
Your events in one place, evaluated and reported
Blackfort Event Intelligence
Collect security-relevant events centrally, evaluate them against a rule set and get notified — on a dedicated instance per customer, operated by us.
Events are generated everywhere: on servers, workstations, network components. As long as they stay there, nobody notices when something looks wrong — and after an incident there is no trail left to follow. Blackfort Event Intelligence collects those events in one place, evaluates them against a maintained rule set and reports what stands out. We run it for you.
Core Capabilities
Central collection
A lightweight agent reports events from your systems to an instance operated exclusively for your company. Triggered rules stay searchable for the agreed period.
Evaluation against a rule set
We maintain the rule set. You get evaluated findings and our assessment at the agreed cadence.
Notification regardless of the hour
Rule violations trigger automatically, whatever the day or time. The delivery channel is agreed during setup.
Operated by Blackfort
You provide no server, run no database and maintain no rule sets. A separate instance per customer.
Typical Use Cases
- Central logging as a basis for NIS2 evidence
- A first detection capability without your own SOC
- Traceability after a security-relevant event
- Adding evaluation and alerting to existing logging
Request This Product
Interested in Blackfort Event Intelligence? Talk to us about your requirements and receive a tailored proposal.
Send RequestRegulatory Context
Addresses logging and monitoring requirements from ISO/IEC 27001 Annex A.8.15/A.8.16 and the BSI IT-Grundschutz module DER.1. You provide the evidence in the end; the product supplies what it is built from.
Real-World Scenarios
No staffed SOC, but a notification
A service account signs in at night from a system it never uses. The rule triggers and the notification goes out — even without a permanently staffed shift.
After the incident
Following a suspected case you can trace which rules triggered in the preceding weeks and on which systems.
Frequently Asked Questions
Is this a SIEM?
It collects events centrally, evaluates them against a rule set and reports what stands out. What it is not: a permanently staffed SOC and a long-term archive. For durable, tamper-evident history there is the Blackfort Independent Log Vault.
How long are events available?
Triggered rules stay searchable for the agreed period. The full raw event stream is not stored permanently; if you need that, combine the product with the Log Vault.
What runs on our systems?
A lightweight agent that reports events. The rights it holds on your systems are documented in the connection description; you can uninstall it yourself at any time.
Where is it operated?
On a dedicated instance per customer at a German hosting provider, named as sub-processor in the Art. 28 GDPR data processing agreement. If you would rather run it in your own environment, we will look at that on request.
Kontakt aufnehmen
Ready to strengthen your security?
Find out more about Blackfort Event Intelligence and how it can improve your security posture.