ANOMAL consulting

Elastic and SIEM consulting: data model, detection and migration

ANOMAL advises on building, migrating and tuning SIEM environments, primarily on Elastic and Microsoft Sentinel. The mandate covers data model and ingest architecture, onboarding of new log sources, detection engineering with version control, and playbook and automation development. Outcomes are measurable, such as coverage per MITRE tactic and fewer noisy rules, not just a concept paper. Every mandate is scoped individually and gets a dedicated quote.

All

Data model and ingest architecture

  • ECS (Elastic Common Schema) mapping for consistent field names across sources, a prerequisite for portable detection rules.
  • Index lifecycle management: hot, warm, cold and frozen tiers matched to query frequency and retention obligations.
  • Retention tiers tailored to regulatory requirements and operational needs.
  • Cost per ingested GB as a steering metric: which source justifies full indexing, which is fine as archive or rollup.

Onboarding new log sources

We onboard new sources (firewalls, cloud audit logs, identity providers, applications) using the same process. We validate parsing, check field normalisation against ECS and estimate volume before going live. Faulty parsers are the most common cause of blind spots in existing SIEM environments.

Detection engineering

  • Use-case development from threat model to concrete rule, with documented rationale for which tactic or technique is covered.
  • Tuning against false positives: per-environment baseline, exclusion lists, threshold adjustment instead of blanket rule muting.
  • Detection-as-code: rules versioned in Git, tested before rollout and reviewed like application code.
  • Playbook and automation development for recurring alert types, including connection to SOAR logic. The SOAR glossary explains what SOAR does.

Migration and health assessment

For existing SIEM deployments we first assess the current state: unused rules, duplicate data sources, unclear ownership, cost per query. We migrate between platforms in stages, running them in parallel to prevent detection gaps. This includes migrations from a legacy SIEM to Elastic or Microsoft Sentinel. See SOC with Elastic Security and SOC with Microsoft 365 Sentinel for details on operating both platforms.

Measurable outcomes

  • Coverage per MITRE ATT&CK tactic as evidence of where detection gaps exist and where they were closed.
  • Reduction of noisy rules, measured by the number of rules with a high false-positive rate before and after tuning.
  • Reliable detection underpins stable MTTD/MTTR values in ongoing SOC operations. See SIEM in the glossary for detection foundations and MTTD and MTTR for operational metrics.

How this compares to neighbouring topics

OfferingCharacterWhen it fits
SIEM engineering consulting (this offering)Time-boxed project: data model, detection engineering, migration.An architecture decision or migration is due, or the existing SIEM is noisy or incomplete.
Managed SIEM operationsContinuous operations including tuning and alert triage.You need ongoing operations; see SOC as a Service Switzerland.
SOC consultingBroader target picture: processes, roles, operating model around the SOC.SIEM is just one building block of a larger SOC build, see SOC consulting and build.
Pure log managementCollecting and retaining logs without detection logic.Only a retention obligation matters; you do not need active detection.

Placement in SOC operations

A clean data model and tuned detection rules are the foundation of any 24/7 SOC operation. SOC as a Service Switzerland describes the overall framework, including roles and escalation. For an overview of all consulting disciplines see Security consulting Switzerland.

Frequently asked questions

Does ANOMAL only work with Elastic?

ANOMAL works primarily with Elastic and also operates and provides consulting on Microsoft Sentinel as a second platform. We recommend either platform based on your environment and existing licensing.

What does SIEM consulting cost?

There is no list price. Scope depends on data volume, number of sources and target architecture. Every mandate gets a dedicated quote after scoping; for general cost logic see [SOC cost Switzerland](/en/soc/soc-cost-switzerland).

Does ANOMAL take over ongoing SIEM operations afterwards?

ANOMAL can take over ongoing operations if you choose. After implementation support and knowledge transfer, the internal team can take over, or the mandate can transition into managed SOC operations.

What does detection-as-code mean in practice?

We version detection rules in a Git repository, test them before rollout and review them like application code. This prevents silent rule changes and makes regressions visible.

Is a health assessment possible without a subsequent migration?

Yes. A health assessment stands on its own and delivers an overview of unused rules, cost and gaps. Whether you migrate afterwards or just optimise is your decision based on the result.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
SOC on Elastic Security: what ANOMAL delivers for existing customers
ANOMAL runs a 24/7 SOC for organisations already invested in Elastic Security. We manage detection engineering, response and threat hunting on your Elastic cluster. We correlate logs, endpoint, identity and cloud signals in one platform and handle documented response. Elastic is your platform, and ANOMAL is your operations team.
SOC for Microsoft 365 and Sentinel: what matters
A SOC for Microsoft 365 and Sentinel environments correlates signals from Entra ID, Defender XDR, Exchange Online and Azure in one detection layer. It responds 24/7. Analysts, playbooks and documented response provide the operational value beyond the licence.
SIEM
SIEM stands for Security Information and Event Management. A SIEM platform aggregates logs from endpoints, network and cloud, correlates them through rules and produces alerts for detection, compliance and forensics. Without analysts it stays a searchable archive, not security.
SOAR
SOAR stands for Security Orchestration, Automation and Response. It provides the automation and playbook layer above SIEM and EDR. It triggers repeatable response steps, such as disabling a user, isolating a host or opening a ticket. Without clean detection underneath, SOAR mostly automates noise; SOAR is therefore not a replacement for a SOC but a tool used inside one.