BusinessLOG
Thousands of organizations trust BusinessLOG to secure their IT
infrastructure and stay compliant with NIS2, GDPR, ISO 27001, DORA,
TISAX — with built-in SIEM, SOC, DLP, Asset Management, and IoT
Security.
On-premises software, agentless in Active Directory, supporting
log collection via Syslog, APIs, SNMP, and the BusinessLOG Agent.
Once you experience BusinessLOG, every other system will feel obsolete
Browse the complete platform through interactive screenshots. Click any image to view in full resolution.
SOC dashboard and AI security analysis
The Security Operation Center dashboard provides an executive and operational summary of the most relevant security findings detected across the monitored environment. BusinessLOG automatically highlights access anomalies, unusual authentication behavior, file activity issues, system weaknesses, and infrastructure risks, transforming raw data into a prioritized security overview. The SOC analysis also includes broader infrastructure insights, such as low disk space conditions, outdated systems, stale hosts, unsupported operating systems, and operational weaknesses that may increase security exposure.
Prioritized security overview for technical teams and decision-makers
Automated detection of access anomalies and authentication issues
Infrastructure weakness identification with remediation focus
Users and permissions management
BusinessLOG includes a granular users and permissions management system that allows administrators to define exactly which functions, archives, alarms, dashboards, and tools each operator can access. Permissions can be assigned in read-only, read-write, export-only, or enabled modes, ensuring that every user works within a controlled and well-defined operational perimeter. This feature is fundamental for segregation of duties, governance, accountability, and secure multi-user platform administration.
Granular role-based access control per function and archive
Read-only, read-write, export-only permission modes
Segregation of duties and accountability enforcement
Access Log – Main view
The Access Log section provides a centralized view of all access-related events collected by the system from Windows environments, Syslog sources, network devices, and heterogeneous infrastructures. The interface allows fast filtering by date, user, machine, source, category, event ID, and risk level, giving administrators and security analysts immediate visibility into recorded activity. This view is designed to simplify the investigation of remote access, password resets, SSH logins, Microsoft 365 activity, and suspicious authentication events.
Centralized view across Windows, Syslog, and cloud sources
Advanced filtering by date, user, machine, and risk level
Investigation of SSH, M365, and remote access events
Certified event detail view
BusinessLOG allows operators to open the documented detail of a single log event, displaying the selected record in a clear, structured, and exportable format. Each event includes all essential metadata, such as event type, ID, timestamp, category, source, machine, user, and session information, together with the original message collected by the platform. This feature is especially valuable for audits, forensic analysis, and compliance reviews, because it makes every event easy to validate, archive, and present as evidence.
Structured and exportable event documentation
Complete metadata for forensic analysis
Audit-ready evidence for compliance reviews
Intelligent log explanation
BusinessLOG enriches raw log data with an intelligent explanation layer that helps users understand what happened, why the event matters, and which actions should be taken. Instead of forcing the operator to manually interpret technical event codes, the platform transforms each log into a readable security assessment with contextual guidance. This capability extends to industrial IoT and OT-related Syslog events, helping security teams understand potentially sensitive activity involving industrial control protocols and critical devices.
AI-powered readable security assessments from raw logs
Contextual guidance with recommended actions
Industrial IoT and OT protocol interpretation
AI-powered incident report generation
The Incident Report module enables BusinessLOG to automatically generate a structured technical assessment starting from a selected user, machine, and time window. The system correlates the available logs, reconstructs the sequence of events, and produces a report that includes summary, classification, timeline, suspicious behaviors, impacted assets, and recommended actions. This function is ideal for SOC teams, MSPs, internal IT departments, and auditors who need a rapid and consistent first-level incident investigation.
Automated structured incident assessment
Timeline reconstruction with event correlation
Ideal for SOC teams, MSPs, and auditors
Incident report – Findings and indicators
BusinessLOG’s incident analysis goes beyond simple event listing by highlighting suspicious behaviors, relevant technical indicators, and affected assets. The platform helps analysts understand whether the observed activity may be linked to credential misuse, firewall manipulation, abnormal file activity, brute-force attempts, or privilege abuse. By consolidating these elements into a single structured report, BusinessLOG supports faster decision-making and more reliable technical validation.
Suspicious behavior and indicator highlighting
Credential misuse and privilege abuse detection
Consolidated findings for faster decision-making
Incident report – Recommended actions
At the end of the investigation workflow, BusinessLOG produces a set of prioritized technical recommendations tailored to the analyzed scenario. These actions may include host isolation, validation of firewall changes, credential review, privilege verification, forensic preservation, correlation with additional telemetry, and hardening measures. This transforms the platform from a pure log collection system into an operational decision-support tool for incident response and security governance.
Prioritized technical recommendations per scenario
Host isolation and forensic preservation guidance
Decision-support for incident response governance
Massive analysis of suspicious events
BusinessLOG also supports large-scale event review, allowing security teams to examine multiple suspicious entries in a single consolidated analysis workflow. The system correlates repeated failures, Azure sign-in anomalies, SharePoint or Graph access attempts, and related patterns that may indicate credential stuffing, password spraying, or misconfigured services. This capability is particularly useful when analysts need to quickly distinguish isolated errors from broader attack patterns affecting multiple users or services.
Large-scale consolidated event analysis
Credential stuffing and password spraying detection
Azure, SharePoint, and Graph anomaly correlation
Event alarms configuration
The Event Alarms module allows administrators to configure detection rules for strategic security events, defining frequency, active time windows, execution conditions, and associated response logic. Rules can be applied to specific event IDs and tuned according to operational requirements, making it possible to detect potentially malicious behavior in real time. This functionality enables BusinessLOG to act proactively, not just as a repository of logs, but as a true monitoring and alerting platform.
Custom detection rules with configurable frequency
Active time windows and execution conditions
Real-time proactive threat monitoring
File alarms configuration
The File Alarms section makes it possible to monitor sensitive folders, files, and paths, generating alerts when specific operations are performed. Administrators can define whether to track read, write, delete, denied access, or all file activities, and optionally limit monitoring to selected users or machines. This is a critical feature for protecting shared folders, confidential documents, regulated archives, and business-critical repositories.
Sensitive folder and file path monitoring
Track read, write, delete, and denied access operations
User and machine-level filtering
Software alarms configuration
With Software Alarms, BusinessLOG can detect software installation, update, and removal events across monitored endpoints. This allows organizations to identify unauthorized tools, potentially dangerous programs, suspicious utilities, or software changes that could impact security posture or compliance. The feature is especially useful for controlling shadow IT, preventing risky applications, and enforcing software governance policies.
Software installation and removal detection
Shadow IT and unauthorized tool identification
Software governance policy enforcement
File access auditing
The Log Access Files archive provides detailed visibility into file activity, including opened, modified, and deleted objects. Each record is associated with timestamp, source, path, machine, user, and session identifiers, allowing analysts to reconstruct who accessed a file, when the action occurred, and what operation was performed. This is extremely valuable in audit scenarios, internal investigations, and compliance contexts where document traceability is required.
Complete file activity tracking (open, modify, delete)
Full traceability with user, machine, and session data
Essential for audit and compliance documentation
USB activity auditing
The USB Access List tracks removable media activity, including insertion events and file operations executed through connected USB devices. BusinessLOG records the executable involved, the source file, the machine, the user, and the exact action performed, giving security teams a clear view of potential data transfers to external storage. This feature is essential for preventing data leakage, enforcing removable-media policies, and supporting internal security controls.
USB insertion and file operation tracking
Data leakage prevention via removable media
Detailed executable and source file logging
Process auditing
The Process Log module records executed processes and elevation-related activity, offering visibility into which executables ran on monitored systems and under which privilege context. This helps administrators identify suspicious binaries, privilege escalation attempts, unknown processes, or unexpected execution paths that may indicate malicious activity or policy violations. It is a powerful capability for deeper endpoint visibility, especially when combined with user, machine, and authentication data.
Process execution and privilege escalation tracking
Suspicious binary and unknown process detection
Deep endpoint visibility with authentication context
Print activity auditing
The Print Logs section monitors printing activity by tracking documents, printers, targets, users, and endpoints involved in each print event. This allows organizations to identify sensitive documents that have been printed, understand who initiated the action, and maintain visibility over a frequently overlooked channel of information leakage. Print auditing is particularly useful in regulated environments where document handling must be traceable and accountable.
Document and printer activity monitoring
Information leakage prevention via print tracking
Traceable document handling for regulated environments
Failed access analysis
The Fails Access List centralizes failed authentication attempts and login anomalies, making it easier to identify brute-force behavior, invalid credentials, unknown accounts, and abnormal access patterns. From this view, operators can immediately inspect the event, create an alarm, print a certified record, or launch an AI-supported external IP analysis. This makes the module highly effective for fast triage and early detection of suspicious access activity.
Brute-force and invalid credential detection
AI-supported external IP analysis
One-click alarm creation and certified record printing
Syslog auditing
The Syslog Access List collects and organizes events generated by network devices, firewalls, NAS systems, Linux hosts, and other third-party appliances. BusinessLOG classifies these logs by area, source, category, user, machine, and risk indicators, allowing the platform to normalize heterogeneous data into a single operational view. This is a key capability for organizations that need centralized visibility across mixed infrastructures and multi-vendor environments.
Multi-vendor device log collection and normalization
Firewalls, NAS, Linux, and third-party appliance support
Unified operational view across heterogeneous infrastructure
Antivirus / EDR / XDR / MDR events
BusinessLOG can also ingest and correlate security events generated by antivirus, EDR, XDR, and MDR solutions, providing a centralized archive of detected threats and remediation actions. In the example shown, the system highlights malware detections, severity levels, engines involved, affected files, and contextual explanation of the threat. This allows analysts to manage endpoint protection alerts alongside all other infrastructure logs within a single platform.
Centralized antivirus, EDR, XDR, and MDR event archive
Malware detection with severity and engine correlation
Single platform for endpoint protection and log management
Local user discovery and account visibility
The Local User List provides a structured view of user accounts detected on monitored machines, including local administrators, guest accounts, built-in profiles, and standard users. For each account, BusinessLOG displays group membership, activation status, first detection date, password change history, and password expiration settings, making it easier to identify weak account configurations or outdated credentials. This feature is especially useful for hardening endpoints, reviewing local privilege assignments, and detecting accounts that may increase security exposure if left unmanaged.
Local admin, guest, and built-in account discovery
Password change history and expiration tracking
Endpoint hardening and privilege review
Shared folders and permissions overview
The Shares List allows administrators to review network shares detected across the infrastructure, including shared paths, associated devices, assigned users or groups, domains, and effective permissions. By consolidating this information into a single view, BusinessLOG helps identify overexposed shared folders, excessive permissions, and risky configurations that may facilitate unauthorized access or lateral movement. This module is particularly valuable for file security reviews, internal audits, and access governance assessments.
Network share discovery with effective permissions
Overexposed folder and excessive permission detection
Access governance for internal audits
Custom dashboard builder
BusinessLOG includes a flexible Custom Dashboard builder that allows users to create personalized visual reports using charts, cards, tables, pies, gauges, maps, and other analytical widgets. Operators can select data sources, apply filters, define aggregations, and configure visual layouts to transform raw log data into tailored dashboards for technical analysis, management reporting, or customer presentation. This feature enables every organization to build the exact visual monitoring layer it needs, without relying on external BI platforms.
Drag-and-drop charts, gauges, maps, and tables
Custom data sources, filters, and aggregations
No external BI platform required
AI-assisted pattern parser generation
The Pattern Generation module helps administrators create and refine parsing rules for heterogeneous Syslog data, using assisted logic to recognize device identifiers, event types, variable fields, and correlation fields. This allows BusinessLOG to normalize previously unknown log formats and convert them into structured, actionable security events. The result is faster onboarding of new devices and more accurate interpretation of third-party logs, even in complex multi-vendor environments.
