forumNew topic

We've been asked to send logs to a SOC — for our size, which team or role should handle this?

BBarış S***MemberCommunity member
Joined
Mar 2023
Message
79
#1

In our latest contract with a major enterprise client, there's a requirement for external SOC integration. We need to forward our server network device, and app logs to a center that monitors 24/7, and respond to incoming security alerts.

We are a 35-person B2B software company. We don't have a dedicated in-house cybersecurity team. Our infrastructure and office network are managed by a 2-person sysadmin team and we have an 8-person dev team on the software side. Management wants to dump this entirely on the sysadmins, but with their current workload they don't want to take on this responsibility alone.

For a company of our size, who should actually own log ingestion, alert triage, and coordination with the SOC vendor? Should we handle this internally with our current staff, or bring in outside consulting?

TTülay K***ExpertCommunity member
Joined
May 2023
Message
182
Most Helpful#2

Short answer: At your scale, preparing log sources falls on the sysadmins, but evaluating incoming alerts and handling weekly coordination with the SOC firm definitely needs outside support from a part-time cybersecurity specialist or MSSP consultant. Ditching 24/7 alert monitoring on an internal 2-person sysadmin team will completely paralyze their day-to-day work.

To set up roles properly, you need a three-stage division of labor: 1) For log generation and shipping, installing agents on servers, configuring firewall syslog forwarding, and setting network permissions fall directly on your sysadmin team. 2) For software logging standards, formatting user activity and auth logs generated by your app to match the SOC's requirements is the dev team's job. 3) For SOC liaison and incident response, someone needs to triage and prioritize incoming security notices.

Our suggestion is to designate one person from your sysadmin team purely as the "technical point of contact," but leave actual alert triage to tier-1 analysts at your SOC provider. If you write into the contract that they must "filter non-critical alerts and only escalate verified incidents" rather than just "collect and ship logs," your sysadmins won't drown under alert fatigue.

PPolat A***ExpertCommunity member
Joined
Apr 2024
Message
365
#3

If you try dumping this on the sysadmins, both sides will be pointing fingers within the first month. The sysadmin will just ship the logs and move on, the SOC will say "these logs are incomplete," and your client will be stuck in the middle. You need at least one coordinator who understands security in between.

BBurcu A***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
workshop
Joined
Jun 2024
Message
49
#4

When pushing data from servers via syslog or agents, don't forget to account for bandwidth usage and CPU load. The sysadmin team can handle the setup, but timestamp consistency and encrypted transport require extra attention.

GGamze D***Veteran
Job title
Courier coordinator
Sector
Food wholesale
Organization type
300-person organization
Joined
Jan 2024
Message
209
#5

We went through a similar process with a 40-person team. We brought in an external security consultant for 20 hours a month, which cost around 18,000 TL monthly. We smoothed out the whole workflow with our sysadmin only spending about 4 hours a week on it.

PPınarExpert
Job title
Analytics Specialist
Joined
Jan 2024
Message
198

Doki · Mobile app · 2025

#6

Don't just start dumping logs blindly because the client asked for it. Most SOC firms charge extra for every useless log ingestion. If you don't strictly define the scope of what gets logged, you'll be hit with massive bills at the end of the month.

EEfe A***Member
Job title
System support specialist
Sector
Software
Organization type
8-person team
Joined
Jul 2022
Message
136

Doki · Infrastructure migration · 2025

#7

Exactly what logs is your client asking for? Just OS and firewall, or are database queries and in-app user activities included in the scope too?

İİsmail Ş***MemberCommunity member
Joined
May 2025
Message
177
#8

Draft an escalation matrix right away. When the SOC calls in the middle of the night, who are they waking up? 1) Sysadmin, 2) Lead dev, or 3) The CEO? Don't even start the integration without getting this in writing.

MMeryem M***Veteran
Job title
Data entry clerk
Sector
Security services
Organization type
8-person team
Joined
Oct 2023
Message
220
#9

they dumped it on our sysadmins too two months in the guys were ready to quit... anyway this definitely needs an outside consultant.

MMustafa U***Member
Job title
Social media manager
Sector
Real estate
Organization type
8-person team
Joined
Aug 2023
Message
65
#10

In short, infrastructure stays with sysadmins, code goes to devs, but alert tracking and contract coordination definitely need outside expert support.

ÜÜlkü Y***Member
Job title
Logistics planning
Sector
Food wholesale
Organization type
a company within a holding
Joined
Nov 2024
Message
84
#11

Noted, thanks. An automated scan report is not the same as a penetration test.

VVildan D***Member
Job title
Quality control inspector
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Apr 2024
Message
160

Doki · Phishing awareness training · 2024

#12

I'll try it.

MMustafa C***MemberCommunity member
Joined
Jan 2026
Message
96
#13

Saved. Everything goes well for the first three months; problems arise in the fourth.

When making decisions, write down the worst-case scenario too, not just the best. Correct me if I'm wrong.

AAli Ş***ExpertCommunity member
Joined
Aug 2024
Message
1
#14

correct.

AAhmet B***MemberCommunity member
Joined
Jan 2023
Message
280
#15

Let me clarify the technical side. If you get three different answers on a topic, the question was asked wrong.

ÖÖmer Ş***Member
Job title
Project manager
Sector
Software
Organization type
chain store
Joined
Feb 2025
Message
179

Doki · Brand identity · 2025

#16

Let me summarize the topic, since several different answers were given. Hasty decisions become decisions you have to fix six months later.

LLale A***Member
Job title
Site Manager
Sector
IT services
Organization type
cooperative
Joined
Jul 2023
Message
86
#17

I was thinking the same thing. Forgotten test environments are more often the entry point than live systems.

KKader K***MemberCommunity member
Joined
Oct 2023
Message
6
#18

Absolutely. If I were to add anything: Taking measures without an inventory leaves doors you haven't seen open.

When making a decision, first look at what data you have on hand. Hope this helps.

ZZehra E***ExpertCommunity member
Joined
Aug 2023
Message
220
#19

Exactly like that. If it's your first time start small; scaling comes later.

If you post the result here it will help others too.

HHakan Y***New member
Job title
Human Resources Specialist
Sector
Advertising and promotion
Organization type
early-stage startup
Joined
Sep 2026
Message
4
#20

Exactly like that. Most incidents start with a leaked password, not a vulnerability.

Security isn't absolute; it's about making attacks not worth the effort. This is my opinion, I'm not claiming it's absolute truth.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic