Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
Case studies

ERBE SIEM Field Deployments

The security monitoring platform we built ourselves, live at two organisations in Istanbul.

A server rack connected to a monitoring panel showing a waveform, on a dark navy background
01

Problem

In an average organisation, the firewall, the Windows servers and the guest hotspot produce millions of log lines a day. Those records pile up somewhere, nobody looks at them — and by the time an attack is noticed it is already too late. The monitoring products on the market either require a security specialist to work through an English-language console, or they move the records to the cloud. There was no option that the person running the business could read and that kept the data inside the organisation.
02

Solution

ERBE SIEM was installed on the organisation's own server from a single installer; firewall, Windows server and hotspot records were collected into one place over syslog. The rules engine, correlation and behaviour analytics were enabled; events were mapped to MITRE ATT&CK techniques and each record was annotated with a plain-language explanation in Turkish. The panel, the alert emails and the reports are all in Turkish. The product runs entirely on-premise — no data is sent to an external service.
03

Result

In the first 24 hours, 262 external attack attempts from 104 distinct IP addresses were recorded. Most were routine noise from cloud scanners; the system identified and surfaced an automated bot making 16 failed SSL-VPN login attempts within one second from a hosting server in France. Another address near the top of the list turned out to be the organisation's own mail gateway, established within minutes by looking at its history on the Entity 360 screen: thousands of successful staff logins from the same address marked it as an infrastructure component, not an attacker. The decision belongs to a person; the panel simply gathers the evidence for that decision onto one screen. Over the same period, the volume of data transferred to the cloud was zero — the records stayed on the organisation's own server.
## The first 24 hours, in numbers - **262** — external attack attempts in 24 hours - **104** — distinct source IP addresses - **16** — VPN attempts in one second (a single bot) - **0** — cloud transfer: the data stayed on site ## Technical build We did not put a logo on an off-the-shelf open source stack. From the server through to the panel it is original code: the core on .NET 10 and ASP.NET Core Web API, the web panel in Next.js 15, the data layer on Entity Framework Core and the desktop console in WPF. The API, the syslog listener and the web panel all run inside the same Windows service; no separate web server, Node.js or IIS installation is required. > The deployment was carried out at an organisation operating in the hospitality sector in Istanbul. The customer name, device names and network details are not disclosed, as no written permission is on record.

Project facts

Sector
Konaklama ve kurumsal ağ

Technology stack

  • .NET 10
  • ASP.NET Core
  • Next.js 15
  • EF Core
  • WPF
View the project

erbebilisim.com