AI-assisted Syslog parsing rule creation
Automatic device and field recognition
Faster onboarding of new log sources
Security Operation Center AI message center
The Security Operation Center AI view centralizes system-generated security messages and operational checks, highlighting issues such as expired passwords, foreign IP access, failed logins, file deletions, new machine detection, and out-of-hours activity. BusinessLOG automatically classifies and groups these alerts, making it easier for analysts to focus on the most relevant findings and quickly investigate suspicious conditions. This module acts as an intelligent operational console for continuous security supervision.
Centralized AI-classified security alerts
Expired password and foreign IP detection
Intelligent console for continuous supervision
Automatic CVE checking and vulnerability correlation
The CVE and Software Matching Report automatically correlates detected software versions with publicly known vulnerabilities, helping organizations understand whether installed applications may be affected by recent CVEs. For each finding, BusinessLOG reports the host, software name, version, CVE identifier, CVSS score, publication date, severity, and source references, turning inventory data into practical vulnerability intelligence. This feature supports faster patching priorities, improved exposure assessment, and more proactive vulnerability management.
Automatic CVE correlation with installed software
CVSS score, severity, and source references
Proactive patching priority and exposure assessment
AI-assisted remote PowerShell execution
The Send PowerShell Command module allows administrators to remotely execute PowerShell actions on selected machines, with support for reusable templates and AI-assisted command preparation. This makes it possible to automate administrative tasks such as restarting services, forcing Group Policy refresh, installing software, or launching maintenance routines across multiple endpoints from a single console. The feature combines operational efficiency with centralized control, making BusinessLOG not only a monitoring platform but also a practical response and management tool.
AI-assisted PowerShell command preparation
Reusable templates for common operations
Remote execution across multiple endpoints
Machine list and infrastructure visibility
The Machines List gives a centralized overview of all detected endpoints and servers, including IP address, role, CPU, operating system, user, last activity, RT agent status, software version, and warning indicators. Color-coded health and status indicators help operators quickly identify critical systems, outdated agents, suspicious conditions, or machines requiring immediate attention. This view is fundamental for maintaining real-time awareness of the monitored infrastructure.
Centralized endpoint and server overview
Color-coded health and status indicators
Real-time infrastructure awareness
Machine technical detail sheet
The Technical Details panel provides a complete profile of a selected machine, including role, operating system, hardware details, free disk space, last user, scan status, log volume, update history, and operating parameters. From this single interface, administrators can access related information such as software inventory, hardware inventory, updates, local users, sessions, scheduled actions, energy consumption, CVE reports, and shared resources. This creates a unified operational workspace for endpoint management, diagnostics, and security review.
Complete machine profile in a single view
Access to inventory, CVE, sessions, and energy data
Unified workspace for endpoint management
Per-machine CVE detail report
BusinessLOG can generate a CVE detail report for a single machine, focusing on the vulnerabilities associated with the software installed on that specific endpoint. The report includes affected products, versions, CVE references, severity levels, publication dates, and short mitigation guidance, allowing analysts to understand risk at the individual host level. This targeted approach helps prioritize remediation where it matters most and simplifies vulnerability review during audits and technical assessments.
Per-endpoint vulnerability detail report
Mitigation guidance per CVE finding
Targeted remediation prioritization
Device diagnostic and connectivity test
The Diagnostics Report verifies the technical health and reachability of a device by testing key parameters such as DNS resolution, ping response, critical TCP ports, CPU load, RAM availability, free disk space, firewall status, and event log accessibility. BusinessLOG presents the outcome in a clear pass/fail format, enabling administrators to immediately identify configuration issues, connectivity problems, or conditions that could affect monitoring reliability. This feature is particularly useful during onboarding, troubleshooting, and validation of monitored hosts.
DNS, ping, TCP ports, and firewall testing
Clear pass/fail diagnostic format
Ideal for onboarding and troubleshooting
Network flowchart and infrastructure mapping
The Network FlowChart visually maps the monitored infrastructure, displaying servers, workstations, standalone systems, and domain-connected devices in a graphical layout. This representation helps administrators understand the structure of the environment at a glance, identify key nodes, and export the resulting diagram in PNG or PDF format for documentation or presentation purposes. It is a valuable feature for technical audits, project planning, compliance reporting, and customer-facing infrastructure overviews.
Visual infrastructure mapping with device topology
PNG and PDF export for documentation
Useful for audits and compliance reporting
Software inventory and version comparison
The Software Inventory module collects and displays installed applications across monitored endpoints, including product name, type, installed version, available version, vendor, detection date, and installation path. By highlighting version gaps and outdated software, BusinessLOG helps organizations identify missing updates, obsolete applications, and software lifecycle issues that may impact security or operational stability. This module is essential for asset management, compliance control, and update planning.
Installed vs. available version comparison
Outdated software and lifecycle issue detection
Essential for compliance and update planning
Hardware inventory and technical asset details
The Hardware Inventory provides a structured view of endpoint and server hardware details, including BIOS data, CPU model, network adapters, connected USB devices, operating system attributes, and other system-level components. BusinessLOG stores both detection date and last observed timestamp, allowing organizations to keep track of asset evolution over time. This capability supports asset governance, configuration review, and hardware-related audit processes.
BIOS, CPU, network adapter, and USB device tracking
Asset evolution over time with detection timestamps
Hardware audit and configuration review support
Energy consumption monitoring
The Energy Consumption module estimates power usage for monitored machines by analyzing the utilization of key hardware components such as CPU, GPU, RAM, and disks. BusinessLOG presents both per-device values and visual trends over time, enabling administrators to compare systems, identify higher-consumption endpoints, and gain a more complete operational view of infrastructure efficiency. This feature is particularly useful for sustainability reporting, cost awareness, and device optimization initiatives.
Per-device power usage estimation (CPU, GPU, RAM, disk)
Visual consumption trends over time
Sustainability reporting and cost optimization
Windows update monitoring
The System Updates section tracks Windows update activity across monitored endpoints, showing whether specific updates were downloaded, installed, or deployed successfully. Each record includes the update title, description, deployment status, and support URL, giving administrators a consolidated view of patching progress and missing updates. This helps improve patch management governance and supports security teams in verifying whether critical updates are actually being applied.
Update download, install, and deployment tracking
Consolidated patching progress view
Critical update verification for security teams
AI virtual assistant / RAG-based guidance
BusinessLOG also includes an AI virtual assistant designed to answer user questions based on the available documentation and product knowledge base. In the example shown, the assistant provides step-by-step guidance for connecting an Azure tenant, combining conversational interaction with structured technical instructions. This feature improves usability, reduces training effort, and gives operators immediate access to contextual product support directly within the platform.
RAG-powered virtual assistant with product knowledge
Step-by-step contextual guidance
Reduced training effort and improved usability
Notification channels and Telegram integration
The Notifications Settings section allows BusinessLOG to manage outbound alert delivery through multiple communication channels, including email and Telegram. Administrators can configure daily notes, test message delivery, define subjects, and link the platform to a Telegram bot and chat ID in order to receive security notifications in real time. This feature ensures that critical events and operational alerts can be delivered quickly to the right people, improving responsiveness and keeping security teams continuously informed.
Email and Telegram alert delivery
Configurable daily notes and test messages
Real-time notification to security teams
Plugins, RT Server, SQL audit, AS400 and Defender integration
BusinessLOG includes a modular Plugin Configuration area that enables the activation of additional connectors and monitoring capabilities according to the customer’s environment. From this section, administrators can enable integrations such as FileMaker, the BusinessLOG RT server, Windows Defender logging, SQL Server auditing, and AS400 log imports, extending the platform beyond standard event collection. This modular approach allows BusinessLOG to adapt to complex infrastructures and vertical use cases while maintaining centralized control from a single interface.
Modular plugin activation per environment
FileMaker, SQL Server, AS400, and Defender connectors
Centralized control for complex infrastructures
Syslog, CVE thresholds and network scan configuration
The System Configuration panel also includes advanced controls for Syslog reception, vulnerability filtering, and network discovery. Administrators can enable UDP or TLS Syslog listeners, define the minimum CVE score to consider, set the time window for recent vulnerabilities, and configure IP ranges for network scans and asset detection. These settings make it possible to tailor BusinessLOG to the organization’s risk model, infrastructure size, and preferred level of monitoring depth.
