Every device on an organization's network — servers, switches, firewalls, web application firewalls, storage systems, NAS — constantly generates events. Without bringing these events together in one place, it's nearly impossible for a security team to answer the question “what's happening right now.” With Cybersecurity Law No. 7545, which took effect on March 19, 2025, this visibility has stopped being optional for organizations classified as critical infrastructure and become a regulatory requirement.
OrianaLOG is a domestic log management and SIEM infrastructure built precisely for this need; OrianaSIEM, built on top of it, extends this foundation into a full threat detection and response experience. In this article we look at what OrianaLOG is, what problem it solves, and what features set it apart as a SIEM product — based directly on the product itself.
What Is OrianaLOG?
OrianaLOG is a log management platform that centrally collects, stores, and analyzes events occurring on the devices and software across a digital infrastructure. Network or security administrators can monitor logs from different sources in a single panel, tracking events, intrusion attempts, or system issues from there. The product's focus can be summarized under three headings:
• Centralized visibility: Bringing together logs from different sources — servers, switches, firewalls, WAFs, storage, NAS, and operating systems — in a single panel.
• Real-time analysis: Processing events as they're generated, so anomalies are caught without delay.
• Regulatory compliance: Storing log data, and preserving its integrity, in a way that can be accepted without question during an audit.
1. One Shot Correlation: An Alternative to Complex Rule Management
In classic SIEM products, correlation rules are usually built on multi-step scenarios that depend on one another. This structure is powerful, but it takes time to set up and maintain; a SOC team spends a significant share of its time fine-tuning rules.
OrianaLOG takes a different approach here: One Shot Correlation — in other words, a one-rule–one-event–one-trigger logic. The system generates an alert the moment a given event occurs, without waiting for predefined chained conditions. According to the manufacturer's own description, example scenarios include:
• Unauthorized file-sharing attempts
• Suspicious or unusual network traffic
• Unauthorized software installation attempts
• Failed login attempts
• Data encryption attempts (a possible ransomware indicator)
In practice, this approach means catching basic but critical threat scenarios without going through lengthy rule-engineering processes. For scenarios that require deeper, behavioral analysis, UEBA (user and entity behavior analytics) and risk scoring at the OrianaSIEM layer come into play — and MITRE ATT&CK alignment, which we touched on in our earlier article, is exactly the kind of question organizations should put to the vendor at this layer.
2. Deduplication: A Detail That Affects Performance and Cost
As log volume grows, storage cost and query performance become critical. OrianaLOG works with a minimization algorithm that deduplicates repeated data. The manufacturer states that this optimizes disk space usage and speeds up search/query operations across large data sets. However, no independent test data showing the concrete magnitude of this improvement (e.g., compression percentage, events-per-second processing capacity) is available in public sources; validating these figures against their own log volumes during a proof-of-concept (POC) is the most concrete step organizations can take before deciding.
3. Regulatory Compliance: Law No. 5651, KVKK, GDPR, and Law No. 7545
OrianaLOG was developed with Turkey's own regulatory framework in mind: Law No. 5651, Electronic Signature Law No. 5070, KVKK (Turkey's data protection law), and GDPR. On the OrianaSIEM side, this scope extends to sectoral/international frameworks such as PCI DSS, ISO 27001, and NIS2.
We covered how serious this regulatory burden is, with figures, in our earlier article “Turkey’s Cybersecurity Regulations and Domestic SIEM”: failing to cooperate with an audit can result in an administrative fine of up to 5% of audited annual gross sales revenue; fines for violating specific obligations can range between 1 million TL and 100 million TL.
One point needs to be clarified here: Law No. 7545 does not contain a provision titled “obligation to use a SIEM.” What the law introduces is an obligation for critical infrastructure providers to use authorized suppliers, and a general principle of priority for domestic/national products; how this translates to SIEM procurement will become clear through the secondary legislation and the current list of authorized suppliers to be published by the Cybersecurity Authority. So rather than “OrianaLOG is a legally mandated choice,” it's more accurate to say “OrianaLOG is a candidate that could ease the procurement process for organizations classified as critical infrastructure.”
Verifying and signing log integrity, and managing retention periods, is one of the areas where teams lose the most time during an audit. Law No. 5651 sets a minimum-maximum retention window, while KVKK requires the destruction of data once it has served its purpose and its retention period has expired; the automated retention/destruction configuration the manufacturer describes for OrianaLOG aims to satisfy both obligations at once.
4. Flexible Deployment Options: On-Premise, Cloud, Appliance, Docker
OrianaLOG was developed to be multi-platform and can be deployed across different operating systems. Thanks to Docker support, organizations with container-based infrastructure can also integrate OrianaLOG into their own environments.
• On-premise: For public sector, financial, and critical infrastructure organizations where data sovereignty is a priority — the scenario, covered in our earlier article, where KVKK's cross-border transfer safeguard burden is removed from the outset.
• Cloud: For teams that want a quick start and don't want to invest in infrastructure.
• Appliance: For small IT teams that want to simplify the setup process.
A multi-tenant architecture, RBAC, and SSO/LDAP integration also address the needs of MSSPs and multi-branch organizations.
5. Beyond Basic Log Management: Additional Capabilities
OrianaLOG isn't just a tool for collecting and storing logs. The product also includes the following capabilities:
• Cyber threat intelligence integration: Sharing of IP-, hash-, and address-based access blocklists.
• Guest network management: Captive portal support that works with LDAP, national ID authentication, SMS, or voucher verification methods.
• Hit-count monitoring: Continuous monitoring of systems by detecting day-to-day changes.
6. Moving to OrianaSIEM: UEBA, MITRE ATT&CK, and SOAR
The log infrastructure that OrianaLOG collects and normalizes is taken to the next level with OrianaSIEM:
• Real-time event analysis and automated response workflows
• UEBA-based behavioral analysis and risk scoring
• MITRE ATT&CK-aligned threat analysis
• Automation through SOAR integration
This layered structure lets an organization deepen its capabilities within the same platform as its needs grow, without having to switch to a new product. In a reference case published by the manufacturer, the CTO of a payment services company states that they can detect attacks early and meet the log/SIEM needs of payment-systems regulations on a single platform; since this is the only concrete customer reference publicly available, it shouldn't be generalized on its own, but it can be a starting point for requesting references from similar sectors during a POC.
What to Look at When Evaluating OrianaLOG
Every criterion we listed in our earlier article under “What to Watch for When Moving to a Domestic SIEM” — scalability, MITRE ATT&CK alignment, integration capacity, reference projects, support SLAs — applies here as well. Specifically for OrianaLOG, it's also worth paying attention to:
• Log volume and scalability: Choosing the deployment model (on-premise, cloud, appliance) based on the organization's current and projected log volume, and testing the deduplication ratio with its own data during a POC.
• Integration scope: Confirming connector compatibility with the existing firewall, WAF, NAS, and other devices.
• Authorized-supplier status: If the organization has critical infrastructure status, verifying alignment with the current authorized-supplier list under Law No. 7545 — by checking the Cybersecurity Authority's official source, not by taking the claim at face value.
• Domestic/national product certification: Asking the manufacturer directly which official document, if any, backs the “domestic and national” claim; the information in this article does not include independent verification on this point.
• Growth plan: Assessing whether a future move to OrianaSIEM's UEBA and SOAR layer will be needed.
Conclusion: Simplicity and Regulatory Compliance, Together, with OrianaLOG
What sets OrianaLOG apart isn't a single “headline feature,” but a combination of complementary elements: the One Shot Correlation approach that reduces complexity, a deduplication algorithm that — according to the manufacturer's claims — lowers cost, a compliance structure designed from the ground up around Turkish regulation, and flexible deployment options that adapt to an organization's size. Together with OrianaSIEM, this foundation becomes a full threat detection and response platform.
But the point we emphasized in our two earlier articles bears repeating here: regulatory compliance is a technology-agnostic obligation — in theory, it can be met with any SIEM. Before choosing OrianaLOG, organizations should keep in mind that the information in this article is vendor-sourced, and shouldn't skip the steps of a POC, reference checks, and confirming authorized-supplier status.
Frequently Asked Questions
Which devices can OrianaLOG collect logs from?
It can collect logs from a wide range of devices, including servers, switches, firewalls, web application firewalls, storage, NAS, and operating systems.
Does OrianaLOG run on Docker?
Yes — its multi-platform architecture means it can be installed and used in environments that have Docker.
What's the difference between One Shot Correlation and classic correlation?
Classic correlation requires multi-step, interdependent rules, while One Shot Correlation works on a one-rule–one-event logic, reducing setup and maintenance complexity.
What's the difference between OrianaLOG and OrianaSIEM?
OrianaLOG focuses on core log collection, centralized management, and regulatory compliance. OrianaSIEM adds real-time correlation, UEBA, MITRE ATT&CK-aligned analysis, and SOAR integration on top of that.
Does OrianaLOG satisfy the authorized-supplier obligation under Law No. 7545?
The law doesn't regulate this obligation at the individual product level, but through the supplier list the Cybersecurity Authority will approve. OrianaLOG states that it's a domestic solution developed with Turkey's regulatory framework in mind; organizations with critical infrastructure status are advised to separately confirm the current supplier list and their own obligations through the Cybersecurity Authority's official announcements.
Next Step: Trying OrianaLOG
To test OrianaLOG in your own infrastructure or to request a demo of OrianaSIEM, you can reach out to our team. Taking inventory of your existing log sources and clarifying your regulatory obligations based on your critical infrastructure status — in line with the practical compliance steps we recommended in our regulatory article — will be the first step toward a sound roadmap.