Use case · Enterprise & Campus · Critical Infrastructure

Asset context for the SIEM and SOC

SOC coverage extended to devices that cannot run an agent or send logs.

  1. 01

    Challenge

    The SIEM has logs from everything except the devices that cannot log: controllers, clinical devices, cameras.

  2. 02

    What WireTrace sees

    Network evidence for the devices that produce no logs of their own.

  3. 03

    What WireTrace understands

    Identity, role and risk for each device that appears in an alert.

  4. 04

    What WireTrace decides

    Which alerts to forward, filtered by type and severity.

  5. 05

    Integration / action

    Syslog in CEF, LEEF or RFC 5424/3164, Splunk HTTP Event Collector, webhooks and the REST API.

  6. 06

    Outcome

    SOC coverage extended to devices that cannot run an agent or send logs.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.