Atlas Observe
Monitoring & SIEM
Every outage, port scan, and failed login surfaced in seconds — open-source monitoring and SIEM you run in-house, so your logs never leave the building.
Why this exists
Without Atlas Observe
A server goes down at 03:00. Nobody knows until users complain at 09:00. Logs exist on each server individually but there is no central collection — an engineer must SSH into 20 machines to piece together a timeline. A compliance auditor asks how long it takes to detect a security event. The honest answer is: we do not know.
With Atlas Observe
Zabbix detects a service outage within 60 seconds and pages the on-call engineer. Graylog correlates firewall, IDS, and application logs — a port scan followed by a failed login from an unknown IP triggers an alert in under 90 seconds. OpenSearch stores 90 days of logs. When a compliance auditor asks for the incident timeline, the Graylog export is ready in minutes.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(b) | Continuous monitoring enables breach detection within the 72h notification window | Graylog alert log · incident detection timestamp |
| NIS2 Art. 23 | SIEM provides the timeline and evidence for competent authority notification | Graylog event export · OpenSearch query results |
| DORA Art. 17(3) | ICT incident classification, detection, and notification pipeline | Graylog stream alert history · severity classification log |
| BSI DER.1.1 | Centralised log collection, correlation rules, alert escalation documented | Graylog stream config export · alert rule documentation |
| BSI OPS.1.1.5 | All relevant systems log to central SIEM with tamper-evident storage | OpenSearch index retention policy · log integrity check |
| GDPR Art. 33 | SIEM must detect personal data breach within 72h of occurrence | Graylog alert timestamp · notification audit trail |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
Zabbix monitoring — standalone
Zabbix 7.x server. Agent on up to 20 hosts. SNMP v3 for network devices. Pre-built templates for Linux, Windows, OPNsense, switches. Email and Slack alerting. 5-day post-install support.
€ 570
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGraylog SIEM — standalone
Graylog 5.x + OpenSearch 2.x. Syslog from up to 5 sources. Windows event log via Winlogbeat. Basic correlation: failed login threshold, port scan detection. 30-day index retention.
€ 720
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGrafana + Prometheus — standalone
Prometheus 2.x + Grafana 10.x. Node_exporter on up to 10 hosts. Blackbox exporter for endpoint monitoring. 3 custom dashboards. AlertManager rules for resource thresholds.
€ 410
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteReady-made boxes
Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.
5–50 users · 1 site · single server
€ 2,190
Net, excl. VAT · one-off fixed price · hardware not included
50–500 users · 1–5 sites · HA-ready
€ 2,940
Net, excl. VAT · one-off fixed price · hardware not included
500+ users · multi-site · cluster-ready
€ 3,650
Net, excl. VAT · one-off fixed price · hardware not included
Consulting services
The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.
Installation & handover
We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.
€ 890
Net, excl. VAT · fixed price
Request this packageIntegration into your environment
Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.
€ 1,890
Net, excl. VAT · fixed price
Request this packageCompliance mapping & audit support
We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.
€ 1,490
Net, excl. VAT · fixed price
Request this packageCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz