Product Description
MicroSIEM is the ultimate solution for automated hardening and continuous monitoring of Linux infrastructure. Designed for SMEs and startups that require enterprise-grade protection without the complexity of traditional SIEMs, MicroSIEM transforms vulnerable servers into fortified systems that meet international standards.
Through an intuitive web console, MicroSIEM allows you to apply security configurations based on established best practices (CIS Benchmarks, NIST, DISA STIG) and to monitor in real time any suspicious or non-compliant activity. The system automatically detects assets in the network, applies custom hardening based on the server's role and generates instant alerts on any deviation from security policies.
Available in two versions:
- MicroSIEM Base: Hardening and full monitoring
- MicroSIEM + Intellidog: Add threat intelligence, exploit detection and virtual patching
Main features
🛡️ Automated Hardening
Operating System Configuration:
- Kernel hardening via sysctl (network stack, memory protection, kernel modules)
- Mandate Access Control with AppArmor or SELinux (default and custom policies)
- Filesystem hardening: mount options (noexec, nosuid), permission enforcement
- Service minimisation: automatic disabling services not necessary
- User management: robust password policy, sudo restriction, shell timeout
Default Models for Compliance:
- NIS2 Directive: Templates compliant with cybersecurity obligations
- ISO 27001: Technical checks Annex A (A.8, A.9, A.12)
- PCI-DSS v4.0: Requirements 2 (secure configurations)
- CIS Benchmarks: Level 1 (essential) and Level 2 (advanced)
- Custom: Create custom templates for specific needs
Server Role Templates:
- Web Server: Hardening Apache/Nginx, ModSecurity, TLS/SSL config
- Database Server: MySQL/PostgreSQL hardening, network isolation
- Application Server: Java/Node. js/Python environment security
- Gateway/Firewall: Safe Routing, NAT Hardening, VPN config
- DNS Server: BIND/Unbound hardening, DNSSEC
Testing and Rollback:
- Dry-run mode: Simulate changes without applying them
- Staged deployment: Staging test before production
- Automatic rollback: Automatic reset if unreachable server after 5 minutes
- Configuration versioning: Historical changes with diff visualizer
- Health checks: Post-hardening verification (active services, connectivity)
📊 Real Time Monitoring
Advanced Logging Audit:
- audited integration: Syscall monitoring with pre-configured rules
- File integrity monitoring: Hash SHA-512 of critical files (/etc, /bin, /usr/bin)
- Command logging: Complete tracking of privileged commands
- Sudo activity: Detailed log who does what with sudo
- Login monitoring: Success/failure, abnormal hours, geoIP tracking
Network Monitoring:
- Connection tracking: TCP/UDP connections with state (ESTABLISHED, LISTEN)
- Remote access monitoring: SSH, RDP, VNC session tracking
- Port monitoring: Alerts on unexpectedly open doors
- Traffic analysis: Abnormal volume, unusual protocols
- DNS monitoring: Query DNS suspect (DGA domains, tunneling)
Security Events Detection:
- Privilege escalation attributes: SUID/SGID abuse, kernel exploit patterns
- Rootkit detection: Kernel module inspection, hidden processes
- Configuration tampering: Unauthorized changes to critical files
- Service anomalies: Unexpected service starts/stops
- User anomalies: Account creation, password changes, privilege modifications
Performance Monitoring:
- CPU, RAM, Disk I/O for correlateon security events
- Process monitoring (high CPU = cryptominer? )
- Network bandwidth usage
- Integration with business metrics (downtime = incident? )
🚨 Alerting Multi-Canale
Notification Channels:
- Email: configurable SMTP, customizable HTML template
- Slack!: Webhook integration with rich formatting and thread
- Telegram: Bot integration for instant mobile notifications
- WhatsApp Business API: For enterprise organizations
- Generic Webhook: Integration custom (PagerDuty, Opsgenie, etc.)
- SMS (via third-party provider): For critical alerts
Alert Severity Levels:
- Critical: Confirmed compromise, immediate action required
- High: Highly suspected activity, urgent investigation
- Medium: Anomaly detected, necessary review
- Low: Info for audit trail, no immediate action
- Info: Non-security events for troubleshooting
Alert Intelligence:
- Deduplication: Avoid spam of identical alerts
- Aggregation: Related alert group in single incident
- Throttling: Rate limiting to avoid notification flood
- Escalation: If alert not acknowledged within X minutes → escalation manager
- Page 2: Quiet hours configurable (no night alert for Low severity)
Alert Customization:
- Custom rules: Create alert on specific conditions (regex on log, threshold metriche)
- Filtering: Alert only for specific asset/severity/hours
- Routing: Different Alerts to different teams (SSH failures → NetOps, sudo abuse → SecOps)
🎛️ Centralized management
Asset Discovery:
- ARP scanning: Discovery automatic host on local network
- Subnet scanning: CIDR scan to identify all servers
- Import from file: CSV/TXT with IP list for bulk import
- Cloud integration (roadmap): Auto-discovery AWS EC2, Azure VM, GCP Compute
- Agent-based discovery: Agent automatically communicates with CMS
Automated Deployment:
- SSH key-based: Authentication via elliptical keys (Ed25519)
- Ansible-like: Orchestration configurations on server fleet
- Parallel execution: Simultaneous Deploy on N Server
- Progress tracking: Real-time status deploy with detailed logs
- Pre-flight checks: Connectivity validation, OS compatibility, dependencies
Role-Based Access Control (RBAC):
- Sysadmin: Full access, can change everything
- Team Leader: Team management, deploy on assigned assets, reporting
- Operator: Deploy default configurations, read-only monitoring
- Reporter: Only dashboard display and report generation
- Auditor: Read-only complete for audit trail
Multi-Tenancy (roadmap v2.5):
- MSP can manage multiple customers
- Data insulation between tenant
- Customizable Branding for Tenant
- Billing for tenant
📈 Reporting and Compliance
Compliance Dashboards:
- Real-time compliance score: Percentage for framework compliance (NIS2, ISO, PCI)
- Control mapping: What controls are implemented, which are lacking
- Gap analysis: Prioritization remediation to bridge gap
- Historical trends: Evolution compliance over time
- Multi-framework view: Comparison between different frameworks
Templates Reports:
- Executive: 1-pager for management (status, trend, risks)
- Technical Report: Detailed configurations, technical evidence
- Report: For external auditors (evidence, timestamp, approvals)
- Compliance Report: Mapping asset → controls → compliance status
- Incident Report: Timeline events security, actions undertaken
Export Formats:
- PDF (customized branding)
- HTML (interactive with graphs)
- CSV (for custom analysis)
- JSON (for integration automation)
- DOCX (for further editing)
Scheduled Reports:
- Daily: Security summary events by operational team
- Weekly: Compliance status for managers
- Monthly: Executive summary for C-level
- Quarterly: Audit-ready report for compliance officer
🧠 Intellidog Module (Premium)
Intellidog is the analytical brain of MicroSIEM that transforms monitoring from responsive to proactive through threat intelligence and advanced correlation.
Threat Intelligence Integration:
- MISP: Malware Information Sharing Platform (community + private feeds)
- AlienVault OTX: Open Threat Exchange with millions of IoC
- Shodan: Internet-wide scanning data for exposure
- VirusTotal: File/URL/IP reputation checking
- AbuseIPDB: IP blacklist with confidence scoring
- Custom feeds: Import IoC from proprietary sources (STIX 2.x format)
Exploit Detection Engine: Multi-source correlation to determine if vulnerability is actively exploited:
- Vulnerability Context (from Sentinel Core or generic detection)
- IoC Matching: Log/network comparison with IoC database
- Behavioral Analysis:
- Syscall abnormal (eBPF monitoring)
- Process tree anomalies (fork bombs, reverse shells)
- Network anomalies (C2 beaconing, data exfiltration patterns)
- File system anomalies (webshell upload, suspicious script execution)
- Pattern Recognition: Signatures exploit known (Metasploit, public PoC)
- Timeline Correlation: Sustained time cluster events
Confidence Scoring:
- Low (0-30%): Anomalous but ambiguous activity
- Medium (30-70%): Sustained behavior, advised investigation
- High (70-90%): Strong exploitation indication, urgent remediation
- Confirmed (90-100%): Exploit confirmed, immediate incident response
Virtual Patching: When official patch not available or unenforceable (legacy systems):
- IDS/IPS-like rules: Malware traffic pattern block
- Application-level filtering: Specific request block (SQL, command injection)
- Network isolation: Temporary Quarantine Assets vulnerable
- Service modification: Disable vulnerable feature
- Integration Firedog: Automatic firewall rules for mitigation
Virtual Patch Lifecycle:
- Detection: Critical Vulnerability without patch available
- Analysis: Intellidog analyzes exploit vectors
- Patch Creation: Generate mitigation rules (automatic or manual)
- Testing: Deploy in "alert mode" for 24-48h (no blocking)
- Validation: If zero false positives → activation blocking mode
- Monitoring: Tracking attempts exploit blocked
- Decommissioning: When official patch available, remove virtual patch
Threat Hunting:
- Sigma Rules: 500+ pre-configured detection rules
- Custom Queries: Query builder for specific threats search
- Historical Search: Search IoC on log retention (30-90 days)
- Hunting Campaigns: Automatic campaigns on new CVE zero-day
- MITRE ATT&CK Mapping: Adversary technique identified → countermeasures
Proactive Alerting:
- Alert when new IoC match on historical logs ("compromised 2 weeks ago? "
- Alert when vulnerability discovery and suspicious traffic detected in the past
- Alert when CVE zero-day published and similar patterns detected
- Weekly digest potential threats detected (not confirmed but suspicous)
Cases of Use
Case 1: FinTech Startup – PCI-DSS compliance
Scenario:
Italian payment processing startup must obtain PCI-DSS certification to process credit cards. 15 servers (web, API, database) to harden.
Implementation:
- Discovery: MicroSIEM scans infrastructure, identifies 15 servers
- Classification: User ranks servers (web, app, db, cardholder data environment)
- Hardening: Apply template "PCI-DSS-Web" and "PCI-DSS-Database"
- Disable non-necessary services (75% disabled services)
- Local firewall with whitelist (only doors 443, 3306 to app tier)
- Strong password policy + sudo restriction
- TLS 1.3 only with cipher suite PCI-compliant
- Monitoring: Active logging audit on all CDE servers
- Database access logs
- Log changes configurations
- Log sudo commands
- Reporting: PCI-DSS report generated automatically
- Requirement 2: 95% compliant (manca disk encryption → manual)
- Requirement 10: 100% compliant (acudit logging active)
Results:
- Before: 0% PCI-DSS compliance
- After 7 days: 85% compliance (technical)
- QSA audit: Passed with minor findings
- Saved time: 40 hours vs manual configuration
Case 2: PMI Manufacturing – Obligation NIS2
Scenario:
Manufacturing company 200 employees, NIS2 obligation per critical sector. 50 mixed servers (ERP, MES, SCADA, server files). Zero internal security skills.
Implementation:
- Initial assessment: External Consultant makes assessment → identifies 50 critical assets
- Deploy MicroSIEM: Central server installation in DMZ
- Bulk import: Import 50 IPs from CSV
- Staged hardening:
- Week 1: Hardening NIS2-base on 10 non-critical servers (test)
- Week 2-3: Hardening 30 production server (maintenance windows)
- Week 4: Hardening 10 SCADA servers (ultra-careful, full backup)
- Active monitoring: Alert on Slack channel #security
- Monthly reports: NIS2 compliance report for CISO
Results:
- Compliance NIS2: From 30% to 78% in 1 month
- Incident detection: Detected brute-force SSH on SCADA (locked in 5 minutes)
- Audit preparedness: NIS2 full audit documentation
- ROI: Avoided potential sanction €10M (4% annual turnover)
Case 3: MSP – Management 20 Customers
Scenario:
Managed Service Provider manages IT for 20 SMEs (500 total servers). Centralized monitoring needs and multi-client compliance.
Implementation:
- Multi-tenant setup (custom deployment, roadmap v2.5 official):
- MicroSIEM dedicated to customer (data insulation)
- Centralized MSP Dashboard (all customers aggregate)
- Standardization:
- Standard hardening templates for customer type (law signature, medical, retail)
- Policy alerts (Critical → PagerDuty, High → Email)
- White-labeling:
- Report with customer logo
- Email alert "from IT of Client X"
- Automation:
- Onboarding new customer: 2 hours (vs 2 days manual)
- Monthly report generation automatic for 20 customers
Results:
- Operational efficiency: 1 operator runs 500 servers (vs 3 operators before)
- Upselling: Sold "Compliance NIS2" as additional service (+€800/year)
- Dissemination: Unique local MSP with compliance automation
- Churn reduction: From 15% to 5% per year (full monitoring customers)
Case 4: E-commerce – Hardening Infrastructure Cloud
Scenario:
E-commerce Magento on AWS, 25 EC2 instances (web, cache, database, ElasticSearch). Immediately attack believersal stuffing + scraping.
Implementation:
- Emergency hardening:
- Deploy MicroSIEM on AWS host bastion
- Hardening instant web tier (rate limiting, fail2ban, ModSecurity WAF rules)
- SSH hardening: disable password auth, key-only, port change
- MicroSIEM + Intellidog:
- Threat intel active: IP attackers identified (AbuseIPDB + MISP)
- Pattern detection: 10,000 req/min from subnet /24 → botnet
- Auto-mitigation: Automatic AWS Security Group Rules (via API)
- Advanced Monitoring:
- Alert on access admin panel out of time
- Alert on anomalous SQL query (possible SQL injection)
- Alert on upload files to unforeseen directories
Results:
- Attack mitigation: 99.8% malicious traffic blocked (10M request/day)
- Zero downtime: No legitimate customer impact
- Cost: Avoided overage bandwidth AWS (~€5k/month)
- Reputation: No customer data compromise
Case 5: Healthcare – GDPR + Security for Sensitive Data
Scenario:
Private clinic with Electronic Health Records (EHR) system. 10 servers with patient data. Obligation GDPR Art. 32 (security measures).
Implementation:
- Medical Hardening-grade:
- Disk encryption enforcement (LUKS)
- Database encryption at rest (PostgreSQL TDE)
- Strict access control: doctors only access their patients
- Audit logging GDPR-compliant:
- Log every access to patient data (who, when, which record)
- Log export data (GDPR right to data portability)
- Log Cancellations (GDPR right to be forgotten)
- Retention 7 years (legal obligation)
- Monitoring Abnormalities:
- Alert if user accesses >100 records/day (possible data breach)
- Alert se export data off working hours
- Alert if access from geographically abnormal IP
- Compliance reporting:
- GDPR report Art. 30 (record processing activities)
- Report for Privacy in case of audit
Results:
- GDPR: Art. 32 fully compliant (security measures)
- Data prevention: Relevated unauthorized access attempt by former employee (licence)
- Audit: Audit Guarantee Privacy exceeded without sanctions
- Patient trust: Certification "Data Protection Compliant" visible on site
FAQ – MicroSIEM
General
Q: MicroSIEM is a traditional SIEM such as Splunk or ELK?
A: No, MicroSIEM is focused on hardening and compliance monitoring, not on advanced security events enterprise-wide correlation. It is lighter, cheaper and easier to deploy. Complement to SIEM enterprise but can work standalone for SMEs.
Q: What operating systems does it work on?
A: Target host: Linux (Debian, Ubuntu, CentOS, RHEL, Rocky Linux, AlmaLinux, Fedora Server).
Central server: Any Linux with Docker, or bare-metal deployment.
Roadmap: Windows Server 2016+ (Q2 2026), macOS Server (Q4 2026).
Q: How many assets can I manage?
A: Basic License: Up to 50 assets.
Scale-up:
- 51-200 assets: band 1
- 201-500 assets: band 2
- 500-1000 assets: band 1
- 1000+ assets: Custom Quotation (Distribution Architecture)
Q: Do you need agent on target servers?
A: v1.x (current): No agent, use SSH with public keys.
v2.0 (Q3 2026): Agent opzionale lightweight (<50MB RAM, <5% CPU) per performance migliori e funzionalità avanzate (eBPF monitoring, real-time response).
Q: How long does it take to deploy MicroSIEM?
A: Basic setup: 2-4 hours (install server, config SMTP, test on 3-5 hosts).
Production deployment (50 hosts): 2-3 days (discovery, classification, internshipd hardening, tuning alerts).
Enterprise deployment (200+ hosts): 1-2 weeks with our support.
Hardening
Q: Can hardening make the server unusable?
A: Risk mitigated with:
- Dry-run mode: Simula changes, shows what would change (no impact)
- Staged deployment: Test on staging environment before prod
- Automatic rollback: If unreachable server after 5 min → automatic rollback
- Health checks: Post-hardening verifies critical services (HTTP, DB, SSH)
- Backup config: Each edit creates timestamped backups
Best practice: SEMPRE testing on non-production first environment.
Q: What hardening frameworks do you support?
A: Default template for:
- CIS Benchmarks: Level 1 (essential) and Level 2 (defensive)
- NIST SP 800-53: Security controls for federal systems
- DISAST: Military-grade hardening (very strict)
- PCI-DSS v4.0: Payment card industry
- HIPAA: Healthcare data protection (US)
- Custom: Create your YAML/JSON templates
Q: Can I customize hardening templates?
A: Yes, completely:
- Template are YAML human-readable files
- You can edit them via UI or text editor
- Integrated syntactic validator (prevents errors)
- Versioning: Each edit creates new template version
- Testing: dry-run on sacrificial host before deploy fleet-wide
Q: Hardening impact performance?
A: Minimum impact:
- Kernel hardening (sysctl): <1% CPU overhead
- AppArmor/SELinux: 2-5% CPU overhead (depending on policy)
- Audit logging: 3-8% CPU overhead (configurable verbosity)
- Overall: ~5-10% CPU, 100-200MB additional RAM
For high-performance servers (database, cache), we can specific tuning profiling.
Q: Does it support container (Docker, Kubernetes)?
A: Container hardening in roadmap v2.5 (Q4 2025):
- Docker daemon hardening
- Container runtime security (AppArmor profiles)
- Image scanning integration
- Kubernetes pod security policies
Currently: hardening of the underlying host (good practice however).
Monitoring
Q: How much is the data collected?
A: Configurable:
- Real-time: Critical events (root login, sudo) abuse immediate
- High-frequency: Metric performance → every 30 seconds
- Standard: File integrity, connection status → every 5 minutes
- Low-frequency: Software inventory, user list → every 1 hour
Balanced Default: Mix on top, ~5 minutes aggregate collection.
Q: How much disk space is it for logs?
A: Storage estimates (for asset):
- Minimal logging: ~50MB/month
- Standard logging: ~200MB/month
- Verbose logging: ~500MB/month
- Paranoid logging (audit everything): ~2GB/month
Fleet 50 assets, standard logging: ~10GB/month.
Compression: gzip reduces ~70-80% (30GB → 6-9GB stored).
Retention: Default 90 days, then automatic purging.
Q: MicroSIEM impacts monitored server performance?
A: Typical overhead:
- auditd: 3-5% CPU (depending on rules)
- Log shipping SSH: <1% CPU, 10-50KB/sec bandwidth
- File integrity checks: CPU spike breve ogni 5 min (<2% average)
Total overhead: 5-8% CPU, 50-100MB RAM, negligible bandwidth.
High performance servers: we can tuning (e.g. audit only critical syscalls).
Q: Supports monitoring applications (not only OS)?
A: Yes, via plugin/custom scripts:
- Apache/Nginx: Access log parsing, error detection
- MySQL/PostgreSQL: Slow query detection, connection anomalies
- Redis/Memcached: Memory usage, eviction rates
- Custom apps: Log file monitoring with regex rules
Q: Can I create custom alerts?
A: Yes, alert builder UI:
- Regex on log lines
- Threshold on metrics (e.g. CPU >80% for >5 min)
- Composite conditions (IF X AND Y THEN alert)
- Severity level customizable
- Notification channel for alert type
Intellidog module
Q: Is Intellidog mandatory?
A: No, it is optional premium module. MicroSIEM Base is complete and functional without Intellidog.
When Need Intellidog:
- Asset exposed Internet with historical attacks
- Compliance requires threat intelligence (e.g. NIS2 advanced)
- Non patchable legacy systems (need virtual patching)
- Team security wants threat hunting proactive
- Budget allows (+€2.500/year)
Q: Intellidog slows down MicroSIEM?
A: No, minimum overhead.:
- Threat intel sync: Background task every 4h (~2 min duration)
- IoC matching: In-memory cache, <50ms latency per event
- Analysis engine: Async processing, does not block monitoring
- CPU: +10-15% during analysis burst
- RAM: +200-300MB for IoC cache (100k+ indicators)
Q: Do you need Shodan for a fee?
A: Recommended but not mandatory:
- Without Shodan: Works with free feed (MISP, AlienVault OTX, AbuseIPDB) → 70% coverage
- With Shodan ($59/month $899/year): +30% coverage, historical data, asset exposure discovery
ROI Shodan: If you detect 1 exploit/year thanks to Shodan → $59/month is irrisorio vs cost incident.
