTik… it takes records from any device that sends standard syslog. On FortiGate, one-click IP blocking also works over the REST API.

Live attack map

MaxMind GeoLite2 · offline

A rotatable 3D globe fed with real GeoIP data. See at a glance which country an attack came from, what it hit and how serious it is.

Correlation and rules engine

MITRE ATT&CK · chain detection

Combines events that mean nothing on their own: it catches chains such as "20 failed logins in three minutes, then a successful one" and maps them to a MITRE ATT&CK technique.

Behaviour analytics (UEBA)

risk score · anomaly

Builds a normal behaviour profile for every user and device. Out-of-hours access, an unusual location or a sudden data movement surface as a risk score.

Law No. 5651 & TÜBİTAK timestamping

RFC 3161 · integrity seal

Hotspot and internet access records are sealed with an RFC 3161 timestamp. In an audit, the proof that "this record has not been altered" can be demonstrated mathematically.

Log interpretation

raw record preserved · evidence safe

Without altering the raw record, it writes a plain-language explanation beside it: "This is an automated password-guessing attempt against the VPN from a server in France."

Alerts by email and Telegram

SMTP · Telegram bot

Immediate notification on a critical event. Anti-flood protection stops one incident producing hundreds of emails; alerts arrive in Turkish with a suggested action.

Entity 360

IP · user · device

Click an IP or a user: total events, successful and failed logins, first and last seen, threat intelligence matches and blocking status, all on one screen.

PDF reporting and compliance

scheduled · PDF · summary

Weekly and monthly management reports are generated automatically and emailed out. The compliance screen shows where you stand against each requirement as a percentage.

From raw record to action: seven steps

The path a single syslog line from your firewall travels before it becomes a meaningful alert on your screen.

  1. 01

    Source

    Syslog (UDP/TCP 514) from firewalls, switches and servers — the brand does not matter. Plus the Windows agent and Active Directory (LDAP).

  2. 02

    Collection

    Records enter a buffer queue with a capacity of 50,000, are parsed and converted into a common event schema. Processing order is preserved through sudden load spikes.

  3. 03

    Enrichment

    IP to geographic location (offline GeoIP), threat intelligence matching and a plain-language explanation are added.

  4. 04

    Detection

    The rules engine, correlation and behaviour analytics run; the event is mapped to a MITRE ATT&CK technique.

  5. 05

    Storage

    The event is written to the database. Records within the scope of Law No. 5651 are sealed with a TÜBİTAK timestamp.

  6. 06

    Alert

    Email and Telegram notifications go out. If you use FortiGate, the attacking IP can be blocked from the panel in one click over the REST API.

  7. 07

    Screen

    The panel updates live — no need to refresh the page.

Technical stack

We did not put our logo on somebody else’s stack

Every layer — from the server to the panel, from the agent to the installer — was written by Erbe Bilişim. Here is what each layer is built with.

ERBE SIEM technical stack
Layer Technology Language
Sunucu (çekirdek) .NET 10 · ASP.NET Core Web API C#
Web paneli Next.js 15 · React 19 TypeScript
Windows ajanı .NET 10 Worker Service C#
Masaüstü konsol WPF C# / XAML
Veritabanı Entity Framework Core 10 → SQLite / PostgreSQL C# (LINQ)
Kurulum Inno Setup · tek dosya installer Pascal / PowerShell
Licensing

Pay for what you use

Packages are shaped by the modules you select. Prices are not published on this page; a quotation is prepared based on the size of your organisation and the number of sources.

Core

Single location, basic log collection and Law No. 5651 requirements

  • Log collection and central management
  • Overview dashboard
  • Real-time monitoring
  • Search engine
  • Email alerts
Get a Quote
Recommended

Security

Organisations that want active threat monitoring

  • Everything in Core
  • Correlation and rules engine
  • Threat detection (MITRE ATT&CK)
  • Behaviour analytics (UEBA)
  • Threat intelligence
  • Active Threats — IP blocking console
  • TÜBİTAK timestamping
Get a Quote