UDP and TLS Syslog listener configuration
CVE score thresholds and vulnerability time windows
IP range-based network scanning and asset detection
Azure and cloud archive configuration
The Cloud Configuration section allows BusinessLOG to connect with Microsoft Azure for cloud log collection and to activate external cloud-based archival services. Through Azure tenant parameters such as client ID and tenant ID, the platform can import cloud-originated logs, while the dedicated cloud archive option makes it possible to store log-access data in an isolated external environment. This capability is particularly valuable for hybrid infrastructures, Microsoft 365 monitoring, and organizations that require externalized archival for security, resilience, or compliance reasons.
Azure tenant integration for cloud log collection
External cloud-based log archival
Microsoft 365 and hybrid infrastructure support
CPU and processing thread optimization
BusinessLOG provides granular control over scan and processing thread allocation, allowing administrators to tune the number of concurrent threads used for collection and log processing based on available hardware resources. The platform shows available cores, suggested values, and separate controls for scanning and queue processing, helping optimize performance without overloading the host system. This configuration is especially useful in high-volume environments where performance, responsiveness, and resource balancing are critical.
Granular thread allocation for scan and processing
Hardware-aware suggested values
Optimized for high-volume environments
General settings, retention policies and service account management
The General Settings area centralizes core platform behaviors such as domain identification, software and hardware inventory activation, archive viewer enablement, and service-level retention policies. Administrators can define how long logs should be retained, whether remote machine logs should be deleted after a configured period, and which account the BusinessLOG service should use to operate. This section is essential for balancing operational efficiency, storage management, and compliance-driven retention requirements.
Configurable log retention policies
Service account and domain management
Compliance-driven storage governance
XML archives, backup, localization and email notification settings
BusinessLOG also includes settings for secondary XML storage, automated backups, localization, working hours, and SMTP email delivery. These options allow organizations to generate structured XML archives, configure backup paths, set the platform language, define standard business hours for anomaly detection, and manage the credentials used to send system notifications. Together, these controls strengthen resilience, simplify administration, and make the platform easier to align with local operational and compliance needs.
Automated XML archival and backup configuration
Localization, working hours, and SMTP setup
Resilience and compliance alignment
Regulatory Report – Automated compliance output for audits
The Regulatory Report module automatically prepares a structured compliance output designed to support audits and regulatory assessments across multiple frameworks. It collects, organizes, and presents all the key technical and operational information that auditors, compliance officers, and security teams typically need — from user and administrator data, machines and asset inventory, shared resources, alarms, software inventory, vulnerability data, endpoint security events, access and security logs, to configuration details useful for control verification. The result is a compliance-oriented output that helps organizations demonstrate the presence of controls, identify possible gaps, and prepare documentation for internal reviews, external audits, and certification processes.
Automated evidence collection across users, assets, logs, and configurations
Supports GDPR, ISO 27001, NIS2, DORA, TISAX, SOC 2, and NIST 800
Reduces manual audit preparation and improves organizational readiness
Agentless, all features, full compliance.
Recommended for regulatory compliance only.
Externally managed SOC for MSPs and resellers
BusinessLOG's on-premises agent collects security data across the entire customer infrastructure and streams it securely to a cloud management portal. MSPs, resellers, and external SOC teams can monitor alerts, manage licenses, activate AI-powered reporting, and deliver security assessments — all without requiring direct access to the customer's network. This model combines the privacy and control of on-premises data collection with the scalability and convenience of cloud-based service delivery.
Centralized multi-tenant security dashboard for external providers
On-premises data collection with secure cloud streaming
Self-service license and subscription management for partners
One-click SOC and AI Report activation per customer
AI-generated reports with prioritized remediation actions
Automatic CVE matching and vulnerability analysis
Get a demo of BusinessLOG
Experience the full power of BusinessLOG with our free demo. Deploy in minutes and see real-time log management, compliance automation, and AI-powered threat detection in action.