Managed SIEM Service

Service Definition • Armstrong Bell • 8 August 2026

Document summary

This document sets out what's included in our Managed Security Information and Event Management (SIEM) solution.

Core service provision

Our Managed SIEM service is designed to provide a comprehensive monitoring, alerting and response service for cyber threats. The service collects data from a wide range of sources in a customer environment, reviewing it for signals of compromise or suspicious activity, with alerts individually reviewed to determine whether further action is required.

The service enables the collection of log data and forwards this to a centralised SIEM platform, where a team of security experts collaborates with our team to investigate any signs of suspicious activity for a customer. Our team are on hand to provide customer-specific knowledge and assist with remediation activities should these be required.

Service desk support

Customers can raise queries directly with our dedicated support team for assistance. Typical requests include:

  • Setting up log sources, such as Windows Event Logs and Syslog

  • Support for resolving issues related to log collection, alerting, or integration with existing systems

  • Information about the capabilities of the Managed SIEM service and how it can be tailored to meet specific needs

Service coverage is provided in line with the customer's existing Managed IT Service support contract.

Alert management

Any alerts received from our partner are sent directly to our service team for investigation. Typically these alerts will be for possible suspicious or unusual activity, as well as notifications for maintenance activities. All items are individually reviewed by our team, and customers are engaged where applicable to ensure they receive the required information.

Available reporting

A periodic SIEM data and events report is available to customers, typically produced on a quarterly basis. These reports are discussed in service review meetings to ensure an expert is on hand to answer any queries customers may have.

Vendor escalation

Our team collaborates with our preferred partner for SIEM and Security Operations Centre services, ensuring investigations are conducted swiftly and troubleshooting is carried out as required. Issues such as log collection or agent-based reporting are investigated by both organisations jointly.

Addition of new features

Where a new feature is introduced to the platform that would benefit a customer, the required changes are reviewed by our team to ensure they are suitable for implementation. If the change requires disruption to service, or an adjustment to core components that may alter existing functionality, this will be communicated to the customer and a route forward agreed.

For any additional functionality requiring considerable work and/or integration, these items will be scoped and discussed independently with the customer.

Onboarding

  • SIEM configuration

    • Configure SIEM platform for customer tenant

    • Configure pre-approved remediation steps for detected alerts

  • Configure log sources

    • Deploy agent to Windows devices

    • Implement Syslog collection for network and other devices

    • Confirm logs are received from all sources into the SIEM

  • Execution and monitoring

    • Review initial log collection for any identified activities that require investigation or re-configuration