Case studiesNetwork & telecommunications
Case study · Network & storage · Australia and Thailand

30–40 TB a Day of Log Management for a Network and Storage Provider

A provider of network and storage services to enterprise customers in Australia and Thailand runs Secure60 as its log management platform, in continuous production, at 30–40 TB of ingest a day.

Network & telecommunications AustraliaThailand Log ManagementSIEM
Ingest
30–40 TB/day
Deployment
Sovereign SaaS, Australia and Thailand regions
In scope
Log Management, SIEM
Operating model
Customer-operated, Secure60 experts on call
Prints as an A4 document.
Current situation

High-volume telemetry across two jurisdictions

The provider’s network estate produces a sustained 30–40 TB of logs a day across Australian and Thai operations. The incumbent tooling was priced per gigabyte ingested, so retention was being shortened to contain cost, and the Thai and Australian environments were monitored separately because moving data between the two raised residency questions under Thailand’s PDPA.

The operations team needed one platform that could take the full volume, hold it long enough for investigation and customer reporting, and keep each country’s data in that country.

What Secure60 delivered

One platform across two sovereign regions

Secure60 was deployed as sovereign SaaS in both regions: the Australian estate lands in the Australian region and the Thai estate on Rackcorp infrastructure in Thailand. Both sit under one tenant, so the provider’s team works in one console with one context across both countries while each country’s data remains in that country.

Ingest runs through Secure60 collectors at the provider’s edge, with parsing into the common information model so network, storage and access telemetry can be correlated. Storage tiering moves data from hot to warm to cold on a fixed schedule, and multi-month retention at this volume is priced on the cold tier. Detection content from the managed rule library runs on the same data.

Components in place

Components in operation

  1. Continuous ingest at 30–40 TB/dayCollectors at the network edge in both countries, with parsing into the common information model on arrival.
  2. Sovereign regions in Australia and ThailandEach country’s data resides in-country; one tenant and one console across both.
  3. Tiered retentionHot, warm and cold tiers on a fixed schedule, sized for investigation windows and customer reporting obligations.
  4. Managed detection contentThe Secure60 rule library runs on the ingested data, tuned with Secure60 experts.
Business impact

Before and after

Area
Before Secure60
After Secure60
Ingest volume
Capped by per-GB pricing; sources dropped to control cost
Full estate ingested, 30–40 TB/day sustained
Retention
Shortened to fit the budget
Multi-month retention on tiered storage
Data residency
Two separate stacks, one per country
One tenant, data resident in each country
Investigation
Searches split across two tools, minutes at volume
Seconds, from one console, across both countries
Detection
Rules maintained in-house on partial data
Managed rule library on the full data set
Outcomes

Results

Cost per terabyte

Platform pricing rather than per-gigabyte metering removed the incentive to drop sources. The full estate is ingested at a lower cost per terabyte than the incumbent, with retention extended rather than cut.

Residency answered

Australian data resides in Australia and Thai data in Thailand under one platform, which is the documented answer to the PDPA residency question.

Operational cadence

Ingest, tiering and retention run on schedule without daily intervention from the operations team.

Reference for scale

The deployment is the reference point Secure60 uses for per-site ingest behaviour and storage-tiering patterns when scoping larger estates.

Scoping a High-Volume Estate

An architecture review covers ingest rate, retention, tiering and region placement for your environment.

30 days, every feature switched on. No credit card.