Skip to main content

Detection

Logging & Log Centralisation

Collect the OT logs that matter, safely, and retain them long enough to investigate.

Defensive guide

Why should I care?

Investigations depend on evidence that must already exist when the incident starts.

How to implement it

  • Prioritise: boundary firewalls, remote access, authentication, engineering hosts, controller change events
  • Forward from OT to a collector via the DMZ; never let the SIEM query into control zones
  • Retain long enough to cover the dwell times seen in documented OT intrusions

What good looks like

  • Time-synchronised logs across OT
  • Retention aligned to investigation needs

Common failure modes

  • Agents installed on fragile systems without vendor approval
  • Log volume so noisy it is never reviewed

How to verify it

  • Pick a recent change and reconstruct it entirely from logs