IT Solutions

Monitoring and logging

We build the monitoring of your IT: infrastructure and security, mostly with open source software. A dedicated instance for larger environments, a shared solution for smaller businesses.

Monitoring watches continuously whether your systems are working. Logging records what happened. One reports the outage, the other answers afterwards what took place and by which route.

What is included

The building blocks we take care of for you.

Infrastructure, not only security

Most outages are not attacks. A disk in the server reports rising error counts weeks before it fails. A backup job has aborted for four nights and nobody reads the mail. A volume runs to 95 percent full. A certificate expires in ten days. A fan in the server room stops. That is what we see and report while it is still an appointment and not an emergency.

Security in the same picture

Sign ins, new administrator accounts, antivirus switched off, access from abroad, changes to permissions. On its own each event says little. Brought together, the pattern emerges that makes a takeover visible.

Open source, no vendor lock in

We rely mostly on open source software. The advantage is practical: no licence cost per device, the data stays where you want it, and you can change provider without rebuilding the whole monitoring.

A dedicated instance for larger environments

From a certain size you get your own instance. Your data sits separately, the retention period follows your requirements, and the reports reflect your business. That is the route when you have NIS2, ISO 27001 or an audit behind you. If you have an IT department of your own, we consider it the better route that your people operate the monitoring themselves. We build it, set it up and train your team on it. After that it is yours.

A shared solution for smaller businesses

A dedicated instance does not pay off for ten devices. For that we run a shared environment. You get the same monitoring without paying for the build yourself. Client data is kept separate.

Alerts that someone reads

A message nobody assesses is not monitoring. We tune the thresholds to your business, so night shifts and maintenance windows raise no false alarms. Otherwise the one real alert is lost among a hundred false ones. The monitoring itself runs continuously and automatically. Assessment happens during our business hours, Monday to Friday, 9 to 17.

Common questions

Briefly and clearly answered.

Do you offer 24/7 monitoring?
No. The monitoring runs continuously and automatically, and prepared playbooks apply at night as well. But we do not run a security operations centre, and we do not offer a round the clock standby service. We assess alerts Monday to Friday, 9 to 17. For smaller businesses we keep an eye on things alongside that. If you need a guaranteed response at three in the morning, we are not the right partner, and we would rather tell you beforehand.
We have our own IT department. What does vetosec do then?
The build and the training. If you have your own people, they should operate the monitoring themselves, because they know the business better than any external provider. We plan the environment, set it up, connect the sources, tune the thresholds and train your team on it. After that you work with it yourselves. On request we stay alongside for questions and for extending it.
What is the difference between monitoring and logging?
Monitoring watches the state and raises an alarm when a value falls outside the expected range. Logging records events without judging them. For day to day operation you need the monitoring. For the question of how an attacker got in, you need the logs.
What exactly is monitored?
Availability of servers and services, free storage, the health of disks and RAID sets, temperature, load, success of the backup jobs, expiry of certificates, ports open to the outside, sign ins, permission changes and the state of the antivirus.
What does monitoring cost?
It depends on the number of systems and on how long the logs are kept. Because we mostly use open source software, there is no licence cost per device. Smaller businesses share the environment, which brings the build down. We look at your systems and set it out for you in figures you can follow.
Logs contain personal data
They do. Logs record who signed in, when and from where. Purpose, retention period and rights of inspection therefore belong in writing beforehand, and any staff representation has to be involved. Monitoring that would serve to measure performance is a separate matter and is not our aim.
Do I need this for NIS2?
Section 32(4) NISG 2026 requires, among other things, the handling of incidents and the assessment of the effectiveness of the measures. Both assume that you can see what is happening at all. Without logs an incident can neither be reported nor reconstructed. This is our interpretation and not legal advice.
How much work is the build?
More than it looks. Each system reports in a form of its own, the clocks have to be set to the same time, and the thresholds have to be tuned to your business. That is where self built setups usually fail: the collecting stands after two days, the tuning is the real work and never quite ends.

Shall we look at this together?

A short call is enough to find out what makes sense for your business.

Get in touch

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.