Q: Does Intellidog share my data?
A: Absolutely.. Intellidog:
- Download IoC from external sources
- Not uploaded your data (IP, vulnerability, log)
Opt-in (voluntary): You can contribute anonymous IoC to MISP community to improve global threat intel.
Q: Is Virtual patching safe?
A: It is a mitigation, not a fix:
- ✅ Pro: Protects immediately, no downtime, reversible
- ⚠️ Against: Does not eliminate vulnerabilities (exploit may evolve), may have false positives
Best practice:
- Virtual patches temporary solution
- Apply official patch just available
- Testing mode 24-48h before blocking mode
- Continuous monitoring virtual patch effectiveness
Use ideal houses: EOL legacy systems (Windows 2008, RHEL 6) where official patches will never exist.
Q: How many IoC runs Intellidog?
A: Local IoC database:
- Default: ~100.000 IoC (IP, domain, file hash, YARA rules)
- Storage: ~500MB tablets
- Update frequency: Every 4 hours (configurable)
- Match performance: <50ms per 10k log lines
Enterprise deployment: It can scale to millions of IoC with dedicated database.
Integration and Automation
Q: Does MicroSIEM have API?
A: Yes, full REST API:
- Authentication: JWT token-based
- Endpoints: Asset management, hardening deploy, monitoring data retrieval, alert config
- Documentation: OpenAPI 3.0 spec (Swagger UI)
- Rate limiting: 1000 req/hour (configurable)
Use API homes:
- Automation with Ansible/Terraform
- Integration SOAR/SIEM
- Custom dashboard (Grafana, Kibana)
- CI/CD pipeline hardening automation
Q: Does it support webhook for alert?
A: Yes, generic webhook for integration with:
- PagerDuty, Opsgenie (incident management)
- Jira, ServiceNow (ticketing)
- Microsoft Teams, Discord (chat)
- Custom systems (POST JSON at any URL)
Q: Can I integrate with Ansible?
A: Yes, in two ways:
- MicroSIEM commands Ansible: Trigger playbook Ansible for remediation
- Ansible commands MicroSIEM: Ansible module for deploy hardening via MicroSIEM API
Q: Integration with SIEM enterprise (Splunk, ELK)?
A: Yes, via syslog forwarding:
- MicroSIEM sends logs to SIEM external (RFC 5424 format)
- Advanced Correlation made by SIEM enterprise
- MicroSIEM keeps focus on hardening/compliance
Architecture: MicroSIEM (hardening + compliance) + Splunk (correlation + forensics) = best of both.
Compliance & Reporting
Q: Are audit-ready reports?
A: Yes, designed for auditor:
- Timestamp certificate (NTP sync)
- Digital signature optional (for immutability)
- Evidence trail: Screenshot config, log excerpts, command output
- Approval workflow: Change records with approver ID
- Export PDF with watermark "Official Report"
Q: Support multiple compliance framework simultaneous?
A: Yes, multi-framework tracking:
- An asset can have tags "PCI-DSS + ISO27001 + NIS2"
- Dashboard shows % compliance for each framework
- Report can be multi-framework or framework-specific
Q: How long does it take to generate reports?
A: Generation time:
- Executive summary: <10 secondi
- Technical report (10 assets): ~1 minute
- Compliance report (50 assets, multi-framework): ~5 minutes
- Historical analysis (90 days, 100 assets): ~10 minutes
Reports are cachati, re-generation only if data changes.
Q: Can I customize logo/branding in reports?
A: Yes, white-labeling:
- Upload corporate logo (header/footer)
- Custom color scheme
- Custom footer text (e.g. "Confidential – Client XYZ")
- Custom cover page
Ideal for MSPs serving customers.
Licensing & Support
Q: Is license perpetual or subscription?
A: Annual subscription (Software-as-a-Service model). Includes:
- Software updates
- Security patches (critical released within 24h)
- Standard email support 48h
- Access documentation and knowledge base
- Community forum
Q: What happens if I don't renew a license?
A: Grace period 30 days:
- Days 1-30: Software works normally, reminder renewal
- Days 31-90: Software works but limited features (no new hardening deploy, monitoring read-only)
- After 90 days: Software in read-only mode (existing data display only)
No data loss: Data remains intact, only limited functionality.
