Security Telemetry on a Budget: Building a Practical Elastic Baseline for a Growing Product Team
Security Telemetry on a Budget How a growing product team turned the Elastic stack it already had into a practical security telemetry baseline — without buying a full SIEM first. DISCLAIMER: This is a real engagement from my professional practice and a project that was successfully completed. The client’s name and identifying details are not disclosed due to an NDA and confidentiality…
The client was a mid-sized software product company with roughly 70–100 engineers, developing applications, services and infrastructure in the cloud using Kubernetes. They already had a DevOps process in place, cloud and Kubernetes environments, application and platform logs, and an existing Elastic/ELK deployment for troubleshooting and monitoring.
However, they lacked a meaningful security telemetry baseline, meaning there was no consistent view of security-related events like failed logins, suspicious access patterns, unexpected container activities, or privilege changes.
The problem wasn’t the lack of data, but rather the lack of a security-focused approach to existing data. Security teams often excel at monitoring system health, but don’t typically have visibility into security-relevant behavior. Without a clear ownership model, signal quality and response process, a mature security program cannot be built on shaky foundations.
Rather than buying a commercial SIEM solution, which would have been expensive and required significant integration effort, the team adopted a pragmatic approach to build a security telemetry baseline using their existing stack. The solution focused on three key objectives: (1) identifying the most valuable security signals for minimal implementation cost, (2) creating a small set of prioritized alerts, and (3) establishing a shared dashboard for engineering and DevOps teams, along with lightweight incident response guidance and clear ownership rules.
The baseline focused on five practical security categories: identity & access, Kubernetes infrastructure warnings, application ingress events, host/system activity, and cloud activity. By prioritizing these signals, the team gained immediately useful visibility into important events without overwhelming them with excessive data.
The end result was a low-cost, low-friction security program that provided a solid foundation for further security initiatives while leveraging the capabilities of the already established Elastic stack.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.