[{"data":1,"prerenderedAt":240},["ShallowReactive",2],{"$f30lhmez5u3l64":3},{"version":4,"title":5,"home_page_url":6,"description":5,"items":7},"https:\u002F\u002Fjsonfeed.org\u002Fversion\u002F1","Eventus Blog Blog","https:\u002F\u002Feventus.blog",[8,24,36,45,60,68,77,86,97,105,116,125,135,145,155,166,185,198,207,227],{"id":9,"content_html":10,"url":9,"title":11,"summary":12,"date_modified":13,"author":14,"tags":17},"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F29\u002Fsentinel-user-behavior-analysis-asim-authentication","\u003Cp>Eventus has published a new engineering article on \u003Ca href=\"https:\u002F\u002Fqiita.com\u002Fjamesyip\u002Fitems\u002F93e168b54a69dbce5af2\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Qiita\u003C\u002Fa>: \u003Cstrong>“Designing Sentinel User Behavior Analytics Without Raw-Table Dependencies: Using ASIM Authentication as the User Baseline.”\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The article looks at why analytics built directly on tables such as \u003Ccode>SigninLogs\u003C\u002Fcode>, \u003Ccode>SecurityEvent\u003C\u002Fcode>, and connector-specific logs become harder to maintain as authentication sources multiply. It also covers how raw event volume can run into result limits, while connector outages or ingestion delays can leave gaps in the data.\u003C\u002Fp>\n\u003Cp>It then explains how ASIM Authentication's normalized \u003Ccode>imAuthentication\u003C\u002Fcode> schema can provide a common basis across supported sources. Aggregating by user early helps keep query results manageable and makes behavior analytics easier to reuse across hybrid environments.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"read-the-article\">Read the article\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F29\u002Fsentinel-user-behavior-analysis-asim-authentication#read-the-article\" class=\"hash-link\" aria-label=\"Direct link to Read the article\" title=\"Direct link to Read the article\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>If you are designing user behavior analytics or UEBA-style detections in Microsoft Sentinel, we invite you to read the full article:\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fqiita.com\u002Fjamesyip\u002Fitems\u002F93e168b54a69dbce5af2\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Read the Sentinel and ASIM article on Qiita\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>To learn more about Eventus's security services, \u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">contact Eventus\u003C\u002Fa>.\u003C\u002Fp>","A New Qiita Article: Sentinel User Behavior Analytics with ASIM Authentication","A new Qiita article explains how Microsoft Sentinel user behavior analytics can use ASIM Authentication to avoid raw-table dependencies and handle diverse authentication sources.","2026-09-29T00:00:00.000Z",{"name":15,"url":16},"James Yip","https:\u002F\u002Fgithub.com\u002Fjamesyip",[18,19,20,21,22,23],"Eventus","Microsoft Sentinel","ASIM","KQL","SIEM+","Cybersecurity",{"id":25,"content_html":26,"url":25,"title":27,"summary":28,"date_modified":29,"author":30,"tags":31},"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F19\u002Fsiem-plus-now-officially-supports-microsoft-sentinel","\u003Cp>We're announcing that SIEM+ now has full, native support for Microsoft Sentinel, joining our existing integrations with Devo, Splunk, and QRadar. If your organization runs Sentinel as its SIEM, you can now add SIEM+'s alert consolidation and AI-powered triage on top of it without changing anything about your existing Sentinel deployment.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"Abstract security operations signals converging into a unified SIEM+ triage layer\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fsiem-plus-microsoft-sentinel-support-5042c043dbe2e8c2b08c53b2ebfcce44.png\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-this-means-in-practice\">What this means in practice\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F19\u002Fsiem-plus-now-officially-supports-microsoft-sentinel#what-this-means-in-practice\" class=\"hash-link\" aria-label=\"Direct link to What this means in practice\" title=\"Direct link to What this means in practice\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>SIEM+ was built on a simple premise: most organizations don't need another SIEM. They need a better way to see across the one or more they already have.\u003C\u002Fp>\n\u003Cp>Adding Sentinel to our supported platforms means:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Sentinel alerts flow into SIEM+ alongside any other SIEM you run.\u003C\u002Fstrong> If you're managing Sentinel in one business unit and Splunk, QRadar, or Devo in another, SIEM+ now gives you a single consolidated view across all of them instead of forcing analysts to switch between consoles.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>AI-driven correlation and noise reduction apply to Sentinel data the same way they do for our other integrations.\u003C\u002Fstrong> Duplicate and low-priority alerts get suppressed, and what's left gets translated into plain-English summaries with remediation guidance, so analysts spend less time interpreting raw alert data and more time acting on it.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>No changes are required to your existing Sentinel setup.\u003C\u002Fstrong> SIEM+ sits on top of Sentinel as an overlay. Your detection rules, data connectors, and retention policies stay exactly as they are.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-this-integration-matters-now\">Why this integration matters now\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F19\u002Fsiem-plus-now-officially-supports-microsoft-sentinel#why-this-integration-matters-now\" class=\"hash-link\" aria-label=\"Direct link to Why this integration matters now\" title=\"Direct link to Why this integration matters now\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Sentinel has become one of the most widely deployed cloud SIEMs, and a growing share of our enterprise conversations—particularly in financial services, pharma, semiconductor, and manufacturing—involve organizations running Sentinel in at least part of their environment. Often, it operates alongside other platforms inherited through M&amp;A or regional IT autonomy.\u003C\u002Fp>\n\u003Cp>For these organizations, official Sentinel support means SIEM+ can now serve as a true cross-platform consolidation layer, regardless of which combination of Sentinel, Devo, Splunk, or QRadar makes up their actual environment.\u003C\u002Fp>\n\u003Cp>That's the scenario SIEM+ was designed for from the start: reducing alert noise and unifying visibility without forcing a SIEM migration to get there.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-to-get-started\">How to get started\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F19\u002Fsiem-plus-now-officially-supports-microsoft-sentinel#how-to-get-started\" class=\"hash-link\" aria-label=\"Direct link to How to get started\" title=\"Direct link to How to get started\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Sentinel support is available now across all three ways SIEM+ is delivered:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Standalone overlay\u003C\u002Fstrong> — add SIEM+ on top of your existing Sentinel deployment.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Bundled with Devo\u003C\u002Fstrong> — for organizations running Sentinel alongside a Devo environment.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Managed service\u003C\u002Fstrong> — SIEM+ operated on your behalf, spanning Sentinel and any other SIEM in your stack.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you're already running Sentinel and dealing with alert volume that's outpacing your team's ability to triage it, this is a good time to talk. \u003Ca href=\"https:\u002F\u002Fsiem.plus\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Reach out\u003C\u002Fa> to see what a consolidated view across your environment looks like.\u003C\u002Fp>","SIEM+ Now Officially Supports Microsoft Sentinel","SIEM+ now natively supports Microsoft Sentinel, bringing cross-platform alert consolidation, AI-powered triage, and plain-English remediation guidance to Sentinel environments.","2026-09-19T00:00:00.000Z",{"name":15,"url":16},[32,19,23,33,34,35],"SIEM Plus","Security Operations","Alert Fatigue","AI Security",{"id":37,"content_html":38,"url":37,"title":39,"summary":40,"date_modified":41,"author":42,"tags":43},"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F12\u002Fwhy-alert-fatigue-is-the-real-soc-problem-business-problem","\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"alert-fatigue-isnt-a-soc-inconvenience-its-an-enterprise-risk\">Alert fatigue isn't a SOC inconvenience. It's an enterprise risk.\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F12\u002Fwhy-alert-fatigue-is-the-real-soc-problem-business-problem#alert-fatigue-isnt-a-soc-inconvenience-its-an-enterprise-risk\" class=\"hash-link\" aria-label=\"Direct link to Alert fatigue isn't a SOC inconvenience. It's an enterprise risk.\" title=\"Direct link to Alert fatigue isn't a SOC inconvenience. It's an enterprise risk.\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>When security leaders talk about alert fatigue, the conversation usually stays inside the SOC: analysts burning out, dashboards full of red, MTTR creeping up quarter over quarter. That framing isn't wrong — it's just too small.\u003C\u002Fp>\n\u003Cp>At the enterprise level — in financial services, pharma, semiconductor, and large-scale manufacturing — alert fatigue isn't an operational nuisance. It's a business risk that shows up on the balance sheet, in audit findings, and in board-level conversations about resilience.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-problem-scales-faster-than-headcount\">The problem scales faster than headcount\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F12\u002Fwhy-alert-fatigue-is-the-real-soc-problem-business-problem#the-problem-scales-faster-than-headcount\" class=\"hash-link\" aria-label=\"Direct link to The problem scales faster than headcount\" title=\"Direct link to The problem scales faster than headcount\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Large enterprises don't run one SIEM. They run several — Splunk in one business unit, Microsoft Sentinel in another, QRadar or Devo somewhere else, often as a byproduct of M&amp;A, regional autonomy, or years of tooling decisions made independently across divisions.\u003C\u002Fp>\n\u003Cp>Each platform generates its own alert volume. Each has its own tuning debt. None of them talk to each other. The result is not just noise — it's fragmented visibility at exactly the moment enterprises need a unified picture of risk.\u003C\u002Fp>\n\u003Cp>Adding analysts doesn't fix this. Headcount scales linearly; alert volume doesn't. The gap between the two is where real incidents get missed — not because the data wasn't there, but because it was buried under everything else.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-this-matters-beyond-the-soc\">Why this matters beyond the SOC\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F12\u002Fwhy-alert-fatigue-is-the-real-soc-problem-business-problem#why-this-matters-beyond-the-soc\" class=\"hash-link\" aria-label=\"Direct link to Why this matters beyond the SOC\" title=\"Direct link to Why this matters beyond the SOC\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>For enterprise leadership, the consequences of alert fatigue extend well past mean-time-to-detect:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Regulatory exposure.\u003C\u002Fstrong> In financial services and pharma, missed or delayed detection isn't just a security failure — it's a compliance and audit finding.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>M&amp;A and integration risk.\u003C\u002Fstrong> Every acquisition that inherits a different SIEM stack compounds the fragmentation problem, often silently, until an incident exposes it.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Analyst retention cost.\u003C\u002Fstrong> SOC burnout has a direct line to attrition, and re-hiring and re-training security talent in specialized industries is neither fast nor cheap.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Board-level accountability.\u003C\u002Fstrong> As cyber risk reporting becomes a standing agenda item, \"we have too many alerts to know which ones matter\" is not an answer that holds up in the room.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-fix-isnt-another-siem\">The fix isn't another SIEM\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F12\u002Fwhy-alert-fatigue-is-the-real-soc-problem-business-problem#the-fix-isnt-another-siem\" class=\"hash-link\" aria-label=\"Direct link to The fix isn't another SIEM\" title=\"Direct link to The fix isn't another SIEM\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The instinct to solve fragmentation by consolidating onto a single SIEM platform is understandable — and often impractical. Rip-and-replace across a multinational, multi-division enterprise takes years, and the switching cost rarely justifies the outcome, especially when the underlying platforms (Sentinel, Splunk, Devo) are already doing their job of ingesting and storing data at scale.\u003C\u002Fp>\n\u003Cp>The more tractable path is adding a consolidation and triage layer on top of what's already there — one that ingests alerts across every SIEM in the environment, correlates them, and surfaces what actually matters through a single view. This is the model behind SIEM+: not a replacement for Sentinel, Splunk, or Devo, but a layer that makes the investment already made in those platforms usable at enterprise scale. For organizations already on Devo, this pairs naturally with Strike48, Devo's own AI SOC extension — SIEM+ adds the cross-platform consolidation Strike48 alone doesn't need to solve, since it lives inside a single Devo environment.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"reframing-the-question\">Reframing the question\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F09\u002F12\u002Fwhy-alert-fatigue-is-the-real-soc-problem-business-problem#reframing-the-question\" class=\"hash-link\" aria-label=\"Direct link to Reframing the question\" title=\"Direct link to Reframing the question\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The question enterprise security leaders should be asking isn't \"how do we get analysts to triage faster.\" It's \"why are we asking humans to triage volumes that were never designed for human review in the first place.\"\u003C\u002Fp>\n\u003Cp>Alert fatigue is a SOC symptom. But the disease — fragmented tooling, unmanaged alert volume, and risk visibility that degrades as the organization scales — is an enterprise problem, and it deserves an enterprise-level answer.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"Fragmented enterprise security signals converging into a few prioritized incident cases\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Falert-fatigue-business-risk-096e6b706cd7923a8515af42384c0dea.png\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>","Why Alert Fatigue Is the Real SOC Problem — And Why It's Actually a Business Problem","Alert fatigue is more than a SOC inconvenience. Learn why fragmented tooling and unmanaged alert volume create enterprise risk, and how a consolidation layer can help.","2026-09-12T00:00:00.000Z",{"name":15,"url":16},[32,23,33,34,35,44],"Enterprise Risk",{"id":46,"content_html":47,"url":46,"title":48,"summary":49,"date_modified":50,"author":51,"tags":52},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F24\u002Fjetro-features-eventus-aiomt-platform","\u003Cp>We are proud to share that \u003Cstrong>Eventus\u003C\u002Fstrong> has been featured by the \u003Cstrong>Japan External Trade Organization (JETRO)\u003C\u002Fstrong> in its latest \u003Cem>Investing in Japan\u003C\u002Fem> newsroom article: \u003Ca href=\"https:\u002F\u002Fwww.jetro.go.jp\u002Fen\u002Finvest\u002Fnewsroom\u002F2026\u002F784e37843a52ae78\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Eventus Hong Kong Limited Establishes Japanese Subsidiary in Tokyo to Provide AIoMT Platform\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Published on August 24, 2026, the feature recognizes Eventus’s expansion from Hong Kong into Japan and introduces our work in AIoMT—Artificial Intelligence of Medical Things. It also highlights how our Tokyo subsidiary, Eventus K.K., is helping bring practical healthcare and cybersecurity solutions to the Japanese market.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"from-hong-kong-to-tokyo\">From Hong Kong to Tokyo\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F24\u002Fjetro-features-eventus-aiomt-platform#from-hong-kong-to-tokyo\" class=\"hash-link\" aria-label=\"Direct link to From Hong Kong to Tokyo\" title=\"Direct link to From Hong Kong to Tokyo\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Eventus Hong Kong Limited was established in 2016 to develop IT solutions that connect data, devices, and intelligence. In September 2024, we established \u003Cstrong>Eventus K.K.\u003C\u002Fstrong> in Tokyo to strengthen our sales and customer support in Japan.\u003C\u002Fp>\n\u003Cp>JETRO’s coverage places this expansion in the context of Japan’s aging population and the growing demand for digitalization across healthcare. For Eventus, Japan is an important market for building partnerships and demonstrating how connected data can improve patient monitoring and operational efficiency.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"making-healthcare-data-more-usable-with-sekhmet\">Making healthcare data more usable with SEKHMET\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F24\u002Fjetro-features-eventus-aiomt-platform#making-healthcare-data-more-usable-with-sekhmet\" class=\"hash-link\" aria-label=\"Direct link to Making healthcare data more usable with SEKHMET\" title=\"Direct link to Making healthcare data more usable with SEKHMET\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The article features \u003Cstrong>SEKHMET\u003C\u002Fstrong>, our AIoMT platform for integrating clinical and IoT data. SEKHMET supports the real-time monitoring and analysis of patient vital information while making data available for broader operational and analytical use.\u003C\u002Fp>\n\u003Cp>At the center of the platform is our \u003Cstrong>Software-Defined Gateway (SDG)\u003C\u002Fstrong> architecture. Existing smartphones and PCs can function as medical IoT hubs, reducing the need for dedicated gateway hardware and helping organizations create remote monitoring environments with less deployment friction.\u003C\u002Fp>\n\u003Cp>This approach gives healthcare providers and technology partners a flexible way to connect devices, collect information, and prepare data for AI-powered analysis.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"supporting-security-with-siem\">Supporting security with SIEM+\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F24\u002Fjetro-features-eventus-aiomt-platform#supporting-security-with-siem\" class=\"hash-link\" aria-label=\"Direct link to Supporting security with SIEM+\" title=\"Direct link to Supporting security with SIEM+\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>JETRO also highlights \u003Cstrong>SIEM+\u003C\u002Fstrong>, Eventus’s AI-based cybersecurity support platform. SIEM+ works within existing IT environments to analyze log data and visualize potential threats, helping small and medium-sized organizations operate more efficiently.\u003C\u002Fp>\n\u003Cp>Together, SEKHMET and SIEM+ reflect a common principle behind our products: useful intelligence starts with connected, understandable data. Whether the data comes from medical devices or IT systems, organizations need practical tools that turn complex signals into timely decisions.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"building-momentum-in-japan\">Building momentum in Japan\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F24\u002Fjetro-features-eventus-aiomt-platform#building-momentum-in-japan\" class=\"hash-link\" aria-label=\"Direct link to Building momentum in Japan\" title=\"Direct link to Building momentum in Japan\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>JETRO’s Invest Japan Business Support Center (IBSC) supported Eventus through exhibition participation assistance, business matching, and public relations support. We are grateful for this support as we continue developing relationships in Japan.\u003C\u002Fp>\n\u003Cp>Our team has participated in domestic exhibitions and startup support programs, including the \u003Cstrong>Innovation Leaders Summit (ILS)\u003C\u002Fstrong> and \u003Cstrong>Startup Japan Expo 2026\u003C\u002Fstrong>. These opportunities have allowed us to demonstrate our solutions, meet potential partners, and learn more about the needs of the Japanese market.\u003C\u002Fp>\n\u003Cp>Being featured by JETRO is an encouraging milestone for Eventus. We look forward to continuing our work with healthcare providers, technology companies, and other partners that are interested in better ways to use medical, IoT, and security data.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"read-the-jetro-feature\">Read the JETRO feature\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F24\u002Fjetro-features-eventus-aiomt-platform#read-the-jetro-feature\" class=\"hash-link\" aria-label=\"Direct link to Read the JETRO feature\" title=\"Direct link to Read the JETRO feature\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Read the full coverage in \u003Ca href=\"https:\u002F\u002Fwww.jetro.go.jp\u002Fen\u002Finvest\u002Fnewsroom\u002F2026\u002F784e37843a52ae78\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">English on JETRO’s website\u003C\u002Fa> or \u003Ca href=\"https:\u002F\u002Fwww.jetro.go.jp\u002Finvest\u002Fnewsroom\u002F2026\u002F1c6226702d92170b\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Japanese on JETRO’s website\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>To learn more about our platforms, visit \u003Ca href=\"https:\u002F\u002Fsekhmet.tech\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">SEKHMET\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Feventus.one\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Eventus\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"Abstract healthcare and IoT data connections between Hong Kong and Tokyo\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fjetro-features-eventus-aiomt-platform-e90f984bc82b68dc7a0b2c6b3cd0d70f.png\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>","JETRO Features Eventus: Expanding AIoMT Innovation from Hong Kong to Japan","JETRO highlights Eventus Hong Kong Limited's Tokyo expansion, AIoMT platform SEKHMET, and the role of JETRO support in growing our business in Japan.","2026-08-24T00:00:00.000Z",{"name":15,"url":16},[18,53,54,55,56,57,58,59],"JETRO","AIoMT","SEKHMET","IoT","HealthTech","Japan","DigitalTransformation",{"id":61,"content_html":62,"url":61,"title":63,"summary":64,"date_modified":65,"author":66,"tags":67},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F23\u002Ffrom-40000-alerts-to-fewer-than-10-cases-a-day","\u003Cp>Security teams are not short on alerts. They are short on time, context, and attention.\u003C\u002Fp>\n\u003Cp>A 2025 survey of 2,058 security leaders found that 59% receive too many alerts, while 52% described their SOCs as overworked. \u003Ca href=\"https:\u002F\u002Fwww.securitymagazine.com\u002Farticles\u002F101646-52-of-soc-teams-are-overworked-new-report-shows\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Security Magazine’s summary of the research\u003C\u002Fa> also found that many teams lose investigation time because their security data is difficult to manage and disconnected across tools.\u003C\u002Fp>\n\u003Cp>The human cost is just as clear. In the 2025 ISC2 Cybersecurity Workforce Study, 48% of respondents said they felt exhausted from trying to keep up with new threats and technologies, while 47% felt overwhelmed by their workload. \u003Ca href=\"https:\u002F\u002Fwww.isc2.org\u002FInsights\u002F2025\u002F12\u002F2025-ISC2-Cybersecurity-Workforce-Study\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">ISC2’s study\u003C\u002Fa> surveyed more than 16,000 cybersecurity professionals and decision-makers.\u003C\u002Fp>\n\u003Cp>This is alert fatigue: the point where every notification starts to look the same, every investigation feels urgent, and analysts have to spend more energy deciding what to ignore than determining what matters.\u003C\u002Fp>\n\u003Cp>It is not a company-specific problem. It is an operational problem affecting security teams everywhere.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-siem-noise-looks-like-in-practice\">What SIEM noise looks like in practice\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F23\u002Ffrom-40000-alerts-to-fewer-than-10-cases-a-day#what-siem-noise-looks-like-in-practice\" class=\"hash-link\" aria-label=\"Direct link to What SIEM noise looks like in practice\" title=\"Direct link to What SIEM noise looks like in practice\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Alert fatigue is often discussed as if it simply means “too many alerts.” In practice, the problem is more complicated.\u003C\u002Fp>\n\u003Cp>A single event can generate multiple notifications across different security systems. One suspicious login might appear as an identity alert, an endpoint alert, a cloud activity alert, and a network anomaly. Each notification may be technically valid, but none of them provides the complete picture.\u003C\u002Fp>\n\u003Cp>Then there are the alerts that are difficult to interpret. They may contain a severity level, a timestamp, and a technical message, but not enough context to answer basic questions:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">Is this activity genuinely unusual?\u003C\u002Fli>\n\u003Cli class=\"\">Has the same behavior already been reviewed?\u003C\u002Fli>\n\u003Cli class=\"\">Is this connected to anything else happening in the environment?\u003C\u002Fli>\n\u003Cli class=\"\">Does it require action now, or can it wait?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Low-signal notifications create the same problem. Routine administrative activity, known-safe behavior, and repeated background events can all compete for attention with a genuine security incident.\u003C\u002Fp>\n\u003Cp>The result is not just a larger queue. It is a weaker triage process.\u003C\u002Fp>\n\u003Cp>The 2026 SANS SOC Survey described the issue plainly: security operations practitioners are dealing with too many alerts that do not connect and not enough shared context to act on. In the survey, 24% of cyber leaders identified a lack of enterprise-wide visibility as the biggest barrier to effective security operations. \u003Ca href=\"https:\u002F\u002Fwww.sans.org\u002Fpress\u002Fannouncements\u002F24-of-cyber-leaders-cite-lack-of-enterprise-wide-visibility-as-the-biggest-barrier-to-soc-effectiveness-the-2026-sans-soc-survey-finds\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">SANS’ 2026 findings\u003C\u002Fa> were based on responses from security operations professionals and senior security executives.\u003C\u002Fp>\n\u003Cp>When analysts cannot quickly connect related activity, every alert becomes a separate task. That is where SIEM noise turns into real operational cost.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"a-real-example-40000-alerts-a-day-to-fewer-than-10-cases\">A real example: 40,000 alerts a day to fewer than 10 cases\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F23\u002Ffrom-40000-alerts-to-fewer-than-10-cases-a-day#a-real-example-40000-alerts-a-day-to-fewer-than-10-cases\" class=\"hash-link\" aria-label=\"Direct link to A real example: 40,000 alerts a day to fewer than 10 cases\" title=\"Direct link to A real example: 40,000 alerts a day to fewer than 10 cases\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>One real SIEM+ customer was dealing with approximately 40,000 alerts per day.\u003C\u002Fp>\n\u003Cp>After SIEM+ was introduced, that volume was reduced to fewer than 10 cases per day.\u003C\u002Fp>\n\u003Cp>The point is not that the environment suddenly stopped producing security activity. The point is that the triage layer became better at separating repeated signals, expected activity, and meaningful risk.\u003C\u002Fp>\n\u003Cp>The customer received a much smaller number of cases that represented actual investigative work. The qualitative outcome was straightforward: the team could focus on what mattered without feeling that something was falling through the cracks.\u003C\u002Fp>\n\u003Cp>That distinction matters.\u003C\u002Fp>\n\u003Cp>Reducing alert volume is not the same as reducing visibility. Suppressing everything may produce a quieter dashboard, but it does not produce better security. Effective SIEM noise reduction means making the remaining cases more useful, more understandable, and easier to prioritize.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-actually-changed\">What actually changed\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F23\u002Ffrom-40000-alerts-to-fewer-than-10-cases-a-day#what-actually-changed\" class=\"hash-link\" aria-label=\"Direct link to What actually changed\" title=\"Direct link to What actually changed\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>At an outcome level, the change came from improving how alerts were evaluated before they reached the human investigation queue.\u003C\u002Fp>\n\u003Cp>First, duplicate alerts were grouped together. Related notifications could be treated as one developing situation instead of several disconnected tasks. This reduced repetition without removing the underlying evidence.\u003C\u002Fp>\n\u003Cp>Second, known-safe and known-bad activity could be handled more consistently. Activity that matched established patterns did not need to consume the same attention as something genuinely unusual. Clearly malicious signals could be prioritized instead of being lost in a larger stream.\u003C\u002Fp>\n\u003Cp>Third, behavioral anomalies were considered in context. An event is not always risky simply because it is uncommon, and familiar activity is not always safe simply because it has happened before. Looking at behavior over time helps distinguish meaningful deviations from ordinary variation.\u003C\u002Fp>\n\u003Cp>Finally, activity across related accounts and systems could be correlated. Instead of asking an analyst to manually connect separate alerts, the triage process could present a more complete view of the activity. That makes it easier to understand whether several events are part of one investigation or unrelated noise.\u003C\u002Fp>\n\u003Cp>This is where AI security triage can be useful: not as a replacement for experienced analysts, but as a way to handle repetitive evaluation and organize the information that analysts need to make decisions.\u003C\u002Fp>\n\u003Cp>The goal is a cleaner queue, better context, and more consistent outcomes.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-answer-is-not-always-more-analysts\">The answer is not always more analysts\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F23\u002Ffrom-40000-alerts-to-fewer-than-10-cases-a-day#the-answer-is-not-always-more-analysts\" class=\"hash-link\" aria-label=\"Direct link to The answer is not always more analysts\" title=\"Direct link to The answer is not always more analysts\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>When an SOC is overwhelmed, the obvious response is often to hire more people.\u003C\u002Fp>\n\u003Cp>Additional expertise can help, but headcount alone does not fix a triage process that sends every duplicate, low-signal, and poorly contextualized alert to a human. More analysts may simply create a larger team working through the same noise.\u003C\u002Fp>\n\u003Cp>The better question is: what should reach an analyst in the first place?\u003C\u002Fp>\n\u003Cp>Security teams need enough information to investigate real risk, but they do not need to manually reconstruct every connection between alerts. They should not have to spend most of their time translating cryptic messages, checking whether an alert is a duplicate, or deciding whether a familiar event is worth escalating.\u003C\u002Fp>\n\u003Cp>That is why the triage layer matters so much. It sits between raw security activity and human decision-making. When it works well, analysts spend more time investigating meaningful cases and less time processing noise.\u003C\u002Fp>\n\u003Cp>SIEM+ is designed for that layer. It works with any SIEM, so teams can improve alert handling without a rip-and-replace project or a complete redesign of their existing security environment.\u003C\u002Fp>\n\u003Cp>The practical lesson from 40,000 alerts becoming fewer than 10 cases is simple: security operations do not always need more data or more dashboards. They need a better way to turn data into focused investigative work.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fsiem.plus\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Book a 15-Minute Demo\u003C\u002Fa> or \u003Ca href=\"https:\u002F\u002Fsiem.plus\u002Fpricing\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">View Pricing\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"A dense stream of security alerts converging into a few clear incident cases\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Falert-fatigue-40k-to-fewer-than-10-cases-52109ba44de83f16f61ff6859be4e797.png\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>","From 40,000 Alerts to Fewer Than 10 Cases a Day: What Alert Fatigue Really Costs Security Teams","See what alert fatigue costs SOC teams and how SIEM+ helped one customer reduce 40,000 daily alerts to fewer than 10 cases.","2026-08-23T00:00:00.000Z",{"name":15,"url":16},[32,23,33,34,35],{"id":69,"content_html":70,"url":69,"title":71,"summary":72,"date_modified":73,"author":74,"tags":75},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations","\u003Cp>At 9:02 on Monday morning, a public-facing firewall starts recording a port scan.\u003C\u002Fp>\n\u003Cp>By 9:05, the SIEM has generated 5,000 alerts. The IT lead opens the dashboard, sees a wall of red, and asks the question every small security team eventually asks:\u003C\u002Fp>\n\u003Cp>“Can’t we just put AI on top of the SIEM and have it tell us what matters?”\u003C\u002Fp>\n\u003Cp>It is a reasonable question. The right direction is, in fact, \u003Cstrong>AI on top of SIEM\u003C\u002Fstrong>. Your existing SIEM already collects events, applies detection rules, and stores the evidence. An AI layer can translate that output into priorities, explanations, and next actions.\u003C\u002Fp>\n\u003Cp>That is the idea behind \u003Ca href=\"https:\u002F\u002Fsiem.plus\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">SIEM+\u003C\u002Fa>, an AI security overlay for teams that want better triage and clearer security posture without replacing the SIEM they already operate.\u003C\u002Fp>\n\u003Cp>A generic chatbot, a one-off LLM script, or a loosely connected AI copilot may produce an impressive answer to one alert. Security operations require something more durable: a system that remembers context, groups related evidence, respects data boundaries, tracks posture over time, and produces outputs people can act on and defend later.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"AI security operations layer transforming noisy SIEM alerts into correlated incident cases\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fai-on-top-of-siem-siem-ai-3f6fb9ac2d27f1f70b1ccd435c5bd217.webp\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-does-ai-on-top-of-siem-mean\">What does AI on top of SIEM mean?\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#what-does-ai-on-top-of-siem-mean\" class=\"hash-link\" aria-label=\"Direct link to What does AI on top of SIEM mean?\" title=\"Direct link to What does AI on top of SIEM mean?\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>AI on top of SIEM means adding an intelligence and workflow layer to an existing SIEM rather than replacing it. The layer ingests alerts, correlates related activity, explains risk, and connects findings to investigation and remediation.\u003C\u002Fp>\n\u003Cp>Most businesses already have a SIEM, years of log retention, alert rules, dashboards, and integrations. Adding a chatbot appears to avoid another platform purchase. An engineer can export a few events, paste them into a prompt, and ask:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">Is this a real threat?\u003C\u002Fli>\n\u003Cli class=\"\">What does this event mean?\u003C\u002Fli>\n\u003Cli class=\"\">Which compliance control does it affect?\u003C\u002Fli>\n\u003Cli class=\"\">What should we do next?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For a single event, this can be useful. An LLM is good at translating jargon, summarizing evidence, and suggesting investigative paths.\u003C\u002Fp>\n\u003Cp>It can turn an event such as \u003Ccode>4625: failed logon\u003C\u002Fcode> into a sentence an IT generalist understands, explain an impossible-travel detection, and draft remediation guidance quickly.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-is-siem-ai\">What is SIEM AI?\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#what-is-siem-ai\" class=\"hash-link\" aria-label=\"Direct link to What is SIEM AI?\" title=\"Direct link to What is SIEM AI?\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>SIEM AI\u003C\u002Fstrong> is an AI layer that turns SIEM alerts and log evidence into correlated cases, prioritized risk, plain-English explanations, and response workflows. It is more than a chatbot connected to a search box.\u003C\u002Fp>\n\u003Cp>That makes \u003Cstrong>SIEM AI\u003C\u002Fstrong> sound simple: take existing alerts, send them to a model, and let the model reduce the noise. But security operations are continuous and stateful, involving incomplete evidence, changing environments, multiple analysts, audit requirements, and production actions.\u003C\u002Fp>\n\u003Cp>The practical difference between generic AI and purpose-built SIEM AI is the operating layer around the model: durable cases, grounded evidence, environment context, and recorded actions.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"where-generic-ai-breaks-down\">Where generic AI breaks down\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#where-generic-ai-breaks-down\" class=\"hash-link\" aria-label=\"Direct link to Where generic AI breaks down\" title=\"Direct link to Where generic AI breaks down\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-it-has-no-reliable-memory-across-alerts-and-shifts\">1. It has no reliable memory across alerts and shifts\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#1-it-has-no-reliable-memory-across-alerts-and-shifts\" class=\"hash-link\" aria-label=\"Direct link to 1. It has no reliable memory across alerts and shifts\" title=\"Direct link to 1. It has no reliable memory across alerts and shifts\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>A chat session may understand the incident currently in front of it. It usually does not maintain a durable, structured history of what happened yesterday, what an analyst already investigated, or which remediation step was completed.\u003C\u002Fp>\n\u003Cp>Consider a user account that produces several low-severity events over three days:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">A login from a new country, multiple failed MFA attempts, and a successful login from an unfamiliar ASN\u003C\u002Fli>\n\u003Cli class=\"\">A token refresh from a device not previously associated with the user\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Viewed separately, none of these events may be decisive. Viewed as a timeline, they may represent one identity incident that needs immediate attention.\u003C\u002Fp>\n\u003Cp>If the AI receives each alert in a separate prompt, it may describe each one accurately while missing the relationship between them. The next analyst or next shift has to reconstruct the case manually.\u003C\u002Fp>\n\u003Cp>A production \u003Cstrong>AI security overlay\u003C\u002Fstrong> needs persistent cases, timelines, analyst decisions, and remediation state. It should know whether an alert is new, already investigated, related to another case, or resolved.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-context-windows-do-not-match-real-log-volume\">2. Context windows do not match real log volume\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#2-context-windows-do-not-match-real-log-volume\" class=\"hash-link\" aria-label=\"Direct link to 2. Context windows do not match real log volume\" title=\"Direct link to 2. Context windows do not match real log volume\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>A SIEM does not produce five events. It produces thousands or millions.