Why this exists

The problem Atlas Observe solves

Without Atlas Observe

A server goes down at 03:00. Nobody knows until users complain at 09:00. Logs exist on each server individually but there is no central collection — an engineer must SSH into 20 machines to piece together a timeline. A compliance auditor asks how long it takes to detect a security event. The honest answer is: we do not know.

With Atlas Observe

Zabbix detects a service outage within 60 seconds and pages the on-call engineer. Graylog correlates firewall, IDS, and application logs — a port scan followed by a failed login from an unknown IP triggers an alert in under 90 seconds. OpenSearch stores 90 days of logs. When a compliance auditor asks for the incident timeline, the Graylog export is ready in minutes.

Architecture

How it works

Atlas Observe — data flows from infrastructure sources into Zabbix Graylog and Prometheus
Architecture overview — Atlas Observe component relationships

Regulatory compliance

What Atlas Observe satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(b)Continuous monitoring enables breach detection within the 72h notification windowGraylog alert log · incident detection timestamp
NIS2 Art. 23SIEM provides the timeline and evidence for competent authority notificationGraylog event export · OpenSearch query results
DORA Art. 17(3)ICT incident classification, detection, and notification pipelineGraylog stream alert history · severity classification log
BSI DER.1.1Centralised log collection, correlation rules, alert escalation documentedGraylog stream config export · alert rule documentation
BSI OPS.1.1.5All relevant systems log to central SIEM with tamper-evident storageOpenSearch index retention policy · log integrity check
GDPR Art. 33SIEM must detect personal data breach within 72h of occurrenceGraylog alert timestamp · notification audit trail

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

Zabbix monitoring — standalone

Zabbix 7.x server. Agent on up to 20 hosts. SNMP v3 for network devices. Pre-built templates for Linux, Windows, OPNsense, switches. Email and Slack alerting. 5-day post-install support.

  • Zabbix 7.x server + frontend
  • Agent on up to 20 hosts
  • SNMP v3 for network devices
  • Pre-built templates
  • Email + Slack alerting
  • 5-day post-install support

€ 990

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Graylog SIEM — standalone

Graylog 5.x + OpenSearch 2.x. Syslog from up to 5 sources. Windows event log via Winlogbeat. Basic correlation: failed login threshold, port scan detection. 30-day index retention.

  • Graylog 5.x + OpenSearch 2.x
  • Syslog from up to 5 sources
  • Winlogbeat for Windows events
  • Basic correlation rules
  • 30-day retention policy
  • 5-day post-install support

€ 1,190

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Grafana + Prometheus — standalone

Prometheus 2.x + Grafana 10.x. Node_exporter on up to 10 hosts. Blackbox exporter for endpoint monitoring. 3 custom dashboards. AlertManager rules for resource thresholds.

  • Prometheus + Grafana install
  • Node_exporter on 10 hosts
  • Blackbox + AlertManager
  • 3 custom dashboards
  • Alerting rules
  • 5-day post-install support

€ 790

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. Full Atlas Observe integration — connecting it into your existing environment — starts with an audit engagement.

Full integration

Foundation · Plus · Enterprise

Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.

Foundation

5–50 users · 1 site · 1 month on-site

1 month on-site

from € 14,400

Net, excl. VAT · fixed price scoped by audit

  • Zabbix single node
  • SNMP for network devices
  • Syslog from Atlas Perimeter
  • Basic Grafana dashboard
  • Email alerting
  • 30-day log retention
Request audit to start
Enterprise

500+ users · multi-site · 6 months on-site

6 months on-site

from € 102,000

Net, excl. VAT · fixed price scoped by audit

  • Zabbix distributed proxies
  • Graylog + OpenSearch cluster
  • ML anomaly detection
  • SOAR integration (TheHive)
  • NIS2/DORA compliance dashboards
  • 1-year log retention
  • ISO 27001 evidence package
Request audit to start

Start with an audit

All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.

Request audit engagement