Enterprise

Multi-branch organisations and service providers

  • Everything in Security
  • All modules enabled
  • Multi-tenant architecture
  • High availability (HA)
  • SOAR automation and API/SDK
  • Priority support
Get a Quote
## Your firewall produces logs. Who reads them? In an average organisation, the firewall, the Windows servers and the guest hotspot produce millions of log lines a day. Those records pile up somewhere, nobody looks at them — and by the time an attack is noticed it is already too late. **Without a SIEM** - Logs sit on the device's own disk and are deleted after a few days - The only way to notice an attack is when "something got slow" - English-language consoles and alert emails nobody reads - No answer to the question of which user did what **With ERBE SIEM** - Every source in one place, with retention under your control - Rules, correlation and behaviour analytics catch an attack as it happens - Turkish-language panel, Turkish alert emails, Turkish reports - Click an IP or a user and get the full 360° history on one screen ## Rather than describe it, let us show you An exact copy of the real panel runs in your browser: live events streaming in, a rotatable attack globe, reports and compliance screens — all open. Nothing to install, no account to create. The demo is read-only; every button that would change something returns a "Demo mode" notice. ## Modular architecture — take only what you need ERBE SIEM is not a single monolithic stack. The core ships with every installation; the rest you enable as you need it and manage later from the panel. Your licence is shaped by the modules you choose. There are also screens that do not appear in the module list because they ship with the panel: Active Threats (the blocking console), VPN Monitoring, Automation and the Audit Log. ## Whichever firewall you run ERBE SIEM is vendor-independent. Every next-generation firewall produces syslog to RFC 3164/5424, and the product reads that standard. You do not have to replace your appliance or buy an additional licence. **Deep integration — Fortinet FortiGate / FortiOS.** On top of syslog collection, the REST API supports one-click IP blocking from the panel and retrieval of historical records from FortiAnalyzer. **Full collection and analysis — every syslog-capable NGFW.** Collection, parsing, correlation, threat detection, alerting and reporting all work. Automated blocking is added on request where the vendor provides an API. Supported: Palo Alto Networks · Sophos XG / XGS · Check Point · Cisco ASA / Firepower · SonicWall · WatchGuard · Juniper SRX · Huawei USG · Zyxel USG · pfSense / OPNsense · MikroTik · Turkish vendors. **Beyond the firewall — servers, directory and network.** Security does not end at the firewall. User and file activity is collected onto the same timeline. Sources: Windows Server (agent) · Active Directory (LDAP) · file servers · hotspot · switches and routers · VPN gateways. > Have a device that is not on the list? Send us a sample log line and we will write the parser and add it to the release, free of charge. ## The panel — all in Turkish The panel was designed for the person running the business, not for a security specialist. Menus, event descriptions, alert emails and reports are in Turkish; the abbreviations the industry has settled on (MITRE, UEBA, SOAR) are explained in Turkish the first time they appear. - **Monitoring:** Overview · Events · Devices · Hotspot / Law No. 5651 - **Security:** Threat Detection · Active Threats · Behaviour Analytics · Threat Intelligence · Digital Risk Protection - **Compliance and records:** Timestamping · Compliance · Reports - **System:** Alerts · Log Interpretation · Settings ## Deployment and operation - **One service, one port:** the API, the syslog listener and the web panel all run inside the same Windows service. No separate web server, Node.js or IIS installation is required. - **Works without internet:** no external CDN, external font or cloud service dependency. Even the GeoIP database is local. It runs cleanly on isolated networks. - **Safe to upgrade:** a new release installs over the existing one; your database, settings and module selections are preserved. Even uninstalling does not delete your records. - **Storage that scales:** the default SQLite works immediately in smaller organisations; at high volume you move to PostgreSQL by changing a single setting.

Frequently Asked Questions

Where does our data go?

Nowhere. ERBE SIEM runs entirely on-premise — on your own server. Logs, user information and reports never leave your machine. It also works on isolated networks with no internet connection.

How long does installation take and what does it need?

You run a single installer; the wizard asks which modules you want and handles the rest. A typical installation takes 15 to 30 minutes. Windows Server (or Windows 10/11) is enough; no separate database server, web server or Node.js is required.

Does it only work with Fortinet?

No — the product is vendor-independent. Every next-generation firewall produces syslog to RFC 3164/5424; ERBE SIEM parses those records, normalises them, runs correlation and stores them in them within the scope of Law No. 5651. Any device that sends syslog can be a source, including Palo Alto, Sophos, Check Point, Cisco, SonicWall, WatchGuard, Juniper, Huawei, Zyxel, pfSense/OPNsense, MikroTik and Turkish vendors.

On Fortinet there is an additional REST API integration: one-click IP blocking from the panel and retrieval of historical records from FortiAnalyzer work only on FortiGate. On other brands, collection, detection, alerting and reporting all work in full; automated blocking over an API is added on request.

Is it really enough for Law No. 5651?

Yes. Hotspot and internet access records are collected and sealed with a TÜBİTAK timestamp (RFC 3161). This proves cryptographically that the record existed at the stated moment and has not been altered since — in an audit, the chain of evidence can be demonstrated mathematically.

The raw record is never modified. The plain-language explanation the product adds is kept in a separate field, leaving the original line exactly as received. The panel also carries an audit trail showing who changed what and when.

ERBE SIEM has passed TRTEST testing.

Do I need to employ a security specialist to use the panel?

No — that is precisely the product's core design goal. Events are explained in plain language, severity is shown by colour and label, and alert emails are written in a "what happened / what you should do" form. We walk through it with you once during installation.

Does the AI feature send our data outside?

The AI-assisted analysis module is off by default. If you choose to enable it, which data is processed is entirely under your control. While it is off, no component of the product sends data to an external service.

How many devices and how much log volume does it support?

In small and medium-sized organisations the default SQLite configuration is sufficient. In high-volume environments (heavy traffic profiles, many locations) you move to PostgreSQL by changing a single setting. We establish the right profile with you.

Will I lose my settings when I move to a new version?

No. The installer is upgrade-safe: the database is kept in a separate location, your configuration file is preserved and your module selection is not overwritten. Even if you uninstall the product completely, your records are not deleted.

How do support and updates work?

Updates and support are included for the duration of the licence. Installation, initial configuration and user training are carried out by Erbe Bilişim. You can request support remotely or on site.