Open-source SIEM, running on-premise

Open-source SIEM, XDR and continuous threat hunting

We deploy an open-source SIEM/XDR infrastructure built on Wazuh and the ELK Stack on your own servers and, if required, fully offline (on-premise, on your own hardware). On-premise AI correlates the logs and automates threat hunting. No expensive licences; your logs and incident data stay in-house.

Explainer

What are SOC, SIEM and XDR?

SIEM (security information and event management) gathers every log source in the organization into one central place and correlates them, making attacks visible. XDR extends that visibility across servers, network and endpoints; the SOC then runs this monitoring continuously as a security operations discipline. For most organizations the critical question is usually not the technology itself but where the logs are processed and stored. Sending sensitive security data to cloud services is unacceptable for most public sector and critical infrastructure organizations.

C3T is not a product vendor; we are the implementing and operating partner. We deploy the open-source stack (Wazuh, ELK Stack, TheHive) securely on your own infrastructure, tune it to your organization and keep it running.

How does an open-source SIEM/SOC work?

An open-source SIEM collects and correlates the organization's server, network and endpoint logs in one central place using Wazuh and the ELK Stack. C3T deploys this infrastructure on the organization's own servers, offline (air-gapped). There are four layers: (1) SIEM and log management — centralised collection and auditable storage; (2) XDR — extended detection across servers, network and endpoints; (3) SOAR — autonomous isolation through TheHive and Shuffle playbooks; (4) threat hunting — sifting through millions of logs with on-premise AI and detecting anomalies. Logs and incident data never leave the organization; the system runs on-premise. It is designed to comply with the logging/monitoring obligations of Law No. 5651, BİGR, KVKK Art. 12 and ISO 27001 A.12.4.

SOC/SIEM scope: four layers

We build security monitoring in four layers: log management, XDR, SOAR automation and threat hunting. All four run on-premise and are fully auditable.

SIEM and log management

Collects, correlates and stores server, network and application logs in one central place.

  • Wazuh + ELK Stack (Elasticsearch / Logstash / Kibana)
  • Centralised log collection and normalisation
  • Auditable, integrity-protected records
  • Law No. 5651 and BİGR compliant log retention

XDR — extended detection and response

Monitors servers, network and endpoints on a single platform with Wazuh agents.

  • Endpoint, server and network visibility
  • File integrity and configuration monitoring
  • Vulnerability and threat detection
  • Correlated attack chain analysis

SOAR — automation and autonomous isolation

Generates an automated, playbook-driven response to every detected threat.

  • TheHive + Shuffle playbook automation
  • Case management and workflow
  • Autonomous isolation of suspicious assets
  • Hand-off into the incident response workflow

Threat hunting and intelligence

Sifts through logs with on-premise AI and hunts for weak signals.

  • Log correlation with on-premise AI
  • Anomaly and unusual behaviour detection
  • Leaked credential and dark web monitoring
  • Prioritised, continuous threat hunting

The open-source stack we use

Mature open-source technologies and on-premise AI instead of commercial licences — lower cost, full data sovereignty, no vendor lock-in.

Wazuh + ELK Stack

The open-source core: SIEM, XDR, log collection, file integrity and vulnerability detection on a single platform. No licence cost, and it scales on your own infrastructure.

TheHive + Shuffle

Case management and SOAR automation: alerts are gathered in a single console and prioritised by playbook; suspicious assets are isolated autonomously to stop the spread.

On-premise AI correlation

AI that sifts through millions of log lines on your own servers, flagging anomalies and attack chains. The model runs on-premise, so log data does not leave the organization during analysis either.

Why C3T?

We do not simply install the SIEM/XDR and hand it over; we operate it, manage the alerts and keep your data in-house. Our hands-on approach comes down to two principles.

We build it, deploy it and operate it

We bring the SIEM/XDR infrastructure to life from scratch, tune the rule sets to your organization, manage the alerts and run the incident response workflow. We do not write a report and walk away; we take responsibility for deployment, monitoring and continuous improvement.

Your data stays in-house (on-premise)

The log store, the SIEM and the AI correlation all run on your own servers, offline if required. The same on-premise AI story sits at the heart of our entire security line; data sovereignty is part of the design.

Compliance obligations

Which obligations does it meet?

The log management and monitoring infrastructure we deploy is designed to meet the main logging/monitoring obligations of the public and private sectors. Logs are auditable, integrity-protected and stored on your own infrastructure.

BİGR — logging / monitoring

Logging and monitoring requirements of Turkey's Information and Communication Security Guide

KVKK Art. 12 — technical measures

Obligation to detect breaches and monitor security incidents

Law No. 5651 — logging

Retention of access and transaction records

ISO 27001 A.12.4 — logging/monitoring

Event logging and monitoring control

For full compliance, see KVKK, ISO 27001 and BİGR compliance consulting and on-premise AI.

Frequently asked questions

Is open-source SIEM as reliable as commercially licensed solutions?

Yes. Wazuh and the ELK Stack (Elasticsearch, Logstash, Kibana) are mature open-source technologies backed by large communities, and they align with official policy that prioritises open-source software in the public sector. The difference is not in security but in cost and vendor lock-in: enterprise-grade log monitoring and threat detection go live without expensive annual licence fees.

Do our logs and security data ever leave the organization?

No. The SIEM, the log store and the AI correlation layer run on your own servers, on-premise and, if required, fully offline (air-gapped). Logs, alerts and incident data never leave your organization, so KVKK (Turkish Personal Data Protection Law) technical-measure obligations and data sovereignty are both preserved.

What is Wazuh, and why do you prefer it?

Wazuh is a SIEM and XDR core that brings server, network and endpoint agents together on a single open-source platform. We choose it as the core because it provides log collection, file integrity monitoring, vulnerability detection and event correlation in one place, scales with the ELK Stack, and runs on your own infrastructure with no licence cost.

Does it meet the Law No. 5651 and BİGR logging obligations?

Yes. The log management infrastructure we deploy is designed to meet the record-keeping requirements under Law No. 5651, the logging/monitoring requirements of BİGR (Turkey's Information and Communication Security Guide) and the ISO 27001 A.12.4 logging and monitoring controls. Logs are auditable, integrity-protected and stored within your organization.

Do you only install it, or do you operate it afterwards as well?

C3T is not a consultancy that writes a report and walks away; we are the team that delivers and operates. We deploy the SIEM/XDR infrastructure, tune the rule sets to your organization, manage the alerts and run the incident response workflow. We take responsibility for deployment, monitoring and continuous improvement.

What exactly does on-premise AI do in log monitoring?

It sifts through millions of log lines at a speed no human eye can match, flagging unusual behaviour, correlated attack chains and weak signals, and brings them to the analyst in priority order. Because the model runs on your own servers, log data does not leave the organization during analysis either.

Is SIEM/SOC the right fit for your organization?

Let's assess your existing log sources and monitoring needs together. In a free security feasibility call we will clarify which open-source SIEM/XDR architecture can be deployed without your data ever leaving the organization.