Log Monitoring and SIEM Powered by CrowdStrike Falcon
Brian Long
Introduction
Endpoint protection sees what happens on each computer. A security information and event management (SIEM) platform sees everything else: firewalls, servers, cloud services, and Microsoft 365, correlated into one picture. It’s how you catch a failed VPN login followed by a successful one from another country, or a compromised service account quietly touching every server.
Log monitoring is part of every Cyber Protection Package, watched around the clock by security analysts. In the Cyber Protection Package with CrowdStrike Falcon, it runs on CrowdStrike Falcon Next-Gen SIEM. It’s also where compliance-ready reporting comes from: the evidence auditors and insurers ask for, produced continuously instead of scrambled together once a year.
- Network: Firewalls, routers, switches, and VPNs
- Servers: Windows and Linux servers and the applications on them
- Cloud: Microsoft Azure and Amazon Web Services activity
- Microsoft 365: Sign-ins, admin changes, mail forwarding rules, and SharePoint and Teams activity
- Firewall anomalies and suspicious remote access
- Unusual server behavior and compromised service accounts
- Suspicious authentication patterns across systems
- Attackers moving through your network in ways a single computer wouldn’t reveal
- Log retention: Keep security logs for the period your framework requires, typically 90 days to a year or more.
- Frameworks: Supports monitoring and retention requirements for HIPAA, PCI DSS, and cyber insurance. Ask us about other frameworks.
- Continuous evidence: Monitoring, alerts, and responses are recorded as they happen, ready when an auditor or insurer asks.
| Option | Best for |
|---|---|
| Cyber Protection Package with CrowdStrike Falcon | Small and medium businesses: log monitoring together with 24/7 monitoring and response, endpoint protection, and identity and email threat detection |
| Standalone SIEM | Enterprise organizations that already have endpoint protection and need managed log monitoring and retention |
Works With Your Cyber Protection Package
In the package, log data is monitored together with endpoint detection and response and identity and email threat detection, so an attack is seen from every angle at once.
Facing an audit or a log-retention requirement? Contact us to talk about your environment.
CrowdStrike and Falcon are trademarks of CrowdStrike, Inc.