Case study · SMB / Technology · Singapore
A Singapore tech company was paying roughly $20,000 a month in SIEM log-ingestion fees. ITSECOPS implemented an open-source stack built on Wazuh with a SOCFortress-style pipeline — and brought the monthly bill down to about $8,000 with equivalent detection coverage.
The client
A technology company in Singapore with a large fleet of servers and endpoints whose commercial SIEM pricing scaled with every gigabyte ingested.
The challenge
Detection coverage was good; the invoice was not. Every new log source made security more expensive, so teams had quietly stopped onboarding sources — the worst possible incentive.
What we did
- Deployed Wazuh as the detection and agent layer across servers and endpoints.
- Built an open-source ingestion pipeline (SOCFortress-style: Wazuh + OpenSearch + Graylog) sized for the real event volume.
- Mapped existing commercial-SIEM detections to Wazuh rules and MITRE ATT&CK so coverage was provably equivalent before cutover.
- Kept a small set of crown-jewel sources on the commercial platform where its analytics genuinely earned the fee.
- Handed operations to a defined runbook — the stack is monitored around the clock by our SOC team.
Results
- Log platform spend: ~$20,000/month → ~$8,000/month (–60%).
- Source onboarding resumed — visibility went up while costs went down.
- Detection parity documented rule-by-rule for the security committee.
FAQ
Is Wazuh production-ready for a company this size?
Yes — with proper index lifecycle management and pipeline sizing. The engineering effort shifts from licence fees to architecture, which is exactly where a partner earns their keep.
What does open-source SIEM really save?
Typically 50–70% of ingestion-based licensing. You trade licence spend for a smaller, predictable operations cost.
Who maintains it after go-live?
Either your team with our runbooks, or ITSECOPS operates it as part of 24×7 SOC monitoring.