Q: Can I do trial before I buy?
A: Yes, 3 trial options:
- Trial cloud 30 days:
- Environment sandbox cloud (managed by us)
- Max 5 asset assets
- Full features (including Intellidog)
- Zero install required
- Free
- PoC on-premise 60 days:
- Deploy on your infra
- Max 20 asset
- Service deployment from our team
- After trial: import config licensed prod (zero re-work)
- Free (Request NDA)
- Live Demo 1-2 hours:
- Video call with solutions architect
- Live demo on our environment
- Technical Q&A
- Free, no commitment
Q: Support includes training?
A: Basic support: No formal training, only documentation + video tutorial.
Premium support: Includes 1 day training (on-site or remote).
Additional training (available separately):
- Workshop 2 days: max 10 participants
- Certification program (in development): provided per person
Q: Is support in Italian?
A: Yes, native Italian support:
- Italian-based team
- Bilingual documentation IT/EN (in development)
- Video tutorial in Italian
- EN support available for international teams
Q: Support response time?
A: Standard support (including):
- P1 Critical (down system): 24h first response
- P2 High (limited functionality): 48h
- P3 Medium (Domande): 72h
- P4 Low (feature request): Best effort
Premium support (+)€2,000/year, contract SLA):
- P1: 4h response first, escalation automatic a senior engineer
- P2: 12h
- P3: 24h
- P4: 48h
- 24/7 hotline (only P1/P2)
Technical
Q: Central server hardware requirements?
A: Minimum (up to 50 assets):
- CPU: 4 cores (2.5GHz+)
- RAM: 8GB
- Disk: 100GB SSD
- Network: 100Mb
Recommended (50-200 assets):
- CPU: 8 cores (3GHz+)
- RAM: 16GB
- Disk: 500GB SSD (or NAS for log storage)
- Network: 1Gb
Enterprise (200+ assets):
- CPU: 16+ cores
- RAM: 32GB+
- Disk: 1TB+ SSD (RAID 10) + NAS backup
- Network: 10Gb
- Database: PostgreSQL on dedicated host
Q: Supports High Availability?
A: Roadmap v3.0 (2026):
- Active-passive HA with automatic failover
- Database replication (PostgreSQL stream replication)
- Shared storage (NFS/GlusterFS)
Currently: Single instance, backup/restore manual (automated via script).
Q: Do you need constant Internet connection?
A: Central server:
- Internet required for: Threat intel updates (Intellidog), email alerts, webhook
- Works offline: Continuous monitoring, use threat intel cached
- Bandwidth: ~100MB/day for threat intel sync
Agent/SSH monitoring:
- No Internet required, communication only to central server (LAN)
Q: Compatible with air-gapped environments?
A: Yes, with restrictions:
- MicroSIEM Base: Works 100% offline (hardening + local monitoring)
- Intellidog: Request threat intel sync (options):
- Manual sync: Export/import USB drive (weekly)
- Dedicated Proxy: Server with Internet → sync → internal copy
- Offline mode: Use only IoC custom (no external feeds)
Q: Database supported?
A: – PostgreSQL 12+ (preferred, best performance)
- MySQL/MariaDB 8.0+ (supported)
- SQLite (development only, not production)
Time-series metrics: TimescaleDB extension (PostgreSQL) recommended for performance.
Q: Does it support IPv6?
A: Yes, dual-stack:
- Discovery: ARP scan (IPv4) + NDP scan (IPv6)
- Monitoring: IPv4 + IPv6 connection tracking
- Hardening: iptables (IPv4) + ip6tables (IPv6)
Q: Can I host on cloud?
A: Yes, compatible with:
- AWS: EC2 instance, RDS per database
- Azure: VM, Azure Database for PostgreSQL
- GCP: Compute Engine, Cloud SQL
- DigitalOcean, Linode, Hetzner: VPS any size
Best practice: Security group / firewall rules to limit access (business IP only).
CONTACT US
Contact Sales Team
Dognet Technologies SRL
Via XXV April 47, 24055
Colony to the Serius (Bg)
Tel: 351.5568240 | 352.0321176
Mail: info@dognet.tech
PI and CF: 04867480164
BG N.R.E.A. 495176
Italy
Pages
Proudly powered by WordPress


