Blackfort Technology
Blackfort Event Intelligence
Product

Your events in one place, evaluated and reported

Blackfort Event Intelligence

Collect security-relevant events centrally, evaluate them against a rule set and get notified — on a dedicated instance per customer, operated by us.

Events are generated everywhere: on servers, workstations, network components. As long as they stay there, nobody notices when something looks wrong — and after an incident there is no trail left to follow. Blackfort Event Intelligence collects those events in one place, evaluates them against a maintained rule set and reports what stands out. We run it for you.

Core Capabilities

Central collection

A lightweight agent reports events from your systems to an instance operated exclusively for your company. Triggered rules stay searchable for the agreed period.

Evaluation against a rule set

We maintain the rule set. You get evaluated findings and our assessment at the agreed cadence.

Notification regardless of the hour

Rule violations trigger automatically, whatever the day or time. The delivery channel is agreed during setup.

Operated by Blackfort

You provide no server, run no database and maintain no rule sets. A separate instance per customer.

Typical Use Cases

  • Central logging as a basis for NIS2 evidence
  • A first detection capability without your own SOC
  • Traceability after a security-relevant event
  • Adding evaluation and alerting to existing logging

Request This Product

Interested in Blackfort Event Intelligence? Talk to us about your requirements and receive a tailored proposal.

Send Request

Regulatory Context

Addresses logging and monitoring requirements from ISO/IEC 27001 Annex A.8.15/A.8.16 and the BSI IT-Grundschutz module DER.1. You provide the evidence in the end; the product supplies what it is built from.

Real-World Scenarios

No staffed SOC, but a notification

A service account signs in at night from a system it never uses. The rule triggers and the notification goes out — even without a permanently staffed shift.

After the incident

Following a suspected case you can trace which rules triggered in the preceding weeks and on which systems.

Frequently Asked Questions

Is this a SIEM?

It collects events centrally, evaluates them against a rule set and reports what stands out. What it is not: a permanently staffed SOC and a long-term archive. For durable, tamper-evident history there is the Blackfort Independent Log Vault.

How long are events available?

Triggered rules stay searchable for the agreed period. The full raw event stream is not stored permanently; if you need that, combine the product with the Log Vault.

What runs on our systems?

A lightweight agent that reports events. The rights it holds on your systems are documented in the connection description; you can uninstall it yourself at any time.

Where is it operated?

On a dedicated instance per customer at a German hosting provider, named as sub-processor in the Art. 28 GDPR data processing agreement. If you would rather run it in your own environment, we will look at that on request.

Kontakt aufnehmen

Ready to strengthen your security?

Find out more about Blackfort Event Intelligence and how it can improve your security posture.