\u003C\u002Fp>\n\u003Cp>You cannot paste 50,000 events into a prompt and expect a model to reliably identify the important relationship. Even if the context window technically accepts the input, the result may be expensive, slow, difficult to reproduce, and vulnerable to irrelevant data drowning out the signal.\u003C\u002Fp>\n\u003Cp>The common workaround is to summarize the logs first. But a seemingly unimportant event may be the detail that connects an account compromise to a privileged action or persistence.\u003C\u002Fp>\n\u003Cp>A robust AI-on-SIEM architecture needs an ingestion and normalization layer before the model sees the data. It should extract consistent fields such as timestamps, identities, IP addresses, devices, event types, and source systems. It should retrieve relevant evidence in bounded sets and preserve links back to the original records.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-it-can-hallucinate-compliance-mappings\">3. It can hallucinate compliance mappings\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#3-it-can-hallucinate-compliance-mappings\" class=\"hash-link\" aria-label=\"Direct link to 3. It can hallucinate compliance mappings\" title=\"Direct link to 3. It can hallucinate compliance mappings\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Generic AI is particularly risky when asked to map findings to frameworks such as \u003Cstrong>NIST CSF\u003C\u002Fstrong> or \u003Cstrong>CIS Controls\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>A model may produce a plausible-sounding control identifier that is outdated, too broad, or simply wrong. It may confuse a framework function with a specific category. It may claim that an event proves a control is operating when the evidence only indicates that a related activity occurred.\u003C\u002Fp>\n\u003Cp>This is why compliance mapping needs a constrained and verified pipeline. The system should use a controlled framework taxonomy, require evidence for each mapping, distinguish between monitored and unmonitored areas, and avoid presenting an inference as proof.\u003C\u002Fp>\n\u003Cp>The same principle applies to posture scores. As we described in \u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">“Why Static Dashboards Are Dead”\u003C\u002Fa>, a meaningful score must be tied to grouped cases, severity, coverage, and explainable evidence rather than raw alert counts.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"4-it-treats-alerts-atomically-instead-of-correlating-cases\">4. It treats alerts atomically instead of correlating cases\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#4-it-treats-alerts-atomically-instead-of-correlating-cases\" class=\"hash-link\" aria-label=\"Direct link to 4. It treats alerts atomically instead of correlating cases\" title=\"Direct link to 4. It treats alerts atomically instead of correlating cases\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>The port-scan example shows the problem clearly.\u003C\u002Fp>\n\u003Cp>Five thousand firewall drops may represent one scanning activity. If generic AI receives those events as separate rows, it may produce a long list of individually correct observations. It may even assign a high-severity label to the overall result simply because the volume is large.\u003C\u002Fp>\n\u003Cp>Security teams need \u003Cstrong>case correlation\u003C\u002Fstrong>. Related alerts should be grouped by intent, identity, source, target, time window, and surrounding activity. The output should be something like:\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>A single external host performed a rapid port scan against a public-facing address over three minutes. No successful connection or downstream compromise was observed.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>That summary is more useful than 5,000 alert explanations and helps decide whether to block the source, investigate, or close it as background noise.\u003C\u002Fp>\n\u003Cp>This is the foundation of effective \u003Cstrong>AI SIEM triage\u003C\u002Fstrong>: reducing duplicate signals into cases that represent actual investigative work.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"5-it-does-not-know-what-is-normal-for-your-environment\">5. It does not know what is normal for your environment\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#5-it-does-not-know-what-is-normal-for-your-environment\" class=\"hash-link\" aria-label=\"Direct link to 5. It does not know what is normal for your environment\" title=\"Direct link to 5. It does not know what is normal for your environment\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>A login from Singapore may be suspicious for one employee and completely normal for another. A service account authenticating from a new host may be expected during a migration or may indicate credential abuse. A burst of administrator activity may be part of a scheduled maintenance window.\u003C\u002Fp>\n\u003Cp>Without an environment-specific baseline, AI can produce confident but generic judgments. It may overreact to normal activity or underreact to a change that is highly unusual for your organization.\u003C\u002Fp>\n\u003Cp>A purpose-built layer should retain relevant environmental context: known identities, expected locations, asset roles, critical systems, normal activity patterns, and recent changes.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"6-a-chat-transcript-is-not-audit-grade-evidence\">6. A chat transcript is not audit-grade evidence\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#6-a-chat-transcript-is-not-audit-grade-evidence\" class=\"hash-link\" aria-label=\"Direct link to 6. A chat transcript is not audit-grade evidence\" title=\"Direct link to 6. A chat transcript is not audit-grade evidence\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>A conversation can help during investigation, but it is rarely the right final artifact for an auditor, insurer, executive, or incident reviewer.\u003C\u002Fp>\n\u003Cp>A transcript does not necessarily show which source records were used, what control was evaluated, whether a gap existed, or who approved remediation.\u003C\u002Fp>\n\u003Cp>Auditors need an evidence-backed explanation, not just an AI-generated conclusion, including what was monitored, what was found, how it maps to a control, and where coverage is limited.\u003C\u002Fp>\n\u003Cp>That is why \u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">audit-ready reporting\u003C\u002Fa> should be designed into the platform rather than assembled manually from screenshots, spreadsheets, and chat history.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"7-advice-without-an-action-loop-leaves-the-work-unfinished\">7. Advice without an action loop leaves the work unfinished\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#7-advice-without-an-action-loop-leaves-the-work-unfinished\" class=\"hash-link\" aria-label=\"Direct link to 7. Advice without an action loop leaves the work unfinished\" title=\"Direct link to 7. Advice without an action loop leaves the work unfinished\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Generic AI can recommend “isolate the endpoint,” “disable the account,” or “rotate the token.” But if the operator must copy that advice into another tool, find the right asset, confirm the identity, and perform the action manually, the workflow still has a significant delay.\u003C\u002Fp>\n\u003Cp>Security operations need a connected action loop:\u003C\u002Fp>\n\u003Col>\n\u003Cli class=\"\">Detect related activity.\u003C\u002Fli>\n\u003Cli class=\"\">Explain the risk in plain English.\u003C\u002Fli>\n\u003Cli class=\"\">Recommend a specific response.\u003C\u002Fli>\n\u003Cli class=\"\">Present the supporting evidence.\u003C\u002Fli>\n\u003Cli class=\"\">Allow an authorized operator to take the action.\u003C\u002Fli>\n\u003Cli class=\"\">Record what happened.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The action should become part of the case history, not disappear into another console or an informal message thread.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-done-right-looks-like\">What “done right” looks like\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#what-done-right-looks-like\" class=\"hash-link\" aria-label=\"Direct link to What “done right” looks like\" title=\"Direct link to What “done right” looks like\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>A real AI-on-SIEM layer should behave less like a chatbot and more like an operational system.\u003C\u002Fp>\n\u003Cp>First, it needs ingestion and normalization across the SIEM tools an organization already uses, including Microsoft Sentinel, Splunk, QRadar, Devo, and Chronicle, without requiring a rip-and-replace project.\u003C\u002Fp>\n\u003Cp>Second, it needs durable security state. That includes correlated cases, historical posture, data coverage, analyst decisions, response status, and environment-specific context. A score that changes over time should explain why it changed.\u003C\u002Fp>\n\u003Cp>Third, the AI needs guardrails. Triage agents should work from retrieved evidence, constrained schemas, controlled severity logic, and defined output fields. Compliance agents should map findings against verified framework references and distinguish evidence from interpretation.\u003C\u002Fp>\n\u003Cp>Fourth, the platform needs two kinds of output.\u003C\u002Fp>\n\u003Cp>Operations needs a prioritized queue, plain-English explanations, case timelines, and remediation steps. Leadership and compliance need trends, category scores, framework alignment, coverage gaps, and defensible reports.\u003C\u002Fp>\n\u003Cp>The same underlying evidence should support both views.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-siem-approaches-this\">How SIEM+ approaches this\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#how-siem-approaches-this\" class=\"hash-link\" aria-label=\"Direct link to How SIEM+ approaches this\" title=\"Direct link to How SIEM+ approaches this\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>SIEM+ is designed as an intelligent overlay for an existing SIEM architecture. It ingests alerts and exported log data, normalizes important event context, and uses AI agents to support triage, investigation context, threat translation, and audit preparation. \u003Ca href=\"https:\u002F\u002Fsiem.plus\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Learn more about SIEM+\u003C\u002Fa> and its AI security overlay.\u003C\u002Fp>\n\u003Cp>Instead of exposing another wall of vendor-specific event codes, SIEM+ turns technical findings into plain-English summaries with business impact, supporting evidence, and prioritized remediation guidance. Its dynamic 0–100 security health score tracks areas such as identity, perimeter, endpoints, and infrastructure, giving teams a view of posture that is more useful than a raw alert count.\u003C\u002Fp>\n\u003Cp>The product also separates the operational and governance workflows. The \u003Cstrong>AI Ops View\u003C\u002Fstrong> focuses on prioritized alerts, incident translation, and response actions such as endpoint isolation. The \u003Cstrong>AI Auditor View\u003C\u002Fstrong> focuses on NIST CSF and CIS control mapping, evidence, posture trends, and one-click PDF exports.\u003C\u002Fp>\n\u003Cp>SIEM+ is intended to work with the security tools organizations already have. Public product information lists Microsoft Sentinel, Google Chronicle, Splunk, Devo, IBM QRadar, Elastic Security, and others, allowing teams to add an AI layer without rebuilding their SIEM foundation.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"ai-on-top-of-siem-is-the-right-idea-with-the-right-architecture\">AI on top of SIEM is the right idea, with the right architecture\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F15\u002Fai-on-top-of-siem-siem-ai-security-operations#ai-on-top-of-siem-is-the-right-idea-with-the-right-architecture\" class=\"hash-link\" aria-label=\"Direct link to AI on top of SIEM is the right idea, with the right architecture\" title=\"Direct link to AI on top of SIEM is the right idea, with the right architecture\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The question is not whether AI belongs on top of a SIEM. It does. The question is whether the AI layer is connected to the operational realities of security work: persistent context, high-volume ingestion, case correlation, environment baselines, constrained compliance mapping, audit-grade evidence, and an action loop.\u003C\u002Fp>\n\u003Cp>A generic model can explain an alert. A purpose-built \u003Cstrong>SIEM AI\u003C\u002Fstrong> platform should help operate the security program around that alert.\u003C\u002Fp>\n\u003Cp>If your team is already running a SIEM but still spends too much time decoding alerts, rebuilding context, and preparing reports, \u003Ca href=\"https:\u002F\u002Fsiem.plus\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">book a 15-minute SIEM+ demo\u003C\u002Fa> to see how an AI security overlay can fit over your existing environment.\u003C\u002Fp>","AI on Top of SIEM: What SIEM AI Needs to Reduce Alert Fatigue","AI on top of SIEM can reduce alert fatigue. Learn what SIEM AI needs for persistent context, case correlation, posture scoring, and audit-ready workflows.","2026-08-15T00:00:00.000Z",{"name":15,"url":16},[32,23,35,33,34,76],"Compliance",{"id":78,"content_html":79,"url":78,"title":80,"summary":81,"date_modified":82,"author":83,"tags":84},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus","\u003Cp>Every audit season, the same scene plays out. A security team exports a mountain of raw logs, a spreadsheet of alert counts, and a screenshot of a dashboard covered in red and yellow blocks. They hand it to the auditor and hope for the best.\u003C\u002Fp>\n\u003Cp>The auditor doesn't want any of that. They want one question answered clearly: \u003Cstrong>\"Can you prove this control is working, and show me the evidence?\"\u003C\u002Fstrong> If the answer takes twenty minutes of dashboard-squinting to extract, you've already failed the real test — not of your security posture, but of your ability to communicate it.\u003C\u002Fp>\n\u003Cp>This is the problem we built the SIEM+ (\u003Ca href=\"https:\u002F\u002Fsiem.plus\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">siem.plus\u003C\u002Fa>) Auditor View to solve. Not \"more visibility.\" \u003Cstrong>Comprehensible\u003C\u002Fstrong> visibility — audit-ready by default, not audit-ready after a week of manual report building.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"SIEM+ audit report turning raw alert noise into a board- and auditor-ready evidence pack\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Faudit-report-clarity-siem-plus-f422e513e47141eb82315710b3ca923b.png\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-real-cost-of-an-unreadable-audit-report\">The real cost of an unreadable audit report\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#the-real-cost-of-an-unreadable-audit-report\" class=\"hash-link\" aria-label=\"Direct link to The real cost of an unreadable audit report\" title=\"Direct link to The real cost of an unreadable audit report\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Most SIEM tooling was built for analysts, not for auditors, executives, or regulators. That's fine for triage — but it's the wrong artifact to hand to someone who needs to sign off on your compliance posture. An unreadable report costs you in three concrete ways:\u003C\u002Fp>\n\u003Col>\n\u003Cli class=\"\">\u003Cstrong>Auditor fatigue becomes auditor suspicion.\u003C\u002Fstrong> When evidence is scattered and requires interpretation, auditors don't assume competence — they assume something is being hidden, and they dig deeper, longer, and more skeptically.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Every audit becomes a fire drill.\u003C\u002Fstrong> If your \"report\" is really a live dashboard plus a week of screenshots and Slack threads to compile evidence, you're paying your best engineers to do report formatting instead of security work.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>The board sees a wall of noise, not a risk decision.\u003C\u002Fstrong> Executives need a number and a trend, not 10,000 alert rows. If they can't parse it, they either over-trust it or ignore it — neither is good governance.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-siem-builds-an-audit-report-that-reads-in-minutes-not-hours\">How SIEM+ builds an audit report that reads in minutes, not hours\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#how-siem-builds-an-audit-report-that-reads-in-minutes-not-hours\" class=\"hash-link\" aria-label=\"Direct link to How SIEM+ builds an audit report that reads in minutes, not hours\" title=\"Direct link to How SIEM+ builds an audit report that reads in minutes, not hours\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>We designed the SIEM+ Auditor View around a simple principle: \u003Cstrong>every score, on every page, must be traceable to a plain-English sentence of evidence.\u003C\u002Fstrong> Here's what that looks like in practice.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-cases-not-alert-floods\">1. Cases, not alert floods\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#1-cases-not-alert-floods\" class=\"hash-link\" aria-label=\"Direct link to 1. Cases, not alert floods\" title=\"Direct link to 1. Cases, not alert floods\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Before anything reaches the report, our AI engine performs \u003Cstrong>Case Grouping\u003C\u002Fstrong> — consolidating related alerts (a burst of failed logins followed by an MFA bypass, for example) into a single Case with a root cause, a timeline, and a severity. An auditor reading the report never sees \"1,204 failed login events.\" They see one line: \u003Cem>\"MFA bypass detected and remediated for a single privileged account.\"\u003C\u002Fem> That is a sentence a compliance officer can act on immediately.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-a-posture-score-that-means-something\">2. A posture score that means something\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#2-a-posture-score-that-means-something\" class=\"hash-link\" aria-label=\"Direct link to 2. A posture score that means something\" title=\"Direct link to 2. A posture score that means something\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Instead of a flat percentage with no explanation, every category — Identity &amp; Access Management, Network Boundary, Continuous Monitoring, Audit Log Management — carries its own score, built from our penalty decay algorithm rather than a naive linear count of alerts. Critically, \u003Cstrong>each score is paired with the evidence that produced it.\u003C\u002Fstrong> Expand \"Access Control · 94%\" and you get the actual sentence: \u003Cem>\"Quarterly access review completed for all business units; one stale contractor entitlement remediated.\"\u003C\u002Fem> No score in SIEM+ exists without a human-readable reason attached to it.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-framework-mapping-done-automatically-not-manually\">3. Framework mapping done automatically, not manually\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#3-framework-mapping-done-automatically-not-manually\" class=\"hash-link\" aria-label=\"Direct link to 3. Framework mapping done automatically, not manually\" title=\"Direct link to 3. Framework mapping done automatically, not manually\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Compliance teams have historically spent hours mapping internal controls to frameworks like \u003Cstrong>NIST CSF v2.0\u003C\u002Fstrong> and \u003Cstrong>CIS Controls v8\u003C\u002Fstrong> in a spreadsheet, by hand, every quarter. SIEM+ does this mapping continuously: each category in the report is tagged directly against the relevant control (\u003Ccode>PR.AC\u003C\u002Fcode>, \u003Ccode>DE.CM\u003C\u002Fcode>, \u003Ccode>Control 6\u003C\u002Fcode>, \u003Ccode>Control 8\u003C\u002Fcode>, and so on), so the auditor can trace a finding straight back to the framework clause they're checking against — no translation layer required.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"4-coverage-gaps-are-called-out-not-hidden\">4. Coverage gaps are called out, not hidden\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#4-coverage-gaps-are-called-out-not-hidden\" class=\"hash-link\" aria-label=\"Direct link to 4. Coverage gaps are called out, not hidden\" title=\"Direct link to 4. Coverage gaps are called out, not hidden\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>An audit report that only shows good news isn't credible — and it isn't useful. If a category has no log coverage, SIEM+ flags it explicitly as \u003Cstrong>unmonitored\u003C\u002Fstrong>, in red, rather than silently omitting it or scoring it as if everything were fine. Auditors trust reports that show their own blind spots. Hiding a gap only guarantees the auditor finds it themselves, and finds it as a bigger problem than it actually is.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"5-operational-proof-not-just-posture\">5. Operational proof, not just posture\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#5-operational-proof-not-just-posture\" class=\"hash-link\" aria-label=\"Direct link to 5. Operational proof, not just posture\" title=\"Direct link to 5. Operational proof, not just posture\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Alongside the framework mapping, the report surfaces the metrics auditors actually ask for in interviews: Mean Time to First Response, total case volume, AI-automated triage rate, and percentage of critical\u002Fhigh cases closed within SLA. These are pulled live from case data over the trailing 30 days — not reconstructed from memory during the audit itself.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"6-continuous-heartbeat-proving-the-logs-never-stopped\">6. Continuous Heartbeat: proving the logs never stopped\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#6-continuous-heartbeat-proving-the-logs-never-stopped\" class=\"hash-link\" aria-label=\"Direct link to 6. Continuous Heartbeat: proving the logs never stopped\" title=\"Direct link to 6. Continuous Heartbeat: proving the logs never stopped\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>A control that \"exists\" on paper but has a silent ingestion gap is worse than no control at all, because it creates false confidence. The Auditor View includes a \u003Cstrong>Continuous Heartbeat\u003C\u002Fstrong> timeline across Cloud\u002FIdentity, Network, and Endpoint sources, color-coded green\u002Fyellow\u002Fred for healthy, degraded, or gapped ingestion — down to the hour, for the last 24 hours, a specific day, or the last 30 days. This answers a question every auditor eventually asks — \u003Cem>\"how do I know you were actually watching?\"\u003C\u002Fem> — with a picture instead of a promise.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"7-one-click-to-a-signed-board-ready-pdf\">7. One click to a signed, board-ready PDF\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#7-one-click-to-a-signed-board-ready-pdf\" class=\"hash-link\" aria-label=\"Direct link to 7. One click to a signed, board-ready PDF\" title=\"Direct link to 7. One click to a signed, board-ready PDF\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>None of this matters if it still takes a week to compile into something shareable. SIEM+ compiles the full posture score, framework mapping, evidence strings, and SLA metrics into a single PDF, on demand, in seconds. Every historical report is versioned and retrievable, so you can show an auditor not just today's posture, but the trend over time — with zero manual reassembly.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-this-matters-commercially-not-just-technically\">Why this matters commercially, not just technically\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F14\u002Feasy-to-understand-audit-reports-siem-plus#why-this-matters-commercially-not-just-technically\" class=\"hash-link\" aria-label=\"Direct link to Why this matters commercially, not just technically\" title=\"Direct link to Why this matters commercially, not just technically\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>An audit report that a human can actually read and trust isn't a nice-to-have UI feature — it's a compliance accelerant. Teams using SIEM+ walk into SOC 2 renewals, ISO 27001 surveillance audits, and board reviews with a document already built, already mapped, and already defensible. That turns audit season from a multi-week fire drill into a five-minute export.\u003C\u002Fp>\n\u003Cp>If your team is still stitching together screenshots, spreadsheets, and Slack threads every time an auditor asks \"show me,\" it's worth seeing what a report that's audit-ready by default looks like.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>See it on your own environment:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fsiem.plus\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">siem.plus\u003C\u002Fa> — or reach out to the Eventus team to talk through your next audit cycle.\u003C\u002Fp>","Why Auditors Don't Want Your Raw Logs: Building Audit Reports People Can Actually Read","Auditors don't need 10,000 raw alerts — they need a clear, evidence-backed answer. Here's how SIEM+ turns compliance monitoring into an audit report anyone can understand, in one click.","2026-08-14T00:00:00.000Z",{"name":15,"url":16},[32,23,76,85,33,35],"Audit",{"id":87,"content_html":88,"url":87,"title":89,"summary":90,"date_modified":91,"author":92,"tags":93},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F10\u002Fsekhmet-software-defined-gateway-qiita","\u003Cp>We’re pleased to share a new Eventus article on \u003Ca href=\"https:\u002F\u002Fqiita.com\u002Fjamesyip\u002Fitems\u002F6768b690f4d941b6b5d7\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Qiita\u003C\u002Fa>: \u003Cstrong>“The Full Story of SEKHMET, a Software-Defined Gateway That Eliminates Dedicated Hardware.”\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Published in Japanese, the article introduces our vision for making IoT deployments lighter and more accessible. Instead of requiring a dedicated gateway for every project, \u003Cstrong>SEKHMET\u003C\u002Fstrong> uses software on existing smartphones and tablets to connect sensors, process data at the edge, and link operational information with cloud services.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"read-and-share\">Read and share\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F10\u002Fsekhmet-software-defined-gateway-qiita#read-and-share\" class=\"hash-link\" aria-label=\"Direct link to Read and share\" title=\"Direct link to Read and share\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>If you work on healthcare, smart factories, digital twins, or other connected-device projects, we invite you to read and share the article with your engineering and product teams:\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fqiita.com\u002Fjamesyip\u002Fitems\u002F6768b690f4d941b6b5d7\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Read the full SEKHMET article on Qiita\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>To learn more about \u003Cstrong>SEKHMET\u003C\u002Fstrong>, \u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">contact Eventus\u003C\u002Fa>.\u003C\u002Fp>","Eventus Publishes a New SEKHMET Article on Qiita","Eventus shares a new Qiita article about SEKHMET, its software-defined gateway approach to simpler, more accessible IoT deployments.","2026-08-10T00:00:00.000Z",{"name":15,"url":16},[18,55,56,94,95,96],"Edge AI","Digital Twin","Software-Defined Gateway",{"id":98,"content_html":99,"url":98,"title":100,"summary":101,"date_modified":102,"author":103,"tags":104},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus","\u003Cp>In the cybersecurity industry, we have a terrible habit of equating “volume” with “risk.” If a traditional SIEM dashboard shows 10,000 alerts, the status indicator turns red, the posture score plummets to zero, and executives panic.\u003C\u002Fp>\n\u003Cp>But as any Tier-1 SOC analyst knows, a simple automated port scan against a public-facing IP can generate 5,000 raw firewall drops in three minutes. That isn’t 5,000 separate critical threats; it is a single, low-level event.\u003C\u002Fp>\n\u003Cp>When we built \u003Cstrong>SIEM+\u003C\u002Fstrong> (\u003Ca href=\"https:\u002F\u002Fsiem.plus\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">siem.plus\u003C\u002Fa>), we knew that if we just fed raw alert counts into a UI, we would be recreating the exact same “alert fatigue” we set out to destroy. We needed a way to translate noisy data lakes into a boardroom-ready metric that reflects actual risk.\u003C\u002Fp>\n\u003Cp>Here is a deep dive into how we engineered the SIEM+ Dynamic Posture Score, our penalty decay algorithm, and how we force LLMs to map threats to compliance frameworks without hallucinating.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"SIEM+ Dynamic Posture Score visualizing grouped cases and actionable risk\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fdynamic-posture-score-siem-plus-a873b77a6f854b5fc9bbea986fb6f56f.webp\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"-step-1-case-grouping-de-duplication-of-intent\">🧠 Step 1: Case Grouping (De-duplication of Intent)\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus#-step-1-case-grouping-de-duplication-of-intent\" class=\"hash-link\" aria-label=\"Direct link to 🧠 Step 1: Case Grouping (De-duplication of Intent)\" title=\"Direct link to 🧠 Step 1: Case Grouping (De-duplication of Intent)\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The first step to generating a real security score is stopping the AI from treating every log as an isolated incident.\u003C\u002Fp>\n\u003Cp>Because we use an event-driven aggregation layer (pulling lightweight summaries from the underlying data lake), our AI engine receives batches of activity. We engineered our LLM pipeline to perform \u003Cstrong>Intent De-duplication\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>If the AI engine sees 50 failed login attempts followed by an MFA bypass for the same user, it does not output 51 alerts. It generates a single JSON object: a \u003Cstrong>Case\u003C\u002Fstrong>. This Case contains the root cause, the timeline, and the severity. This dramatically reduces the denominator for our scoring engine.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"️-step-2-the-penalty-decay-algorithm\">⚖️ Step 2: The Penalty Decay Algorithm\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus#%EF%B8%8F-step-2-the-penalty-decay-algorithm\" class=\"hash-link\" aria-label=\"Direct link to ⚖️ Step 2: The Penalty Decay Algorithm\" title=\"Direct link to ⚖️ Step 2: The Penalty Decay Algorithm\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Once we have consolidated the noise into distinct Cases, we need to calculate the actual Posture Score (0–100) for specific security categories, such as Identity &amp; Access Management and Network Boundary.\u003C\u002Fp>\n\u003Cp>Instead of a linear deduction (which drops the score to zero too quickly), we implemented a customized penalty decay algorithm based on the severity of the grouped \u003Cem>Cases\u003C\u002Fem>, not the raw alerts.\u003C\u002Fp>\n\u003Cp>Our scoring engine evaluates two main factors:\u003C\u002Fp>\n\u003Col>\n\u003Cli class=\"\">\u003Cstrong>Severity Weighting:\u003C\u002Fstrong> Each case is assigned a base penalty score. Critical events carry a heavy penalty, while Low events carry a minimal one.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Logarithmic Decay:\u003C\u002Fstrong> If a flood of similar cases occurs simultaneously, the system applies a decay function. Successive events of the same type do not subtract the full penalty amount over and over.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>This logic ensures that a single critical MFA bypass actually hurts the posture score far more than 1,000 low-level firewall pings, providing a much more accurate reflection of true infrastructure risk.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"️-step-3-dynamic-framework-mapping-nist--cis\">🛡️ Step 3: Dynamic Framework Mapping (NIST &amp; CIS)\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus#%EF%B8%8F-step-3-dynamic-framework-mapping-nist--cis\" class=\"hash-link\" aria-label=\"Direct link to 🛡️ Step 3: Dynamic Framework Mapping (NIST &amp; CIS)\" title=\"Direct link to 🛡️ Step 3: Dynamic Framework Mapping (NIST &amp; CIS)\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Static compliance dashboards are notoriously brittle. They rely on hardcoded rules, such as “If Rule ID 404 fires, flag NIST PR.AC-1.” The moment your infrastructure changes, the mapping breaks.\u003C\u002Fp>\n\u003Cp>We configured the SIEM+ AI engine to dynamically map Cases to \u003Cstrong>NIST CSF v2.0\u003C\u002Fstrong> and \u003Cstrong>CIS Controls v8\u003C\u002Fstrong>. To do this without the LLM hallucinating fake compliance codes, we use strict system prompts infused with RAG (Retrieval-Augmented Generation) context from the official framework documentation.\u003C\u002Fp>\n\u003Cp>The AI evaluates the nature of the attack—such as an unauthorized email forwarding rule—and maps it to the exact control family being violated.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"️-step-4-taming-the-ai-with-strict-data-contracts\">🏗️ Step 4: Taming the AI with Strict Data Contracts\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus#%EF%B8%8F-step-4-taming-the-ai-with-strict-data-contracts\" class=\"hash-link\" aria-label=\"Direct link to 🏗️ Step 4: Taming the AI with Strict Data Contracts\" title=\"Direct link to 🏗️ Step 4: Taming the AI with Strict Data Contracts\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>One of the hardest parts of building an AI-driven platform is taming the unpredictability of LLMs. You can’t just feed raw, conversational text into a structured enterprise dashboard and expect it to render correctly.\u003C\u002Fp>\n\u003Cp>Even though our \u003Cstrong>end-users never interact with raw code or JSON\u003C\u002Fstrong>—they simply see a sleek, executive-ready interface—our backend relies heavily on deterministic data contracts. We force the LLM to output strictly formatted JSON payloads, constraining it to our exact schema and penalizing it heavily if it hallucinates extra fields.\u003C\u002Fp>\n\u003Cp>To give you an idea of how the AI engine talks to the UI, here is a peek behind the curtain at the structured intelligence generated behind the scenes:\u003C\u002Fp>\n\u003Cdiv class=\"language-json codeBlockContainer_Ckt0 theme-code-block\" style=\"--prism-color:#393A34;--prism-background-color:#f6f8fa\">\u003Cdiv class=\"codeBlockContent_QJqH\">\u003Cpre tabindex=\"0\" class=\"prism-code language-json codeBlock_bY9V thin-scrollbar\" style=\"color:#393A34;background-color:#f6f8fa\">\u003Ccode class=\"codeBlockLines_e6Vv\">\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">{\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"ui_category\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token string\" style=\"color:#e3116c\">\"Cloud &amp; Infrastructure Security\"\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"has_log_coverage\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token boolean\" style=\"color:#36acaa\">true\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"score\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token number\" style=\"color:#36acaa\">72.5\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"cases\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">{\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">    \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"critical\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token number\" style=\"color:#36acaa\">0\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">    \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"high\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token number\" style=\"color:#36acaa\">2\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">    \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"medium\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token number\" style=\"color:#36acaa\">4\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">}\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"frameworks\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">{\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">    \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"nist_v2\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token string\" style=\"color:#e3116c\">\"PR.DS\"\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">    \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"cis_v8\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token string\" style=\"color:#e3116c\">\"CIS_CONTROL_5\"\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">}\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">,\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">  \u003C\u002Fspan>\u003Cspan class=\"token property\" style=\"color:#36acaa\">\"evidence_string\"\u003C\u002Fspan>\u003Cspan class=\"token operator\" style=\"color:#393A34\">:\u003C\u002Fspan>\u003Cspan class=\"token plain\"> \u003C\u002Fspan>\u003Cspan class=\"token string\" style=\"color:#e3116c\">\"Score degraded due to 2 High-severity cases: Public S3 bucket misconfiguration and unauthorized IAM role assumption.\"\u003C\u002Fspan>\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003Cdiv class=\"token-line\" style=\"color:#393A34\">\u003Cspan class=\"token plain\">\u003C\u002Fspan>\u003Cspan class=\"token punctuation\" style=\"color:#393A34\">}\u003C\u002Fspan>\u003Cbr>\u003C\u002Fdiv>\u003C\u002Fcode>\u003C\u002Fpre>\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-result-actionable-security\">The Result: Actionable Security\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F09\u002Fwhy-static-dashboards-are-dead-engineering-dynamic-posture-score-siem-plus#the-result-actionable-security\" class=\"hash-link\" aria-label=\"Direct link to The Result: Actionable Security\" title=\"Direct link to The Result: Actionable Security\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>By combining Case Grouping, the Penalty Decay algorithm, and dynamic JSON schema generation, SIEM+ bridges the gap between the SOC floor and the executive boardroom.\u003C\u002Fp>\n\u003Cp>Security engineers get the exact context and remediation steps they need, and CISOs get a mathematical, defensible Posture Score that accurately reflects their infrastructure’s health.\u003C\u002Fp>","Why Static Dashboards Are Dead: Engineering the Dynamic Posture Score in SIEM+","How Eventus engineered the SIEM+ Dynamic Posture Score to turn noisy alert streams into a defensible, executive-ready view of security risk.","2026-08-09T00:00:00.000Z",{"name":15,"url":16},[32,23,33,35,76,34],{"id":106,"content_html":107,"url":106,"title":108,"summary":109,"date_modified":110,"author":111,"tags":112},"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F08\u002Feventus-joins-qiita","\u003Cp>Eventus is pleased to announce that we have joined \u003Cstrong>Qiita\u003C\u002Fstrong>, Japan's technology knowledge-sharing platform, to make our practical experience more accessible to engineers, IT teams, and technology leaders.\u003C\u002Fp>\n\u003Cp>Qiita gives us a place to share what we learn while helping organizations improve security operations, use cloud technologies effectively, and turn operational data into better decisions.\u003C\u002Fp>\n\u003Cp>Our Qiita launch follows Eventus's recent work on \u003Ca class=\"\" href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring\">SIEM+ managed security monitoring\u003C\u002Fa> and practical security operations.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"our-first-qiita-article-siem\">Our first Qiita article: SIEM+\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F08\u002Feventus-joins-qiita#our-first-qiita-article-siem\" class=\"hash-link\" aria-label=\"Direct link to Our first Qiita article: SIEM+\" title=\"Direct link to Our first Qiita article: SIEM+\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Our first article introduces \u003Cstrong>SIEM+\u003C\u002Fstrong>, Eventus's managed security service built on Devo's cloud-native SIEM platform:\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fqiita.com\u002Fjamesyip\u002Fitems\u002F28113376480c04bb8e93\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Read the first Eventus SIEM+ article on Qiita\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>SIEM+ combines scalable security log analytics with Eventus expertise in monitoring, alert triage, noise reduction, and incident response workflows. The goal is to help lean IT and security teams focus on the events that matter without taking on the cost and complexity of building a large SOC from scratch.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-we-will-share\">What we will share\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F08\u002Feventus-joins-qiita#what-we-will-share\" class=\"hash-link\" aria-label=\"Direct link to What we will share\" title=\"Direct link to What we will share\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Future Qiita posts will cover topics such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Security operations:\u003C\u002Fstrong> Practical approaches to SIEM, alert fatigue, detection, and response.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Cloud and IT operations:\u003C\u002Fstrong> Lessons from designing reliable, maintainable technology services.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>IoT and data platforms:\u003C\u002Fstrong> Ways to collect, manage, and use data from connected devices through SEKHMET.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Digital transformation:\u003C\u002Fstrong> Patterns that help organizations move from technology investment to measurable business outcomes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>We will aim to keep each article useful and concrete, with ideas that readers can apply to their own environments.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"follow-eventus-on-qiita\">Follow Eventus on Qiita\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F08\u002F08\u002Feventus-joins-qiita#follow-eventus-on-qiita\" class=\"hash-link\" aria-label=\"Direct link to Follow Eventus on Qiita\" title=\"Direct link to Follow Eventus on Qiita\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>We invite you to read the first SIEM+ article and follow along as we publish more technical content on Qiita. If you are exploring managed security, cloud-native platforms, IoT, or practical digital transformation, we would be glad to share what we have learned.\u003C\u002Fp>\n\u003Cp>To discuss how Eventus can support your organization, \u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">contact Eventus\u003C\u002Fa>.\u003C\u002Fp>","Eventus Joins Qiita: Sharing Practical Security and Technology Insights","Eventus joins Qiita to share practical cybersecurity, SIEM+, cloud operations, IoT, and digital transformation insights with Japan's technology community.","2026-08-08T00:00:00.000Z",{"name":15,"url":16},[18,113,22,114,23,115],"Qiita","Devo","Technology",{"id":117,"content_html":118,"url":117,"title":119,"summary":120,"date_modified":121,"author":122,"tags":123},"https:\u002F\u002Feventus.blog\u002F2026\u002F07\u002F27\u002Feventus-at-tech-beat-shizuoka-2026","\u003Cp>Eventus K.K. (イベントス株式会社) was pleased to attend \u003Cstrong>TECH BEAT Shizuoka 2026\u003C\u002Fstrong>, a platform that brings together businesses in Shizuoka and startups to create new value through collaboration and open innovation.\u003C\u002Fp>\n\u003Cp>At the event, we showcased two solutions that help organizations make better use of the data already flowing through their operations: \u003Cstrong>SIEM+\u003C\u002Fstrong> for security visibility and response, and \u003Cstrong>SEKHMET\u003C\u002Fstrong> for IoT data collection and application development.\u003C\u002Fp>\n\u003Cp>Learn more about \u003Ca class=\"\" href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring\">SIEM+ managed security monitoring\u003C\u002Fa> and Eventus's approach to reducing alert fatigue.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"Eventus at TECH BEAT Shizuoka 2026\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Ftech-beat-shizuoka-2026-eventus-837059f1e125602ea2296fc7f1ba2d35.jpg\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"siem-turn-security-signals-into-action\">SIEM+: Turn security signals into action\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F07\u002F27\u002Feventus-at-tech-beat-shizuoka-2026#siem-turn-security-signals-into-action\" class=\"hash-link\" aria-label=\"Direct link to SIEM+: Turn security signals into action\" title=\"Direct link to SIEM+: Turn security signals into action\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>SIEM+ combines Devo's cloud-native SIEM with Eventus managed security services. It brings logs and security signals together, helps reduce repetitive alert noise, and gives internal teams clearer next steps when an incident needs attention.\u003C\u002Fp>\n\u003Cp>For companies, the benefits include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Faster visibility:\u003C\u002Fstrong> Understand activity across cloud, on-premises, identity, endpoint, and business systems from a more unified view.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Less alert fatigue:\u003C\u002Fstrong> Filter, group, and prioritize events so teams can focus on higher-risk activity.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Lower infrastructure burden:\u003C\u002Fstrong> Use a cloud-native foundation without building and maintaining a large SIEM platform in-house.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Actionable response:\u003C\u002Fstrong> Connect prioritized findings to operational workflows and remediation guidance.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This is especially valuable for organizations with lean IT or security teams that need stronger coverage without adding a full internal SOC overnight.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"sekhmet-make-iot-data-useful\">SEKHMET: Make IoT data useful\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F07\u002F27\u002Feventus-at-tech-beat-shizuoka-2026#sekhmet-make-iot-data-useful\" class=\"hash-link\" aria-label=\"Direct link to SEKHMET: Make IoT data useful\" title=\"Direct link to SEKHMET: Make IoT data useful\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>SEKHMET is Eventus's IoT data platform for collecting, managing, and using data from connected devices. It helps teams move from isolated sensor readings to applications and dashboards that support real operational decisions.\u003C\u002Fp>\n\u003Cp>For manufacturers, facilities, logistics operators, and other organizations, SEKHMET can help deliver:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>A clearer view of operations:\u003C\u002Fstrong> Bring data from devices and sites into a more consistent platform.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Earlier issue detection:\u003C\u002Fstrong> Use live data to identify abnormal conditions before they become expensive disruptions.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>More efficient development:\u003C\u002Fstrong> Build and extend IoT applications without starting the data layer from scratch for every project.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Scalable innovation:\u003C\u002Fstrong> Create a foundation for monitoring, predictive maintenance, energy management, and other use cases.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"from-data-to-collaboration\">From data to collaboration\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F07\u002F27\u002Feventus-at-tech-beat-shizuoka-2026#from-data-to-collaboration\" class=\"hash-link\" aria-label=\"Direct link to From data to collaboration\" title=\"Direct link to From data to collaboration\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>TECH BEAT Shizuoka reflects the value of connecting established businesses with new technology. Security data and IoT data may serve different teams, but both require the same discipline: reliable collection, useful context, and a path from insight to action.\u003C\u002Fp>\n\u003Cp>Eventus helps organizations design that path. If you would like to learn more about \u003Cstrong>SIEM+\u003C\u002Fstrong>, \u003Cstrong>SEKHMET\u003C\u002Fstrong>, or how these solutions could support your business, \u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">contact Eventus\u003C\u002Fa> to discuss your requirements.\u003C\u002Fp>\n\u003Cp>Learn more about \u003Ca href=\"https:\u002F\u002Ftechbeat.jp\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">TECH BEAT Shizuoka\u003C\u002Fa>.\u003C\u002Fp>","Eventus at TECH BEAT Shizuoka 2026: Connecting Security and IoT Innovation","At TECH BEAT Shizuoka 2026, Eventus K.K. showcased SIEM+ managed security monitoring and SEKHMET IoT data platforms for practical business outcomes.","2026-07-27T00:00:00.000Z",{"name":15,"url":16},[18,124,22,55,23,56],"TECH BEAT Shizuoka",{"id":126,"content_html":127,"url":126,"title":128,"summary":129,"date_modified":130,"author":131,"tags":132},"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring","\u003Cp>For IT Directors, CISOs, and Security Operations Managers, the challenge is no longer whether the organization has enough security tools. The real challenge is whether a lean team can turn thousands of daily signals into the few decisions that truly matter.\u003C\u002Fp>\n\u003Cp>Modern environments generate alerts from firewalls, endpoints, identity platforms, Microsoft 365, cloud workloads, SaaS applications, and network infrastructure. Many of those alerts are low-fidelity. Some are duplicates. Some are known false positives. A small number may indicate real business risk.\u003C\u002Fp>\n\u003Cp>This is where \u003Cstrong>SIEM Plus\u003C\u002Fstrong> from Eventus comes in. SIEM Plus combines \u003Cstrong>Devo's cloud-native SIEM\u003C\u002Fstrong> with Eventus managed services, AI-enhanced noise reduction, and actionable ITSM workflows to help teams conquer alert fatigue without building a large internal SOC from scratch.\u003C\u002Fp>\n\u003Cp>See SIEM+ in context at \u003Ca class=\"\" href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F07\u002F27\u002Feventus-at-tech-beat-shizuoka-2026\">TECH BEAT Shizuoka 2026\u003C\u002Fa>, where Eventus showcased the solution alongside its SEKHMET IoT data platform.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"SIEM Plus cloud-native SIEM and managed security operations\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fsiem-plus-cloud-native-managed-services-d3db6da0f7691a2030b7324c42fd557c.jpg\" width=\"1672\" height=\"941\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-operational-bottleneck-alert-fatigue\">The Operational Bottleneck: Alert Fatigue\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#the-operational-bottleneck-alert-fatigue\" class=\"hash-link\" aria-label=\"Direct link to The Operational Bottleneck: Alert Fatigue\" title=\"Direct link to The Operational Bottleneck: Alert Fatigue\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Internal IT and security teams are drowning in a sea of low-fidelity alerts. Every tool has its own dashboard, severity model, and notification logic. Analysts are expected to review them all, decide what matters, and respond quickly, often while also managing infrastructure, users, compliance tasks, and business projects.\u003C\u002Fp>\n\u003Cp>The consequence is predictable: when analysts are forced to chase every false positive, true high-priority threats can slip through the cracks.\u003C\u002Fp>\n\u003Cp>Alert fatigue creates several operational risks:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Delayed incident response:\u003C\u002Fstrong> Critical alerts wait behind routine noise.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Inefficient operations:\u003C\u002Fstrong> Skilled staff spend too much time validating events that do not require action.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Team burnout:\u003C\u002Fstrong> Continuous alert pressure drains focus and increases turnover risk.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Reduced security ROI:\u003C\u002Fstrong> Existing tools generate telemetry, but the organization cannot consistently operationalize it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The answer is not simply to add another dashboard. Teams need a better foundation for collecting security data and a managed operating model that turns raw alerts into prioritized work.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-foundation-lowering-costs-with-a-pure-cloud-solution\">The Foundation: Lowering Costs with a Pure Cloud Solution\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#the-foundation-lowering-costs-with-a-pure-cloud-solution\" class=\"hash-link\" aria-label=\"Direct link to The Foundation: Lowering Costs with a Pure Cloud Solution\" title=\"Direct link to The Foundation: Lowering Costs with a Pure Cloud Solution\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Traditional on-premise SIEM solutions often require heavy infrastructure investment. Organizations must plan storage, maintain servers, scale ingestion capacity, tune performance, and keep the platform available. As log volume grows, cost and complexity grow with it.\u003C\u002Fp>\n\u003Cp>SIEM Plus takes a different path by leveraging \u003Cstrong>Devo\u003C\u002Fstrong>, a pure cloud platform built for high-volume security analytics.\u003C\u002Fp>\n\u003Cp>With Devo as the foundation, organizations can reduce the infrastructure burden that comes with legacy SIEM architectures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>No hardware overhead:\u003C\u002Fstrong> Avoid the cost and operational work of managing SIEM infrastructure.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Lower Total Cost of Ownership:\u003C\u002Fstrong> Reduce maintenance, scaling, and platform administration demands.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Scalable hot data storage:\u003C\u002Fstrong> Keep security data searchable and ready for investigation without traditional storage bottlenecks.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Fast query performance:\u003C\u002Fstrong> Give analysts the ability to search and correlate large volumes of data quickly.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For lean teams, this matters. A cloud-native SIEM helps shift resources away from platform maintenance and back toward security outcomes.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-missing-link-why-just-buying-a-tool-is-not-enough\">The Missing Link: Why Just Buying a Tool Is Not Enough\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#the-missing-link-why-just-buying-a-tool-is-not-enough\" class=\"hash-link\" aria-label=\"Direct link to The Missing Link: Why Just Buying a Tool Is Not Enough\" title=\"Direct link to The Missing Link: Why Just Buying a Tool Is Not Enough\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Buying a powerful cloud SIEM is only half the battle. Without dedicated experts to tune rules, monitor dashboards, investigate alerts, and continuously improve detection logic, even a strong platform can become underused.\u003C\u002Fp>\n\u003Cp>This is the \"tool-only\" trap. The organization buys a license, connects data sources, and expects the value to appear automatically. In reality, value comes from operationalization.\u003C\u002Fp>\n\u003Cp>SIEM Plus adds that missing operating layer. By combining Devo with Eventus managed services, organizations gain more than software. They gain a practical, AI-enhanced security operations capability without having to hire a large team of internal analysts.\u003C\u002Fp>\n\u003Cp>Eventus helps with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">Tuning alert logic and reducing recurring false positives\u003C\u002Fli>\n\u003Cli class=\"\">Monitoring security signals across connected data sources\u003C\u002Fli>\n\u003Cli class=\"\">Investigating suspicious activity with business context\u003C\u002Fli>\n\u003Cli class=\"\">Prioritizing incidents based on risk and urgency\u003C\u002Fli>\n\u003Cli class=\"\">Providing clear remediation guidance to internal IT teams\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The goal is simple: turn Devo's visibility into daily security action.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"ai-enhanced-noise-reduction-tier-0-filtering\">AI-Enhanced Noise Reduction: Tier 0 Filtering\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#ai-enhanced-noise-reduction-tier-0-filtering\" class=\"hash-link\" aria-label=\"Direct link to AI-Enhanced Noise Reduction: Tier 0 Filtering\" title=\"Direct link to AI-Enhanced Noise Reduction: Tier 0 Filtering\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>A major source of alert fatigue is the raw volume of background noise. SIEM Plus uses AI-enhanced managed services to help reduce that burden before it reaches human analysts.\u003C\u002Fp>\n\u003Cp>At the Tier 0 filtering layer, advanced machine learning and AI techniques can continuously pre-screen raw events and alert streams. The system helps suppress, deduplicate, and dismiss low-confidence background noise so analysts can focus on verified anomalies and meaningful patterns.\u003C\u002Fp>\n\u003Cp>In suitable environments, this approach can reduce a substantial portion of repetitive, low-value alerts, helping teams reserve human attention for the events most likely to matter.\u003C\u002Fp>\n\u003Cp>AI-enhanced filtering supports:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Autonomous pre-screening:\u003C\u002Fstrong> Raw events are assessed before they become analyst workload.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Deduplication:\u003C\u002Fstrong> Repeated alerts are grouped so teams do not investigate the same issue again and again.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Noise suppression:\u003C\u002Fstrong> Known low-confidence events are reduced where appropriate.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Analyst focus:\u003C\u002Fstrong> Human review is directed toward verified anomalies and higher-risk activity.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>AI does not replace security judgment. It helps protect that judgment from being wasted on noise.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"actionable-itsm-integration\">Actionable ITSM Integration\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#actionable-itsm-integration\" class=\"hash-link\" aria-label=\"Direct link to Actionable ITSM Integration\" title=\"Direct link to Actionable ITSM Integration\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>High-fidelity critical alerts should not disappear into a generic shared inbox. They should become structured work items inside the systems your IT and security teams already use.\u003C\u002Fp>\n\u003Cp>SIEM Plus can route prioritized alerts into ITSM tools such as \u003Cstrong>Jira\u003C\u002Fstrong>, helping teams move from detection to action with less friction.\u003C\u002Fp>\n\u003Cp>Each escalated ticket can include the operational context needed for fast response:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Blast-radius assessment:\u003C\u002Fstrong> Which users, systems, assets, or services may be affected.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Alert summary:\u003C\u002Fstrong> What happened, when it happened, and why it matters.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Evidence and related events:\u003C\u002Fstrong> Key logs, correlated signals, and supporting details.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Step-by-step remediation guidance:\u003C\u002Fstrong> Clear next actions for containment, investigation, and recovery.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Priority and ownership:\u003C\u002Fstrong> Routing information that helps the right team respond quickly.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This eliminates guesswork. Internal IT teams receive a prioritized ticket with context and recommended actions, not a vague alert that requires starting the investigation from zero.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"siem-plus-a-complete-managed-approach\">SIEM Plus: A Complete Managed Approach\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#siem-plus-a-complete-managed-approach\" class=\"hash-link\" aria-label=\"Direct link to SIEM Plus: A Complete Managed Approach\" title=\"Direct link to SIEM Plus: A Complete Managed Approach\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>SIEM Plus is built for organizations that need stronger security operations without the cost and complexity of building everything in-house.\u003C\u002Fp>\n\u003Cp>It brings together:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Devo cloud-native SIEM\u003C\u002Fstrong> for scalable log collection, hot data storage, and fast search\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Eventus managed services\u003C\u002Fstrong> for monitoring, triage, and prioritization\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>AI-enhanced Tier 0 filtering\u003C\u002Fstrong> to reduce low-confidence noise\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>ITSM integration\u003C\u002Fstrong> to route verified incidents into operational workflows\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Actionable remediation guidance\u003C\u002Fstrong> so internal teams can respond decisively\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For lean teams, this combination is the difference between owning another tool and operating a security function that can act.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"move-beyond-alert-fatigue\">Move Beyond Alert Fatigue\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring#move-beyond-alert-fatigue\" class=\"hash-link\" aria-label=\"Direct link to Move Beyond Alert Fatigue\" title=\"Direct link to Move Beyond Alert Fatigue\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Alert fatigue is not solved by adding more alerts. It is solved by combining the right platform with the right operating model.\u003C\u002Fp>\n\u003Cp>With SIEM Plus, Eventus helps organizations centralize logs and alerts through Devo, reduce noise with AI-enhanced filtering, prioritize what matters, and route actionable incidents into existing ITSM workflows.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Contact Eventus\u003C\u002Fa> to learn how SIEM Plus can help your team lower SIEM operating costs, reduce alert fatigue, and respond faster to real threats.\u003C\u002Fp>","SIEM+ Managed SIEM: Cloud-Native Devo Security Monitoring | Eventus","Eventus SIEM+ combines Devo cloud-native SIEM, managed monitoring, alert filtering, and ITSM workflows to help lean security teams reduce alert fatigue.","2026-06-05T00:00:00.000Z",{"name":15,"url":16},[32,114,133,134,23,33,34],"Managed SIEM","Managed Services",{"id":136,"content_html":137,"url":136,"title":138,"summary":139,"date_modified":140,"author":141,"tags":142},"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo","\u003Cp>Hong Kong's cybersecurity landscape is undergoing a major shift with the introduction of the \u003Cstrong>Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653)\u003C\u002Fstrong>. Under this regulation, Critical Infrastructure Operators (CIOs) must meet strict statutory obligations regarding organizational governance, preventive security measures, and prompt incident response.\u003C\u002Fp>\n\u003Cp>At Eventus, we partner with Devo to deliver a unified SIEM and security data platform that helps organizations maintain continuous visibility, streamline investigations, and achieve full compliance with Cap. 653.\u003C\u002Fp>\n\u003Cp>This compliance use case builds on \u003Ca class=\"\" href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services\">Eventus Managed SIEM and Managed SOC services\u003C\u002Fa> for continuous monitoring and response support.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"Eventus &amp;amp; Devo HK Cap. 653 Compliance\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Feventus-devo-cap653-3307a61c5281f7cd5ed1648f6a4322ba.png\" title=\"Eventus &amp;amp; Devo HK Cap. 653 Compliance\" width=\"1024\" height=\"1024\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"understanding-cap-653-obligations\">Understanding Cap. 653 Obligations\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo#understanding-cap-653-obligations\" class=\"hash-link\" aria-label=\"Direct link to Understanding Cap. 653 Obligations\" title=\"Direct link to Understanding Cap. 653 Obligations\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The Cap. 653 ordinance targets critical computer systems (CCSs) within sectors vital to Hong Kong's economy and society—such as energy, transport, finance, healthcare, and telecommunications. CIOs have three major categories of obligations:\u003C\u002Fp>\n\u003Col>\n\u003Cli class=\"\">\u003Cstrong>Organizational Obligations:\u003C\u002Fstrong> Establishing a dedicated security unit and designated contact persons.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Preventive Obligations:\u003C\u002Fstrong> Implementing security management policies, performing regular security audits, conducting risk assessments, and executing system security drills.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Incident Reporting &amp; Response:\u003C\u002Fstrong> Promptly reporting serious computer system security incidents (such as system failures or data breaches) within strict timeframes—often as short as 2 hours after detection.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-eventus-siem-and-devo-deliver-compliance\">How Eventus SIEM+ and Devo Deliver Compliance\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo#how-eventus-siem-and-devo-deliver-compliance\" class=\"hash-link\" aria-label=\"Direct link to How Eventus SIEM+ and Devo Deliver Compliance\" title=\"Direct link to How Eventus SIEM+ and Devo Deliver Compliance\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Meeting these statutory requirements without adding operational overhead requires a platform built for massive scale, advanced threat correlation, and automated response.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-continuous-visibility-and-centralized-logging\">1. Continuous Visibility and Centralized Logging\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo#1-continuous-visibility-and-centralized-logging\" class=\"hash-link\" aria-label=\"Direct link to 1. Continuous Visibility and Centralized Logging\" title=\"Direct link to 1. Continuous Visibility and Centralized Logging\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Cap. 653 requires operators to maintain comprehensive log records and monitor systems to identify anomalies. Traditional logging tools often drop packets under high volumes or slow down when querying old data.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Devo's Cloud-Native Platform:\u003C\u002Fstrong> Ingests petabytes of security telemetry across your entire infrastructure—on-premise, cloud, and edge. It provides a secure, immutable log repository.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Continuous Monitoring:\u003C\u002Fstrong> Eventus SIEM+ processes these logs without delay, establishing behavioral baselines and alerting on anomalous patterns.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Sub-Second Search:\u003C\u002Fstrong> Analysts can query months of historical security logs in milliseconds, ensuring that investigative efforts are never delayed by slow databases.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-rapid-response-and-soar-integration\">2. Rapid Response and SOAR Integration\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo#2-rapid-response-and-soar-integration\" class=\"hash-link\" aria-label=\"Direct link to 2. Rapid Response and SOAR Integration\" title=\"Direct link to 2. Rapid Response and SOAR Integration\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>When an incident is detected, the clock starts ticking for Cap. 653's 2-hour reporting window. Traditional manual triage is too slow.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Automated Correlation:\u003C\u002Fstrong> Eventus SIEM+ uses advanced rules to correlate alerts across network devices, endpoints, and identity providers, isolating true threats from false alarms.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Instant Containment (SOAR):\u003C\u002Fstrong> Predefined playbooks automatically isolate compromised hosts, revoke compromised credentials, or block malicious IPs.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Pre-Packaged Evidence:\u003C\u002Fstrong> The platform automatically compiles the security event timeline, providing the documentation needed to report incidents to HK authorities well within the reporting window.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-simplified-security-audits\">3. Simplified Security Audits\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo#3-simplified-security-audits\" class=\"hash-link\" aria-label=\"Direct link to 3. Simplified Security Audits\" title=\"Direct link to 3. Simplified Security Audits\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Under Cap. 653, regular independent audits are mandatory. Preparing for these audits can take weeks of manual log collection.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Compliance Dashboards:\u003C\u002Fstrong> Eventus SIEM+ features pre-built dashboards designed to map directly to Cap. 653 controls.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Long-Term Retention:\u003C\u002Fstrong> Devo's efficient storage architecture lets you retain hot, searchable log data for years, keeping you audit-ready at a lower total cost of ownership (TCO).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-eventus-advantage-expert-remediation-guidance\">The Eventus Advantage: Expert Remediation Guidance\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F01\u002Fhk-gov-compliance-siem-devo#the-eventus-advantage-expert-remediation-guidance\" class=\"hash-link\" aria-label=\"Direct link to The Eventus Advantage: Expert Remediation Guidance\" title=\"Direct link to The Eventus Advantage: Expert Remediation Guidance\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Eventus doesn't just alert you to threats. Our dedicated security team works alongside yours, providing step-by-step remediation advice to help you fix vulnerabilities and strengthen your security posture over time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Contact Eventus today\u003C\u002Fa> to learn how we can help secure your critical infrastructure and simplify your Cap. 653 compliance journey.\u003C\u002Fstrong>\u003C\u002Fp>","Hong Kong Cap. 653 Compliance for Critical Infrastructure | Eventus SIEM+","Learn how Hong Kong critical infrastructure operators can use Eventus SIEM+ and Devo for visibility, incident response, and Cap. 653 compliance planning.","2026-06-01T00:00:00.000Z",{"name":15,"url":16},[76,143,114,144,23,18],"Cap653","SIEM",{"id":146,"content_html":147,"url":146,"title":148,"summary":149,"date_modified":150,"author":151,"tags":152},"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services","\u003Cp>In today’s hyper-connected business landscape, organizations deploy an array of security tools to protect their digital assets. From endpoint detection and response (EDR) and cloud firewalls to email gateways and identity providers, every system is constantly generating telemetry.\u003C\u002Fp>\n\u003Cp>However, this abundance of security tooling has created a new, critical vulnerability: \u003Cstrong>alert fatigue\u003C\u002Fstrong>. The sheer volume of alerts generated across multiple siloed platforms is overwhelming. For many organizations, the harsh reality is that \u003Cstrong>no one has the time or resources to check them all\u003C\u002Fstrong>. Crucial indicators of compromise get buried in a mountain of noise, leaving the door wide open for cybercriminals.\u003C\u002Fp>\n\u003Cp>To solve this exact challenge, Eventus is proud to announce the launch of our new \u003Cstrong>Managed SIEM (powered by Devo)\u003C\u002Fstrong> and \u003Cstrong>Managed SOC\u003C\u002Fstrong> services. We are bridging the security resource gap, turning chaotic alerts into clear, actionable, and 24\u002F7 threat detection and response.\u003C\u002Fp>\n\u003Cp>For a deeper look at the platform and operating model, read \u003Ca class=\"\" href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F06\u002F05\u002Fintroducing-siem-plus-managed-log-alert-monitoring\">how cloud-native SIEM and managed services reduce alert fatigue\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"Managed SIEM powered by Devo and Managed SOC services\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fintroducing-managed-siem-devo-managed-soc-services-f121a5212c24b0d719e87087cc0790d8.png\" width=\"1024\" height=\"1024\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-reality-siloed-tools-and-the-cybersecurity-talent-shortage\">The Reality: Siloed Tools and the Cybersecurity Talent Shortage\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services#the-reality-siloed-tools-and-the-cybersecurity-talent-shortage\" class=\"hash-link\" aria-label=\"Direct link to The Reality: Siloed Tools and the Cybersecurity Talent Shortage\" title=\"Direct link to The Reality: Siloed Tools and the Cybersecurity Talent Shortage\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Modern businesses are facing a double-edged sword:\u003C\u002Fp>\n\u003Col>\n\u003Cli class=\"\">\u003Cstrong>Alert Fatigue:\u003C\u002Fstrong> A single security incident can trigger hundreds of disconnected alerts across different dashboards. IT teams spend hours sorting through false positives, leading to burnout and missed threats.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>The Resource Gap:\u003C\u002Fstrong> Building a 24\u002F7 Security Operations Center (SOC) in-house is cost-prohibitive for most organizations. Between the global cybersecurity talent shortage and the high salary demands of specialized analysts, maintaining round-the-clock coverage is nearly impossible for internal IT teams.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>When alerts are ignored because there is no one to watch them, your investments in cybersecurity tools are rendered ineffective. Security is only as good as the eyes watching the screens.\u003C\u002Fp>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introducing-managed-siem-powered-by-devo\">Introducing Managed SIEM (Powered by Devo)\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services#introducing-managed-siem-powered-by-devo\" class=\"hash-link\" aria-label=\"Direct link to Introducing Managed SIEM (Powered by Devo)\" title=\"Direct link to Introducing Managed SIEM (Powered by Devo)\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>At the core of our detection engine is \u003Cstrong>Devo\u003C\u002Fstrong>, a leader in cloud-native logging, analytics, and SIEM. Our Managed SIEM service centralizes security telemetry from all your platforms—endpoints, cloud infrastructure, networks, and applications—into a single, high-performance data lake.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-devo\">Why Devo?\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services#why-devo\" class=\"hash-link\" aria-label=\"Direct link to Why Devo?\" title=\"Direct link to Why Devo?\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Unparalleled Scale and Speed:\u003C\u002Fstrong> Devo ingests massive volumes of data in real time, delivering lightning-fast query speeds so threat hunters can search months of data in seconds.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Correlated Intelligence:\u003C\u002Fstrong> Instead of viewing alerts in isolation, Devo automatically correlates events from different sources to map out the entire lifecycle of an attack.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Elimination of Data Silos:\u003C\u002Fstrong> By aggregating logs from Microsoft 365, AWS\u002FAzure, firewalls, and endpoints into one platform, you get a single pane of glass for your entire security posture.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"247-vigilance-with-managed-soc\">24\u002F7 Vigilance with Managed SOC\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services#247-vigilance-with-managed-soc\" class=\"hash-link\" aria-label=\"Direct link to 24\u002F7 Vigilance with Managed SOC\" title=\"Direct link to 24\u002F7 Vigilance with Managed SOC\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>A powerful SIEM is only half the equation; you need the expertise to act on the insights. That is where Eventus’ \u003Cstrong>Managed SOC (Security Operations Center)\u003C\u002Fstrong> comes in.\u003C\u002Fp>\n\u003Cp>Our team of dedicated cybersecurity analysts acts as an extension of your business, monitoring your environment \u003Cstrong>24\u002F7\u002F365\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Expert Alert Triage:\u003C\u002Fstrong> We filter out the noise. Our analysts investigate every alert, weed out the false positives, and ensure you only get notified about verified, high-fidelity security incidents.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Actionable Remediation Advice:\u003C\u002Fstrong> We don’t just send you an alert saying \"something is wrong.\" We provide clear, step-by-step guidance on how to contain and resolve the threat.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Proactive Threat Hunting:\u003C\u002Fstrong> Our SOC doesn't just wait for alerts to trigger. We proactively hunt for stealthy, persistent threats that might have bypassed standard detection rules.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Rapid Incident Response:\u003C\u002Fstrong> When a critical threat is detected, our team initiates immediate containment protocols to minimize impact and prevent lateral movement across your network.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"key-benefits-for-your-organization\">Key Benefits for Your Organization\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services#key-benefits-for-your-organization\" class=\"hash-link\" aria-label=\"Direct link to Key Benefits for Your Organization\" title=\"Direct link to Key Benefits for Your Organization\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>By partnering with Eventus for Managed SIEM and SOC, you can:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Focus on Your Business:\u003C\u002Fstrong> Free your IT team from the burden of security monitoring, allowing them to focus on strategic growth initiatives rather than chasing alerts.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Achieve True 24\u002F7 Protection:\u003C\u002Fstrong> Cyber threats don’t stick to a 9-to-5 schedule. Neither do we. Gain peace of mind knowing that security experts are watching your network overnight, during weekends, and over holidays.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Maximize Security ROI:\u003C\u002Fstrong> Get the full value out of your existing security tool investments by ensuring every alert they generate is audited and investigated.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Lower Total Cost of Ownership (TCO):\u003C\u002Fstrong> Access enterprise-grade security operations, next-gen cloud SIEM technology, and a team of certified analysts for a fraction of the cost of building it in-house.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Chr>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"lets-secure-your-future\">Let’s Secure Your Future\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F23\u002Fintroducing-managed-siem-devo-managed-soc-services#lets-secure-your-future\" class=\"hash-link\" aria-label=\"Direct link to Let’s Secure Your Future\" title=\"Direct link to Let’s Secure Your Future\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>You shouldn't have to choose between leaving alerts unchecked and burning out your IT team. Let Eventus take the wheel.\u003C\u002Fp>\n\u003Cp>Are you ready to eliminate alert fatigue and secure your organization with round-the-clock monitoring?\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Contact Eventus Today\u003C\u002Fa> to schedule a consultation and learn how our Managed SIEM and Managed SOC services can be tailored to your business needs.\u003C\u002Fp>","Managed SIEM and Managed SOC Services Powered by Devo | Eventus","See how Eventus Managed SIEM and Managed SOC services, powered by Devo, help lean teams reduce alert fatigue with 24\u002F7 threat detection and response.","2026-05-23T00:00:00.000Z",{"name":15,"url":16},[133,153,114,23,33,34,154],"Managed SOC","Services",{"id":156,"content_html":157,"url":156,"title":158,"summary":159,"date_modified":160,"author":161,"tags":162},"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F10\u002Fmodernizing-soc-operations-with-devo-and-ai","\u003Cp>In today’s rapidly evolving threat landscape, traditional Security Operations Centers (SOCs) are often overwhelmed by the sheer volume of data and the sophistication of modern attacks. Legacy SIEM solutions frequently struggle with scalability, leading to \"alert fatigue\" and missed threats.\u003C\u002Fp>\n\u003Cp>At Eventus, we have redefined SOC operations by integrating \u003Cstrong>Devo\u003C\u002Fstrong>, the cloud-native logging and SIEM platform, with advanced \u003Cstrong>AI\u003C\u002Fstrong> capabilities. This combination allows us to streamline operations, reduce workloads, and move beyond reactive monitoring to proactive defense.\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"streamlining-with-devo-speed-and-scale-at-your-fingertips\">Streamlining with Devo: Speed and Scale at Your Fingertips\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F10\u002Fmodernizing-soc-operations-with-devo-and-ai#streamlining-with-devo-speed-and-scale-at-your-fingertips\" class=\"hash-link\" aria-label=\"Direct link to Streamlining with Devo: Speed and Scale at Your Fingertips\" title=\"Direct link to Streamlining with Devo: Speed and Scale at Your Fingertips\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The foundation of a modern SOC is its ability to ingest, process, and analyze massive amounts of data in real-time. Devo provides the scalability and speed required to handle the data demands of even the most complex environments.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Zero-Latency Ingestion:\u003C\u002Fstrong> Devo allows us to ingest security data at lightning speed, ensuring that no event goes unlogged.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Real-Time Analytics:\u003C\u002Fstrong> With Devo, our analysts can run complex queries across petabytes of data and receive results in seconds, not minutes or hours.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Unified Visibility:\u003C\u002Fstrong> By centralizing logs from across your entire infrastructure—cloud, on-prem, and edge—we gain a holistic view of your security posture.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"reducing-workload-with-ai-from-noise-to-insights\">Reducing Workload with AI: From Noise to Insights\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F10\u002Fmodernizing-soc-operations-with-devo-and-ai#reducing-workload-with-ai-from-noise-to-insights\" class=\"hash-link\" aria-label=\"Direct link to Reducing Workload with AI: From Noise to Insights\" title=\"Direct link to Reducing Workload with AI: From Noise to Insights\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>One of the biggest challenges in any SOC is separating the \"signal\" from the \"noise.\" This is where AI plays a crucial role in our operations.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Automated Alert Triage:\u003C\u002Fstrong> AI algorithms analyze incoming alerts, automatically dismissing known false positives and prioritizing high-risk incidents.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Contextual Correlation:\u003C\u002Fstrong> AI helps correlate seemingly unrelated events across different systems, uncovering complex attack patterns that might otherwise be missed.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Reduced Analyst Fatigue:\u003C\u002Fstrong> By automating repetitive tasks and reducing the volume of low-fidelity alerts, our analysts can focus their expertise on deep threat hunting and incident response.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-eventus-advantage-we-dont-just-monitor-we-fix\">The Eventus Advantage: We Don’t Just Monitor, We Fix\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F10\u002Fmodernizing-soc-operations-with-devo-and-ai#the-eventus-advantage-we-dont-just-monitor-we-fix\" class=\"hash-link\" aria-label=\"Direct link to The Eventus Advantage: We Don’t Just Monitor, We Fix\" title=\"Direct link to The Eventus Advantage: We Don’t Just Monitor, We Fix\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>While many managed security providers stop at sending you an alert, Eventus takes a different approach. We believe that true security requires partnership and action.\u003C\u002Fp>\n\u003Cp>When you choose Eventus for your SOC operations, our technology team does more than just watch the screens. We provide \u003Cstrong>actionable remediation guidance\u003C\u002Fstrong> for every critical incident.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Proactive Suggestions:\u003C\u002Fstrong> For every threat detected within the covered environment, we don't just tell you there's a problem—we suggest exactly how to fix it.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Collaborative Remediation:\u003C\u002Fstrong> Our team works closely with yours to ensure that fixes are implemented correctly and that the root cause is addressed.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Continuous Improvement:\u003C\u002Fstrong> We use the insights gained from each incident to further tune our AI models and Devo dashboards, strengthening your defenses over time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"elevate-your-security-posture-today\">Elevate Your Security Posture Today\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F05\u002F10\u002Fmodernizing-soc-operations-with-devo-and-ai#elevate-your-security-posture-today\" class=\"hash-link\" aria-label=\"Direct link to Elevate Your Security Posture Today\" title=\"Direct link to Elevate Your Security Posture Today\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Is your organization ready to move beyond basic monitoring? Don't let your security team get bogged down by legacy tools and alert fatigue.\u003C\u002Fp>\n\u003Cp>Consider partnering with Eventus for your SOC operations. Experience the power of Devo and AI combined with a team that is dedicated to not just identifying threats, but helping you eliminate them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Contact us today\u003C\u002Fa> to learn more about our SOC services and how we can help secure your organization's future.\u003C\u002Fstrong>\u003C\u002Fp>","Modernizing SOC Operations: How Eventus Leverages Devo and AI for Proactive Security","Discover how Eventus is transforming SOC operations by combining the power of Devo's cloud-native SIEM with advanced AI to deliver proactive security that goes beyond simple monitoring.","2026-05-10T00:00:00.000Z",{"name":15,"url":16},[163,114,164,23,165,18,154],"SOC","AI","ManagedServices",{"id":167,"content_html":168,"url":167,"title":169,"summary":170,"date_modified":171,"author":172,"tags":173},"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F30\u002Fcatch-eventus-at-cybersec-2026-discover-the-future-of-cyber-resilience-at-booth-p212","\u003Cp>CYBERSEC 2026 is just around the corner, taking place from \u003Cstrong>May 5–7, 2026\u003C\u002Fstrong> at the Taipei Nangang Exhibition Center, Hall 2. This year’s event is all about building a \"Resilient Future,\" and the Eventus team is thrilled to be right at the heart of the action!\u003C\u002Fp>\n\u003Cp>Whether your organization is looking to upgrade its threat detection capabilities, secure critical communications, or protect edge devices, we have exactly what you need. Come visit us at \u003Cstrong>Booth P212\u003C\u002Fstrong> to explore how our cutting-edge partnerships and solutions are redefining modern cybersecurity.\u003C\u002Fp>\n\u003Cp>Here is a sneak peek at what we will be showcasing:\u003C\u002Fp>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"️-modern-cloud-based-siem-devo--strike48\">☁️ Modern Cloud-Based SIEM: Devo &amp; Strike48\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F30\u002Fcatch-eventus-at-cybersec-2026-discover-the-future-of-cyber-resilience-at-booth-p212#%EF%B8%8F-modern-cloud-based-siem-devo--strike48\" class=\"hash-link\" aria-label=\"Direct link to ☁️ Modern Cloud-Based SIEM: Devo &amp; Strike48\" title=\"Direct link to ☁️ Modern Cloud-Based SIEM: Devo &amp; Strike48\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Say goodbye to legacy bottlenecks and alert fatigue. We are showcasing \u003Cstrong>Devo\u003C\u002Fstrong> and \u003Cstrong>Strike48\u003C\u002Fstrong> to bring you the ultimate modern, cloud-native SIEM experience.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Unmatched Scalability:\u003C\u002Fstrong> Ingest your security data at warp speed without compromising search performance.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Real-Time Analytics:\u003C\u002Fstrong> Gain instant, actionable visibility into your entire threat landscape.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Outcome-Driven Operations:\u003C\u002Fstrong> Move away from reactive alert-chasing and empower your team with proactive threat hunting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"️-modern-security-mimecast\">🛡️ Modern Security: Mimecast\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F30\u002Fcatch-eventus-at-cybersec-2026-discover-the-future-of-cyber-resilience-at-booth-p212#%EF%B8%8F-modern-security-mimecast\" class=\"hash-link\" aria-label=\"Direct link to 🛡️ Modern Security: Mimecast\" title=\"Direct link to 🛡️ Modern Security: Mimecast\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>The threat landscape is constantly evolving, and so must your defense mechanisms. We are proud to feature \u003Cstrong>Mimecast\u003C\u002Fstrong> at our booth to demonstrate what next-generation security looks like today.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Advanced Email Protection:\u003C\u002Fstrong> Block phishing, ransomware, and targeted attacks before they ever reach the inbox.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Human Risk Management:\u003C\u002Fstrong> Transform your workforce from a potential vulnerability into your strongest line of defense.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Data Security:\u003C\u002Fstrong> Protect your critical information across cloud environments and collaborative workspaces.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"-aiot--software-defined-gateways-sekhmet\">🌐 AIoT &amp; Software-Defined Gateways: SEKHMET\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F30\u002Fcatch-eventus-at-cybersec-2026-discover-the-future-of-cyber-resilience-at-booth-p212#-aiot--software-defined-gateways-sekhmet\" class=\"hash-link\" aria-label=\"Direct link to 🌐 AIoT &amp; Software-Defined Gateways: SEKHMET\" title=\"Direct link to 🌐 AIoT &amp; Software-Defined Gateways: SEKHMET\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>As the boundary between physical and digital worlds continues to blur, managing the edge efficiently has never been more critical. If you have specific needs in the AIoT space, you won't want to miss our showcase of \u003Cstrong>SEKHMET\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Software-Defined Gateways:\u003C\u002Fstrong> Deploy agile, highly secure, and easily manageable network perimeters.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Seamless AIoT Integration:\u003C\u002Fstrong> Connect, manage, and scale your smart ecosystems and edge devices with ease.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Optimized Data Routing:\u003C\u002Fstrong> Ensure reliable and efficient data flow across your entire infrastructure.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"-lets-connect\">📍 Let's Connect!\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F30\u002Fcatch-eventus-at-cybersec-2026-discover-the-future-of-cyber-resilience-at-booth-p212#-lets-connect\" class=\"hash-link\" aria-label=\"Direct link to 📍 Let's Connect!\" title=\"Direct link to 📍 Let's Connect!\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Event:\u003C\u002Fstrong> CYBERSEC 2026\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Dates:\u003C\u002Fstrong> May 5–7, 2026\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Location:\u003C\u002Fstrong> Taipei Nangang Exhibition Center, Hall 2\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Booth:\u003C\u002Fstrong> P212\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Our team of experts will be on standby to run live demonstrations, answer your technical questions, and discuss how we can tailor these powerful tools to fit your organization's unique security roadmap.\u003C\u002Fp>\n\u003Cp>Don't leave your cyber resilience to chance. Drop by \u003Cstrong>Booth P212\u003C\u002Fstrong> and let's build a stronger, more secure future together. We can't wait to see you there!\u003C\u002Fp>","[CYBERSEC 2026] Visit Eventus at Booth P212: Devo, Mimecast & Sekhmet Security Solutions","Join Eventus at CYBERSEC 2026, Booth P212! Discover modern cybersecurity solutions tailored for your organization, including Devo's cloud-native SIEM, Mimecast's advanced security, and Sekhmet's AIoT software-defined gateways.","2026-04-30T00:00:00.000Z",{"name":15,"url":16},[174,175,114,176,177,178,23,179,180,181,182,183,184],"CYBERSEC2026","CybersecurityConference","Strike48","Mimecast","Sekhmet","CloudSIEM","EmailSecurity","AIoTSecurity","SoftwareDefinedGateway","ZeroTrust","CyberResilience",{"id":186,"content_html":187,"url":186,"title":188,"summary":189,"date_modified":190,"author":191,"tags":192},"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F17\u002Fnna-highlights-eventus-redefining-the-iot-market-with-the-software-defined-gateway","\u003Cp>We are proud to share that \u003Cstrong>Eventus\u003C\u002Fstrong> was recently featured in an in-depth report by \u003Cstrong>NNA\u003C\u002Fstrong>, the premier business news source for Asian markets. The article (NNA News ID: 2915173) highlights our mission to eliminate the high costs associated with traditional IoT deployment and our strategic expansion via the \u003Cstrong>Startup Tokyo\u003C\u002Fstrong> program.\n\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"NNA Asia Article Snaphost\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fnna-asia-2915173-b4636cecb9946ed52bda35c504e5e575.png\" title=\"NNA Asia Article Snaphost\" width=\"687\" height=\"388\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-authoritative-recap-of-the-nna-coverage\">The Authoritative Recap of the NNA Coverage\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F17\u002Fnna-highlights-eventus-redefining-the-iot-market-with-the-software-defined-gateway#the-authoritative-recap-of-the-nna-coverage\" class=\"hash-link\" aria-label=\"Direct link to The Authoritative Recap of the NNA Coverage\" title=\"Direct link to The Authoritative Recap of the NNA Coverage\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>The NNA feature focuses on our revolutionary \u003Cstrong>Software-Defined Gateway (SDG)\u003C\u002Fstrong>, a technology that is fundamentally changing how data is collected in healthcare and smart cities. As noted in the NNA report (2915173), Eventus is effectively ending the \"Hardware Tax\"—the expensive burden of purchasing dedicated gateways and paying for professional installation.\u003C\u002Fp>\n\u003Cp>Key insights from the NNA reporting:\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Transforming Existing Assets:\u003C\u002Fstrong> How any smartphone or PC can now serve as a medical-grade IoT hub.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Zero-CAPEX Infrastructure:\u003C\u002Fstrong> The report highlights our ability to launch large-scale monitoring projects without upfront hardware investment.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>The \"Universal Data Glue\":\u003C\u002Fstrong> Our platform’s role in unifying data from high-precision sensors, such as \u003Cstrong>Quanta\u003C\u002Fstrong>, into a single AI-ready stream.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-the-industry-is-following-the-latest-nna-insights\">Why the Industry is Following the Latest NNA Insights\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F17\u002Fnna-highlights-eventus-redefining-the-iot-market-with-the-software-defined-gateway#why-the-industry-is-following-the-latest-nna-insights\" class=\"hash-link\" aria-label=\"Direct link to Why the Industry is Following the Latest NNA Insights\" title=\"Direct link to Why the Industry is Following the Latest NNA Insights\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>This specific coverage marks a turning point for Eventus in Japan. Following our selection for \u003Cstrong>Startup Tokyo\u003C\u002Fstrong>, the NNA report (2915173) validates our \"Hybrid Infrastructure\" strategy. We provide the agility of a software-based gateway for home care while maintaining robust support for industrial hardware gateways in 24\u002F7 mission-critical environments.\u003C\u002Fp>\n\u003Cp>We invite our partners and stakeholders searching for more information on the \u003Cstrong>NNA Eventus feature (2915173)\u003C\u002Fstrong> to see a live demonstration of these capabilities at our upcoming exhibitions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>[Official Link to NNA Article: \u003Ca href=\"https:\u002F\u002Fwww.nna.jp\u002Fnews\u002F2915173\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https:\u002F\u002Fwww.nna.jp\u002Fnews\u002F2915173\u003C\u002Fa>]\u003C\u002Fstrong>\n\u003Cstrong>Explore the Sekhmet Platform:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fsekhmet.tech\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https:\u002F\u002Fsekhmet.tech\u003C\u002Fa>\n\u003Cstrong>Visit Eventus Official:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Feventus.one\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https:\u002F\u002Feventus.one\u003C\u002Fa>\u003C\u002Fp>","NNA Highlights Eventus: Redefining the IoT Market with the \"Software-Defined Gateway\"","Eventus joins Startup Tokyo 2026 and disrupts the IoT landscape with the launch of the Software-Defined Gateway. Learn how we are eliminating the \"Hardware Tax\" by enabling zero-CAPEX remote monitoring through iOS, Android, macOS, and Windows apps. Read the official PR TIMES release and visit us at Startup JAPAN EXPO 2026 for a live demo of the \"Universal Data Glue.\".","2026-04-17T00:00:00.000Z",{"name":15,"url":16},[55,56,57,59,193,194,195,196,182,197],"ZeroCAPEX","StartupTokyo","SmartCity","RemoteMonitoring","NNA",{"id":199,"content_html":200,"url":199,"title":201,"summary":189,"date_modified":202,"author":203,"tags":204},"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F14\u002Fbreaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway","\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"breaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway\">Breaking the \"Hardware Tax\": Eventus Joins Startup Tokyo and Launches Software-Defined Gateway\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F14\u002Fbreaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway#breaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway\" class=\"hash-link\" aria-label=\"Direct link to Breaking the &quot;Hardware Tax&quot;: Eventus Joins Startup Tokyo and Launches Software-Defined Gateway\" title=\"Direct link to Breaking the &quot;Hardware Tax&quot;: Eventus Joins Startup Tokyo and Launches Software-Defined Gateway\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>We are thrilled to share some major milestones for the Eventus team! Today, we officially published our latest press release on PR TIMES, detailing our selection for the Startup Tokyo program and the global launch of our revolutionary Software-Defined Gateway (SDG) feature.\u003C\u002Fp>\n\u003Cp>Read the full press release on PR TIMES here:\n👉 \u003Ca href=\"https:\u002F\u002Fprtimes.jp\u002Fmain\u002Fhtml\u002Frd\u002Fp\u002F000000002.000175422.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">イベントス株式会社 、「Startup JAPAN EXPO 2026」出展および「ソフトウェア定義型ゲートウェイ」の提供開始を発表\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cimg decoding=\"async\" loading=\"lazy\" alt=\"PR Times Article Snapshot\" src=\"https:\u002F\u002Feventus.blog\u002Fassets\u002Fimages\u002Fprtimes-46247288bdcca3a7232cc06392197f3a.png\" title=\"PR Times Article Snapshot\" width=\"851\" height=\"262\" class=\"img_ev3q\">\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-end-of-the-hardware-tax\">The End of the \"Hardware Tax\"\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F14\u002Fbreaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway#the-end-of-the-hardware-tax\" class=\"hash-link\" aria-label=\"Direct link to The End of the &quot;Hardware Tax&quot;\" title=\"Direct link to The End of the &quot;Hardware Tax&quot;\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>For years, the biggest barrier to IoT and Digital Transformation (DX) has been the \"Hardware Tax.\" To monitor a single patient or room, organizations previously had to purchase expensive dedicated gateways, hire electricians for installation, and deal with complex wiring.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>That ends today.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>With the launch of our Software-Defined Gateway, any existing smartphone, tablet, or PC (iOS, Android, macOS, Windows) can now be transformed into a medical-grade IoT hub.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">Zero CAPEX: No new hardware to buy.\u003C\u002Fli>\n\u003Cli class=\"\">Zero Installation: No drilling holes or wiring. Just download the app.\u003C\u002Fli>\n\u003Cli class=\"\">Instant Scaling: Deploy a monitoring network across an entire facility or country in minutes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"a-hybrid-approach-for-real-world-needs\">A Hybrid Approach for Real-World Needs\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F14\u002Fbreaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway#a-hybrid-approach-for-real-world-needs\" class=\"hash-link\" aria-label=\"Direct link to A Hybrid Approach for Real-World Needs\" title=\"Direct link to A Hybrid Approach for Real-World Needs\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>While we are excited about the software revolution, we know that mission-critical environments like hospital wards still require permanent infrastructure. That is why Eventus continues to support a Hybrid Strategy. Whether you need the portability of our new app-based gateway or the 24\u002F7 reliability of traditional hardware (like Cassia hubs), Eventus provides the \"Universal Data Glue\" to bring all your data into one AI-ready stream.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"meet-us-at-startup-japan-expo-2026\">Meet Us at Startup JAPAN EXPO 2026\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F14\u002Fbreaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway#meet-us-at-startup-japan-expo-2026\" class=\"hash-link\" aria-label=\"Direct link to Meet Us at Startup JAPAN EXPO 2026\" title=\"Direct link to Meet Us at Startup JAPAN EXPO 2026\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>We are also proud to announce that Eventus will be exhibiting at Startup JAPAN EXPO 2026 in Tokyo!\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">When: April 15-16, 2026\u003C\u002Fli>\n\u003Cli class=\"\">Where: Our dedicated booth in the Startup Tokyo pavilion.\nCome visit our Managing Director, James Yip, and the rest of the team to see a live demo of the Software-Defined Gateway in action. We will be showcasing how we integrate high-precision clinical data from Quanta sensors and environmental data into a single, unified platform.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"join-the-revolution\">Join the Revolution\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2026\u002F04\u002F14\u002Fbreaking-the-hardware-tax-eventus-joins-startup-tokyo-and-launches-software-defined-gateway#join-the-revolution\" class=\"hash-link\" aria-label=\"Direct link to Join the Revolution\" title=\"Direct link to Join the Revolution\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Whether you are in healthcare, elderly care, or smart city development, the barrier to entry has never been lower. We invite you to read our official announcement and reach out to us to see how we can accelerate your DX journey.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">Official Press Release: \u003Ca href=\"https:\u002F\u002Fprtimes.jp\u002Fmain\u002Fhtml\u002Frd\u002Fp\u002F000000002.000175422.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https:\u002F\u002Fprtimes.jp\u002Fmain\u002Fhtml\u002Frd\u002Fp\u002F000000002.000175422.html\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli class=\"\">Learn more about Sekhmet: \u003Ca href=\"https:\u002F\u002Fsekhmet.tech\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https:\u002F\u002Fsekhmet.tech\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli class=\"\">Visit Eventus: \u003Ca href=\"https:\u002F\u002Feventus.one\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https:\u002F\u002Feventus.one\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","Breaking the Hardware Tax: Eventus Joins Startup Tokyo and Launches Software-Defined Gateway","2026-04-14T00:00:00.000Z",{"name":15,"url":16},[55,56,205,194,195,57,206,193],"DigitalHealth","DX",{"id":208,"content_html":209,"url":208,"title":210,"summary":211,"date_modified":212,"author":213,"tags":214},"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection","\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"enki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection\">Enki: The Microsoft 365 Outlook Add-in for Enterprise Spam Reporting and Data Collection\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection#enki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection\" class=\"hash-link\" aria-label=\"Direct link to Enki: The Microsoft 365 Outlook Add-in for Enterprise Spam Reporting and Data Collection\" title=\"Direct link to Enki: The Microsoft 365 Outlook Add-in for Enterprise Spam Reporting and Data Collection\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"unlock-advanced-email-security-and-data-collection-with-enki\">\u003Cstrong>Unlock Advanced Email Security and Data Collection with Enki\u003C\u002Fstrong>\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection#unlock-advanced-email-security-and-data-collection-with-enki\" class=\"hash-link\" aria-label=\"Direct link to unlock-advanced-email-security-and-data-collection-with-enki\" title=\"Direct link to unlock-advanced-email-security-and-data-collection-with-enki\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>In today's digital landscape, effective email management goes beyond a clean inbox. You need a powerful solution to collect and analyze email security data. We are excited to introduce \u003Cstrong>Enki\u003C\u002Fstrong>, a versatile new Outlook add-in designed specifically for organizations using Microsoft 365 Exchange Online or Exhcnage Server.\u003C\u002Fp>\n\u003Cp>Enki is not a typical email filtering solution. Instead, it is a specialized tool for \u003Cstrong>email security data collection\u003C\u002Fstrong>, providing your IT and security teams with the actionable intelligence they need to respond to threats and improve security protocols.\u003C\u002Fp>\n\u003Cp>Enki is available in three editions, tailored to fit every business size and need.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"enki-basic-the-free-spam-reporting-solution\">\u003Cstrong>Enki Basic: The Free Spam Reporting Solution\u003C\u002Fstrong>\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection#enki-basic-the-free-spam-reporting-solution\" class=\"hash-link\" aria-label=\"Direct link to enki-basic-the-free-spam-reporting-solution\" title=\"Direct link to enki-basic-the-free-spam-reporting-solution\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Getting started with Enki is completely free and risk-free. Our Basic edition is the perfect \u003Cstrong>Outlook spam reporting add-in\u003C\u002Fstrong> for individuals and small teams. It allows users to flag unwanted emails with a single click, automatically collecting them in a designated email box. This provides a simple, centralized method for reviewing reported messages.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"enki-standard-advanced-statistics-for-your-microsoft-365-tenant\">\u003Cstrong>Enki Standard: Advanced Statistics for Your Microsoft 365 Tenant\u003C\u002Fstrong>\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection#enki-standard-advanced-statistics-for-your-microsoft-365-tenant\" class=\"hash-link\" aria-label=\"Direct link to enki-standard-advanced-statistics-for-your-microsoft-365-tenant\" title=\"Direct link to enki-standard-advanced-statistics-for-your-microsoft-365-tenant\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>For organizations that need more than just simple collection, the \u003Cstrong>Enki Standard edition\u003C\u002Fstrong> is the ideal choice. Priced at just USD100 per month per Microsoft 365 tenant, this premium version expands on the Basic edition by providing the ability to \u003Cstrong>collect detailed statistics on reported emails\u003C\u002Fstrong>. This data gives you valuable insights into the types and volume of threats your organization faces. The Standard edition also includes priority support and greater customization options to seamlessly integrate with your existing workflows.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"enki-enterprise-on-premise-deployment-and-outlook-classic-support\">\u003Cstrong>Enki Enterprise: On-Premise Deployment and Outlook Classic Support\u003C\u002Fstrong>\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection#enki-enterprise-on-premise-deployment-and-outlook-classic-support\" class=\"hash-link\" aria-label=\"Direct link to enki-enterprise-on-premise-deployment-and-outlook-classic-support\" title=\"Direct link to enki-enterprise-on-premise-deployment-and-outlook-classic-support\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Large enterprises with complex security requirements or on-premise infrastructure can leverage the full power of Enki Enterprise. This edition provides the ultimate flexibility by supporting \u003Cstrong>on-premise deployment\u003C\u002Fstrong>, allowing you to host the add-in on your own servers and maintain complete control over your data.\u003C\u002Fp>\n\u003Cp>A key feature for enterprise clients is our \u003Cstrong>support for Outlook classic\u003C\u002Fstrong>, ensuring that Enki works across your entire organization's client environment, regardless of whether you're using the latest versions or traditional desktop clients. The Enterprise edition offers all the features of the Standard edition, along with enhanced security and dedicated migration support. Pricing for the Enterprise edition is available via a custom quote.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"key-features-for-a-smarter-email-environment\">\u003Cstrong>Key Features for a Smarter Email Environment\u003C\u002Fstrong>\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Fenki-the-microsoft-365-outlook-add-in-for-enterprise-spam-reporting-and-data-collection#key-features-for-a-smarter-email-environment\" class=\"hash-link\" aria-label=\"Direct link to key-features-for-a-smarter-email-environment\" title=\"Direct link to key-features-for-a-smarter-email-environment\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Effortless Spam and Phishing Collection:\u003C\u002Fstrong> Streamline the reporting of suspicious emails with a simple, one-click process.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Data-Focused, Not Filter-Focused:\u003C\u002Fstrong> Enki collects data for your security team to analyze, rather than automatically blocking emails.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Detailed Statistics (Standard &amp; Enterprise):\u003C\u002Fstrong> Gain crucial insights into the types of threats your users are reporting.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Microsoft 365 Admin Portal Deployment:\u003C\u002Fstrong> Easily deploy the add-in across your organization by adding a URL in your Microsoft 365 admin portal.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Customization and Control (Standard &amp; Enterprise):\u003C\u002Fstrong> Adapt Enki to your specific security policies and infrastructure.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Ready to take control of your organization’s email security data? Start with our free Basic edition, or \u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">contact\u003C\u002Fa> our sales team for more information on the Standard and Enterprise editions.\u003C\u002Fp>","Enki - The Microsoft 365 Outlook Add-in for Enterprise Spam Reporting and Data Collection","Empower your organization with Enki, a powerful Outlook add-in for Microsoft 365. Easily collect spam and phishing emails, analyze security statistics, and deploy on-premise for full control.","2025-08-22T00:00:00.000Z",{"name":15,"url":16},[215,216,217,218,219,220,221,222,223,224,225,226,23],"Outlook","Microsoft 365","Email Security","Spam Reporting","Add-in","IT Security","Enterprise","Data Collection","On-Premise","Outlook Classic","Phishing","Exchange Online",{"id":228,"content_html":229,"url":228,"title":230,"summary":231,"date_modified":212,"author":232,"tags":233},"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook","\u003Ch2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"take-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook\">Take Control of Your Inbox: The Ultimate Guide to the Enki Spam Report Add-in for Outlook\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#take-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook\" class=\"hash-link\" aria-label=\"Direct link to Take Control of Your Inbox: The Ultimate Guide to the Enki Spam Report Add-in for Outlook\" title=\"Direct link to Take Control of Your Inbox: The Ultimate Guide to the Enki Spam Report Add-in for Outlook\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh2>\n\u003Cp>Are you overwhelmed by spam and phishing emails? A cluttered inbox not only wastes your time but also poses a security risk. It's time to fight back and create a cleaner, safer digital space. Introducing the \u003Cstrong>Enki add-in for Outlook\u003C\u002Fstrong>, your new secret weapon for effortless email management.\u003C\u002Fp>\n\u003Cp>Enki is a lightweight yet powerful tool designed to help you easily report spam and phishing attempts directly from your Outlook application. By flagging unwanted messages, you not only tidy up your personal inbox but also contribute to a better, more secure email environment for everyone.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-makes-the-enki-add-in-an-essential-outlook-tool\">What Makes the Enki Add-in an Essential Outlook Tool?\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#what-makes-the-enki-add-in-an-essential-outlook-tool\" class=\"hash-link\" aria-label=\"Direct link to What Makes the Enki Add-in an Essential Outlook Tool?\" title=\"Direct link to What Makes the Enki Add-in an Essential Outlook Tool?\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>The Enki add-in simplifies the tedious task of dealing with unwanted emails. Instead of manually moving messages or hoping your email provider catches them, Enki gives you a one-click solution to report malicious or unsolicited content. This enhances your \u003Cstrong>Outlook productivity\u003C\u002Fstrong> and protects you from potential threats like phishing scams.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-to-install-and-use-the-enki-add-in-a-step-by-step-guide\">How to Install and Use the Enki Add-in: A Step-by-Step Guide\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#how-to-install-and-use-the-enki-add-in-a-step-by-step-guide\" class=\"hash-link\" aria-label=\"Direct link to How to Install and Use the Enki Add-in: A Step-by-Step Guide\" title=\"Direct link to How to Install and Use the Enki Add-in: A Step-by-Step Guide\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>Getting started with Enki is straightforward. Here’s how you can deploy the add-in and start reporting spam in just a few simple steps.\u003C\u002Fp>\n\u003Ch4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-1-get-the-manifest-file\">Step 1: Get the Manifest File\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#step-1-get-the-manifest-file\" class=\"hash-link\" aria-label=\"Direct link to Step 1: Get the Manifest File\" title=\"Direct link to Step 1: Get the Manifest File\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh4>\n\u003Cp>To install Enki, you first need its manifest file. This file contains all the necessary information for Outlook to recognize and install the add-in. You can obtain it directly from the official source:\u003C\u002Fp>\n\u003Cp>The submission URL template is as follows:\n\u003Ccode>https:\u002F\u002Fmanifest.addin.eventusenki.com\u002Fmanifest\u002Fspamreport\u002F?submitTo=&lt;submit to email&gt;\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>Simply replace \u003Ccode>&lt;submit to email&gt;\u003C\u002Fcode> with the appropriate email address to direct your report.\u003C\u002Fp>\n\u003Ch4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-2-deploy-to-outlook\">Step 2: Deploy to Outlook\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#step-2-deploy-to-outlook\" class=\"hash-link\" aria-label=\"Direct link to Step 2: Deploy to Outlook\" title=\"Direct link to Step 2: Deploy to Outlook\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh4>\n\u003Cp>With the manifest file ready, you can add it to your Outlook. This process can vary slightly depending on your version of Outlook and your organization's settings. For a comprehensive guide on managing and deploying add-ins, especially for administrators, we highly recommend this official resource from Microsoft:\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fadmin\u002Fmanage\u002Fmanage-deployment-of-add-ins?view=o365-worldwide\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">\u003Cstrong>Learn how to manage and deploy add-ins in the Microsoft 365 admin center\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-3-start-reporting-spam-with-a-single-click\">Step 3: Start Reporting Spam with a Single Click\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#step-3-start-reporting-spam-with-a-single-click\" class=\"hash-link\" aria-label=\"Direct link to Step 3: Start Reporting Spam with a Single Click\" title=\"Direct link to Step 3: Start Reporting Spam with a Single Click\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh4>\n\u003Cp>Once the add-in is installed, you will see the Enki spam report option appear within your Outlook interface. The add-in handles the submission process for you using a secure URL structure. The URL sends your report to the designated address, helping to manage and block future spam.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"upgrade-to-enki-standard-and-enterprise-editions\">Upgrade to Enki Standard and Enterprise Editions\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#upgrade-to-enki-standard-and-enterprise-editions\" class=\"hash-link\" aria-label=\"Direct link to Upgrade to Enki Standard and Enterprise Editions\" title=\"Direct link to Upgrade to Enki Standard and Enterprise Editions\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>While the basic Enki add-in is a powerful free tool, we offer more robust solutions for users and organizations that need advanced features.\u003C\u002Fp>\n\u003Cul>\n\u003Cli class=\"\">\u003Cstrong>Enki Standard Edition\u003C\u002Fstrong> is designed for power users who require enhanced reporting capabilities and more granular control over their email environment.\u003C\u002Fli>\n\u003Cli class=\"\">\u003Cstrong>Enki Enterprise Edition\u003C\u002Fstrong> provides a complete solution for corporate environments, with features such as centralized administration, detailed analytics, and custom reporting to help you manage your organization's security posture.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>To learn more about the benefits of a paid edition and to discuss an upgrade from the free version, please \u003Ca href=\"https:\u002F\u002Feventus.one\u002Fcontact\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">contact\u003C\u002Fa> our sales team.\u003C\u002Fp>\n\u003Ch3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"a-safer-inbox-one-report-at-a-time\">A Safer Inbox, One Report at a Time\u003Ca href=\"https:\u002F\u002Feventus.blog\u002F2025\u002F08\u002F22\u002Ftake-control-of-your-inbox-the-ultimate-guide-to-the-enki-spam-report-add-in-for-outlook#a-safer-inbox-one-report-at-a-time\" class=\"hash-link\" aria-label=\"Direct link to A Safer Inbox, One Report at a Time\" title=\"Direct link to A Safer Inbox, One Report at a Time\" translate=\"no\">​\u003C\u002Fa>\u003C\u002Fh3>\n\u003Cp>By leveraging the power of the Enki spam report add-in, you can maintain a cleaner, more organized, and secure inbox. Stop letting unwanted emails dictate your day.\u003C\u002Fp>","Take Control of Your Inbox - The Ultimate Guide to the Enki Spam Report Add-in for Outlook","Clean up your Outlook inbox with the powerful Enki spam report add-in. This guide shows you how to easily report unwanted emails, manage your inbox, and enhance your productivity. Learn how to install Enki and explore our paid editions.",{"name":15,"url":16},[234,215,235,225,236,219,237,238,216,221,239],"Enki","Spam","Email","Productivity","Security","Email Management",1790817555210]