Atlas Observe
Monitoring & SIEM
Every outage, port scan, and failed login surfaced in seconds — open-source monitoring and SIEM you run in-house, so your logs never leave the building.
Why this exists
Without Atlas Observe
A server goes down at 03:00. Nobody knows until users complain at 09:00. Logs exist on each server individually but there is no central collection — an engineer must SSH into 20 machines to piece together a timeline. A compliance auditor asks how long it takes to detect a security event. The honest answer is: we do not know.
With Atlas Observe
Zabbix detects a service outage within 60 seconds and pages the on-call engineer. Graylog correlates firewall, IDS, and application logs — a port scan followed by a failed login from an unknown IP triggers an alert in under 90 seconds. OpenSearch stores 90 days of logs. When a compliance auditor asks for the incident timeline, the Graylog export is ready in minutes.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(b) | Continuous monitoring enables breach detection within the 72h notification window | Graylog alert log · incident detection timestamp |
| NIS2 Art. 23 | SIEM provides the timeline and evidence for competent authority notification | Graylog event export · OpenSearch query results |
| DORA Art. 17(3) | ICT incident classification, detection, and notification pipeline | Graylog stream alert history · severity classification log |
| BSI DER.1.1 | Centralised log collection, correlation rules, alert escalation documented | Graylog stream config export · alert rule documentation |
| BSI OPS.1.1.5 | All relevant systems log to central SIEM with tamper-evident storage | OpenSearch index retention policy · log integrity check |
| GDPR Art. 33 | SIEM must detect personal data breach within 72h of occurrence | Graylog alert timestamp · notification audit trail |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
Zabbix monitoring — standalone
Zabbix 7.x server. Agent on up to 20 hosts. SNMP v3 for network devices. Pre-built templates for Linux, Windows, OPNsense, switches. Email and Slack alerting. 5-day post-install support.
€ 990
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGraylog SIEM — standalone
Graylog 5.x + OpenSearch 2.x. Syslog from up to 5 sources. Windows event log via Winlogbeat. Basic correlation: failed login threshold, port scan detection. 30-day index retention.
€ 1,190
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGrafana + Prometheus — standalone
Prometheus 2.x + Grafana 10.x. Node_exporter on up to 10 hosts. Blackbox exporter for endpoint monitoring. 3 custom dashboards. AlertManager rules for resource thresholds.
€ 790
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 14,400
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 48,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 102,000
Net, excl. VAT · fixed price scoped by audit
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz