A SIEM, Security Information and Event Management platform, is the central nervous system of an ISP's security operations programme. It aggregates log data from across the infrastructure, correlates events to identify suspicious patterns, and provides the evidence trail that CTDISR-2025 compliance and nTSOC integration both depend on. Selecting the wrong platform creates compliance risk, operational pain, and a migration project later when the platform cannot scale or integrate correctly.

For Pakistani ISPs, SIEM selection has specific constraints that differ from the generic enterprise SIEM evaluation: nTSOC integration requirements, the specific log sources present in a Pakistani ISP environment (MikroTik, FreeRADIUS, Zabbix, Splynx), and the budget reality of most operators in the market.

What CTDISR-2025 Requires from a SIEM

CTDISR-2025 does not name specific SIEM products or platforms. What it requires is the capability to: collect and retain logs from all critical infrastructure components (Section 9 and Section 17), detect and alert on security events in near-real-time (Section 5 and Section 6), forward qualifying events to nTSOC in the required format (Section 6), and produce evidence of security event monitoring that an auditor can verify (Section 17).

These requirements define the functional specification for SIEM selection regardless of which platform delivers them.

The Non-Negotiable Capabilities

Log collection from MikroTik RouterOS is the first test. Most enterprise SIEMs are built around Windows event logs and Linux syslog sources from enterprise vendors. MikroTik sends standard syslog, which any SIEM should accept, but the parsing of MikroTik-specific log formats (firewall filter hits, BGP session events, DHCP leases, authentication events) requires either native MikroTik parsing support or the ability to create custom parsers. Verify MikroTik parser quality specifically, not just generic syslog support.

FreeRADIUS accounting log ingestion is the second critical source. RADIUS accounting records are your subscriber authentication and session evidence, essential for both security monitoring and lawful intercept logging. The SIEM needs to ingest FreeRADIUS log format or the database that FreeRADIUS writes to, and correlate subscriber IPs against authentication records.

nTSOC integration requires the ability to forward selected event types in the format PTA's nTSOC expects. At the time of writing, confirm the current required format with PTA's CS directorate, as it has evolved as nTSOC infrastructure matured. Your SIEM needs to support that output format, either natively or through a forwarding configuration.

Log retention for at least 12 months is required for CTDISR audit evidence. Verify that the platform supports hot retention of this duration at your expected log volume without cost that makes the platform unviable.

Platforms Worth Evaluating

Wazuh is an open-source SIEM and XDR platform that is the most commonly deployable option for Pakistani ISPs without enterprise security budgets. It handles syslog ingestion from MikroTik and other sources, provides correlation rules, generates alerts, and has active community development around new integrations. The management overhead of a self-hosted Wazuh deployment is real but manageable for an operator with internal Linux administration capability. It does not have commercial support unless you engage a managed service provider, which is a consideration for operators without security engineering depth.

Graylog is a log management platform with SIEM capabilities. It excels at log aggregation and search at high volume, has good syslog ingestion, and is deployable on modest infrastructure. Its correlation and alerting capabilities are less mature than dedicated SIEMs but are adequate for CTDISR compliance monitoring. Also open-source with a commercial enterprise option.

Elastic SIEM (built on the Elasticsearch stack) provides sophisticated correlation and detection rules, strong log ingestion pipeline (via Logstash and Beats agents), and good visualisation. The operational complexity of running an Elastic stack at scale is higher than Wazuh or Graylog, and storage costs for large log volumes can be significant.

Commercial cloud-hosted options from Microsoft (Microsoft Sentinel) and others eliminate the operational burden of self-hosting but introduce data sovereignty considerations: subscriber log data sent to a foreign cloud service needs to be assessed against Section 7's data localisation requirements.

What to Avoid

Avoid platforms that cannot ingest your actual log sources. A SIEM selected based on a vendor presentation that has never been tested against MikroTik syslog and FreeRADIUS logs will create integration work after purchase.

Avoid platforms where log retention costs make 12-month retention economically unviable. Some commercial SIEMs charge per GB of log ingestion: at ISP log volumes (thousands of RADIUS accounting records per day, continuous syslog from dozens of routers), per-GB pricing can become very expensive very quickly.

For operators who need SIEM selection, deployment, and nTSOC integration handled as a managed engagement rather than an internal project, nTSOC Integration covers the full integration from SIEM selection through acceptance testing. For the broader security programme design that the SIEM is one component of, Cybersecurity for ISPs covers the full security architecture.