About the Client
The client is a U.S.-based financial services technology provider delivering industry-leading payments infrastructure, core banking software and tailored solutions to strengthen payments capabilities.
They use multiple HPE Nonstop servers for mission-critical services in a highly available technology environment and have been using CSP’s security solutions for over 15 years to secure the systems and comply with regulatory requirements.
For confidentiality reasons, the client’s name and any operational metrics are not disclosed in this case study.
Objectives
As part of its commitment to maintaining secure, highly available payment services, the client sought to improve visibility into events generated by its Hardware Security Modules (HSMs), and Enterprise Security Key Managers (ESKMs) connected to the Nonstop environment.
A key objective was to obtain better visibility into HSM status and activity, particularly during software upgrades where events and failures may not be readily visible in conventional HSM log files.
To address these requirements, they wanted to collect syslog messages from multiple sources and make those messages available to its existing monitoring environment.
Challenges
There were some challenges making it difficult to obtain the required information:
- Segmented Network – HSM’s & ESKM’s were only connected to Nonstop server
- Restrictions – Cannot send events directly from HSM to a SIEM
- Lack of visibility – Hardware or Power failures discovered very late, especially for backup HSM’s.
- Troubleshooting – Limited visibility and no real-time view during software upgrades
- Lack of Notifications – No email alerts to Nonstop users for critical issues
Key Requirements
- Receive SYSLOG messages and forward to EMS & SIEM
- Real-time Monitoring of HSM Health and Status
- Support Multiple Devices like HSM’s, EKSM’s and others
- Support Multiple Protocols like TCP/IP and UDP
- Get email alerts for critical issues
- All Devices need dedicated EMS collectors for easier monitoring
The CSP Solution
The CSP Syslog Receiver is an OSS Gateway tool for Nonstop servers that receives syslog messages from multiple sources, including Hardware Security Modules and Enterprise Security Key Managers, and forwards them to EMS collectors and Security Information & Event Managers (SIEM).
The solution provided the client with:
- Real-time visibility into messages generated by HSMs and other syslog sources
- Support for both TCP/IP and UDP protocols
- The ability to consolidate messages from multiple syslog sources
- The ability to specify a dedicated EMS collector for syslog messages
- The ability to run as a Pathway process
- The ability to forward syslog messages to external SIEM systems such as Splunk
- A simple configuration model using a YAML configuration file
- Quick installation and setup
- A simple operating model with no GUI to install
Implementation
The CSP Syslog Receiver was implemented within the client’s Nonstop environment to receive messages from its security and infrastructure devices and delivered major benefits like:
- Improved insight into HSM’s and Enterprise Security Key Managers
- Increased visibility and awareness of devices connected to the Nonstop environment
- Real-time insight into the HSM software update process and status
- Improved ability to identify and troubleshoot upgrade issues and failures
- Greater awareness of critical hardware and power-failure messages
- Integration of syslog information with existing enterprise monitoring and SIEM infrastructure
The result was a straightforward mechanism for bringing security-device and infrastructure events into the client’s existing monitoring environment.
Conclusion
The client has strengthened visibility across its mission-critical Nonstop environment with the implementation of CSP Syslog Receiver.
By receiving critical messages from Hardware Security modules & Enterprise Security Key Managers, and forwarding them to EMS or external SIEM systems, the solution provides the client with greater awareness of security and infrastructure events.
The result is improved visibility, enhanced operational awareness, and better support for managing and troubleshooting critical payment infrastructure.