An audit asks two things of every log: that it was collected, and that it has not changed since. A report built on a log that could have been edited proves little. PCI DSS v4.0.1 requires 12 months of audit log history, with the most recent three months immediately available for analysis.
Audit
PCI DSS Requirement 10.3 requires audit logs to be protected from modification. HIPAA requires audit controls that record activity in systems holding electronic health information, and protection of that information from improper alteration or destruction. Across frameworks, an auditor asks four things of the logs.
Scope
Logs from every system in scope, collected and readable.
Integrity
Proof that no log was altered or removed after it was written.
Retention
Records kept for the period the framework sets, and produced when asked.
Access
A record of who read each source, ran each search and changed each rule.
Integrity
A log the team could have edited proves little. An auditor, an insurer or a court has to check the record without trusting the team that produced it.
ARRTECH SIEM hashes and signs every write. Each signature file records the previous file’s name and hash, so a missing or altered file breaks the chain. Once a day a qualified timestamp authority stamps the signature files, and integrity is checked continuously and on demand.
Retention is set per source or per group, and logs are kept for at least two years. Archived logs stay searchable from the console. Any source exports with its signatures, the certificate and a standalone verification tool, so an auditor or a court verifies the logs without access to your SIEM.
Reports
Most audit requests repeat each period, and a report is only as complete as the sources behind it. A report built by hand has to be rebuilt every time.
ARRTECH SIEM collects from firewalls, servers, Active Directory, databases and cloud services by agent, syslog, WMI or SQL, and parses more than 500 log types. Unsupported sources get a parser at no charge under support.
Ready reports and dashboards for PCI DSS, HIPAA, GDPR, SOX, FISMA/NIST, ISO/IEC, KVKK, GLBA and NERC/CIP install from the Store, and any saved query becomes a report. Reports run on a schedule, down to every few minutes, and arrive by email as PDF, CSV, HTML, DOC or XLSX. A non-repudiation report lists every source by day, with any faulty file highlighted.
Data
GDPR, KVKK, HIPAA and PCI DSS cover personal, health and card data wherever it sits. A team has to know where that data lives before it can show an auditor how it is protected.
ARRTECH DLP discovery scans endpoints with its agent, and file servers and Oracle, MSSQL, MySQL and PostgreSQL databases without one, for national IDs, tax numbers, IBANs and card numbers, each checked by algorithm rather than pattern alone. Files are labeled, fingerprinted, copied to the console, moved or deleted by rule. Databases are inventoried. DLP events also feed the SIEM as a log source, so they sit in the same signed store as every other log.
Response
Compliance is your team’s call. Roles limit who reads each log source and each feature, and the console’s audit log records every login, search and configuration change. ARRTECH SOAR detects nothing on its own. When a SIEM alert needs action, a person decides, and SOAR runs the playbook, with every decision recorded in the run history.
Limits
What the suite does not do for an audit.
Certification
The products do not certify you. Ready reports and DLP classification support your compliance program, and your auditor assesses it.
Controls
ARRTECH SIEM does not track policies or control owners. It collects, signs and reports on logs.
Coverage
A report covers the sources that send logs to the SIEM. A system that sends nothing is missing from the evidence.
Evaluation
Bring one framework report your auditor asks for and one log source. In the first meeting you see that source collected and signed, the report run on schedule, and an exported source verified outside the SIEM.
Schedule a meetingSources
Products

Collects logs from more than 500 log types, signs and timestamps them, and ships ready reports for nine frameworks.

Finds national IDs, tax numbers, IBANs and card numbers on endpoints, file servers and databases, and stops them leaving.

Runs incident playbooks through API integrations, with a human decision built into the flow.