Project profile
A software company operated approximately 18 Linux servers across production, staging, database, VPN, and internal service environments.
The company already followed several cybersecurity best practices:
- SSH keys instead of password-only authentication;
- firewalls;
- regular updates;
- TLS certificates;
- server backups;
- basic DDoS protection.
The main problem was visibility. Security information existed, but it was distributed across many independent systems.
Initial situation
Each Linux server produced authentication logs, application logs, firewall events and system events. Administrators normally investigated them only when there was already a problem. For example, diagnosing suspicious authentication activity required connecting to several servers individually and comparing timestamps manually.
There was no central answer to questions such as:
- Is the same IP attempting to log in to multiple servers?
- Did a privileged configuration file change?
- Are authentication failures increasing?
- Which servers are missing security updates?
- Did a firewall or SSH rule change?
- Is suspicious activity isolated or infrastructure-wide?
The company wanted a practical SIEM for small business rather than a large enterprise security platform requiring a dedicated SOC team.
The technical challenge
The objective was to centralize security telemetry without creating an infrastructure project larger than the environment being protected.
The solution needed to:
- aggregate logs from Linux servers;
- correlate authentication events;
- detect suspicious login behavior;
- monitor important file changes;
- track selected security events;
- retain searchable logs;
- generate useful alerts without excessive noise;
- remain manageable by a small technical team.
What the Unihost team did
- Reviewed the existing security configuration
The first stage was not SIEM installation.
The team reviewed the environment itself:
- SSH configuration;
- exposed network ports;
- firewall rules;
- administrative access;
- system updates;
- TLS configuration;
- backup availability;
- public-facing services.
Several unnecessary externally accessible services were restricted before centralized monitoring was introduced. This followed a simple principle: monitoring an avoidable exposure is less useful than removing the exposure.
- Built a centralized security monitoring node
A dedicated management server was prepared for the security stack. Agents and log forwarding were then configured across the infrastructure.
The central system received relevant events from:
- Linux servers
– authentication logs
– sudo activity
– system events
– selected application logs - Web infrastructure
– web server security events
– suspicious request patterns - Network layer
– firewall/security events - Monitoring
– service and availability alerts
- Normalized authentication monitoring
SSH activity was one of the first use cases. Instead of reviewing failed logins on individual machines, authentication events became searchable across the whole environment. This allowed administrators to identify patterns such as one source attempting authentication against multiple servers.
- Added file integrity monitoring
Important configuration directories were added to file integrity monitoring. Unexpected changes to files such as SSH, web-server and selected application configurations generated security events. The intention was not to alert on every changed file, but to monitor areas where unauthorized changes could materially affect the system.
- Tuned alerting
The first version generated too many low-value events.
The support team therefore separated events into categories:
- informational: retained for investigation but not actively alerted;
- warning: requires review;
- critical: requires immediate action.
Repeated authentication failures, unexpected privileged changes and security service failures received higher priority.
- Hardened the surrounding infrastructure
SIEM was treated as one component of the security architecture rather than the entire solution.
The team also reviewed:
- DDoS protection;
- firewall configuration;
- SSH access;
- TLS certificates;
- OS patching;
- backups;
- administrative permissions.
Unihost provides DDoS protection on its dedicated infrastructure and supports additional firewall options; Managed PRO also includes continuous monitoring of infrastructure, services, ports, databases and other system components.
Architecture: Production / staging / database servers – security agents + system logs – central SIEM node – normalization and correlation – dashboard + alerts – administrator investigation
Unihost solution used
Managed Dedicated Server + Security Monitoring
Support work included:
- OS and service configuration;
- firewall review;
- security hardening;
- centralized log collection;
- SIEM deployment;
- alert configuration;
- monitoring;
- backup configuration;
- ongoing administration.
Unihost Managed services currently cover OS and Linux-service configuration, security/virus-related operations and proactive infrastructure monitoring. During validation, simulated suspicious authentication attempts across multiple hosts became visible from one interface within seconds. A test modification of a monitored system configuration also generated the expected security event. The biggest improvement was therefore not simply “more security alerts.” It was context. An administrator could see whether an event affected one machine or represented a pattern across the infrastructure.
Business impact
The company gained many of the visibility benefits associated with larger SIEM deployments without creating a dedicated internal SOC. It also established repeatable security best practices for onboarding additional servers: log forwarding, monitoring, access controls and baseline security checks became part of the standard deployment process.
What’s next
The company plans to extend monitoring to selected application events and improve automated response for repeatable low-risk scenarios.
Results at a glance: 18 servers centrally monitored, unified security logs, faster investigation, file integrity monitoring, security alerts with context.