Elastic and SIEM consulting: data model, detection and migration
ANOMAL advises on building, migrating and tuning SIEM environments, primarily on Elastic and Microsoft Sentinel. The mandate covers data model and ingest architecture, onboarding of new log sources, detection engineering with version control, and playbook and automation development. Outcomes are measurable, such as coverage per MITRE tactic and fewer noisy rules, not just a concept paper. Every mandate is scoped individually and gets a dedicated quote.
Data model and ingest architecture
- ECS (Elastic Common Schema) mapping for consistent field names across sources, a prerequisite for portable detection rules.
- Index lifecycle management: hot, warm, cold and frozen tiers matched to query frequency and retention obligations.
- Retention tiers tailored to regulatory requirements and operational needs.
- Cost per ingested GB as a steering metric: which source justifies full indexing, which is fine as archive or rollup.
Onboarding new log sources
We onboard new sources (firewalls, cloud audit logs, identity providers, applications) using the same process. We validate parsing, check field normalisation against ECS and estimate volume before going live. Faulty parsers are the most common cause of blind spots in existing SIEM environments.
Detection engineering
- Use-case development from threat model to concrete rule, with documented rationale for which tactic or technique is covered.
- Tuning against false positives: per-environment baseline, exclusion lists, threshold adjustment instead of blanket rule muting.
- Detection-as-code: rules versioned in Git, tested before rollout and reviewed like application code.
- Playbook and automation development for recurring alert types, including connection to SOAR logic. The SOAR glossary explains what SOAR does.
Migration and health assessment
For existing SIEM deployments we first assess the current state: unused rules, duplicate data sources, unclear ownership, cost per query. We migrate between platforms in stages, running them in parallel to prevent detection gaps. This includes migrations from a legacy SIEM to Elastic or Microsoft Sentinel. See SOC with Elastic Security and SOC with Microsoft 365 Sentinel for details on operating both platforms.
Measurable outcomes
- Coverage per MITRE ATT&CK tactic as evidence of where detection gaps exist and where they were closed.
- Reduction of noisy rules, measured by the number of rules with a high false-positive rate before and after tuning.
- Reliable detection underpins stable MTTD/MTTR values in ongoing SOC operations. See SIEM in the glossary for detection foundations and MTTD and MTTR for operational metrics.
How this compares to neighbouring topics
| Offering | Character | When it fits |
|---|---|---|
| SIEM engineering consulting (this offering) | Time-boxed project: data model, detection engineering, migration. | An architecture decision or migration is due, or the existing SIEM is noisy or incomplete. |
| Managed SIEM operations | Continuous operations including tuning and alert triage. | You need ongoing operations; see SOC as a Service Switzerland. |
| SOC consulting | Broader target picture: processes, roles, operating model around the SOC. | SIEM is just one building block of a larger SOC build, see SOC consulting and build. |
| Pure log management | Collecting and retaining logs without detection logic. | Only a retention obligation matters; you do not need active detection. |
Placement in SOC operations
A clean data model and tuned detection rules are the foundation of any 24/7 SOC operation. SOC as a Service Switzerland describes the overall framework, including roles and escalation. For an overview of all consulting disciplines see Security consulting Switzerland.
Frequently asked questions
Does ANOMAL only work with Elastic?
ANOMAL works primarily with Elastic and also operates and provides consulting on Microsoft Sentinel as a second platform. We recommend either platform based on your environment and existing licensing.
What does SIEM consulting cost?
There is no list price. Scope depends on data volume, number of sources and target architecture. Every mandate gets a dedicated quote after scoping; for general cost logic see [SOC cost Switzerland](/en/soc/soc-cost-switzerland).
Does ANOMAL take over ongoing SIEM operations afterwards?
ANOMAL can take over ongoing operations if you choose. After implementation support and knowledge transfer, the internal team can take over, or the mandate can transition into managed SOC operations.
What does detection-as-code mean in practice?
We version detection rules in a Git repository, test them before rollout and review them like application code. This prevents silent rule changes and makes regressions visible.
Is a health assessment possible without a subsequent migration?
Yes. A health assessment stands on its own and delivers an overview of unused rules, cost and gaps. Whether you migrate afterwards or just optimise is your decision based on the result.
Related terms
- SIEM A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.
- Detection as Code Detection as Code manages detection rules like software: versioned, tested, reviewed and deployed automatically.
- Correlation Rule A correlation rule links events from various sources and triggers an Alert when a defined pattern is matched.
- Log Source A log source is any system that provides security-relevant events to a SIEM or the SOC.
- Sigma Rules Sigma rules describe detection logic for logs in an open format that can be translated for many SIEM platforms.