How Traditional Bank reduced investigation time with Log360

About Traditional Bank
Traditional Bank is an independent community bank with deep roots in Kentucky that date back to 1902. The bank has grown organically through long-standing customer relationships and referrals, combining personal service with customer-focused technology to support individuals, businesses, and local communities.
-
Organization
Traditional Bank -
Country
United States -
Industry
Banking
Breaking down the business requirements
Traditional Bank needed stronger visibility into identity-related activity across its environment. As a community bank, the security team’s priority was understanding what was happening inside Active Directory and being alerted immediately when sensitive actions occurred.
The team needed to track account creation, administrative group changes, and account lockouts, and it needed to know who performed those actions and why. The bank already followed a checklist-based process for onboarding users, so the real challenge was identifying activity that did not align with approved internal requests.
Before adopting Log360, Traditional Bank used SolarWinds Security Event Manager. While the product met the bank's functional needs, it required extensive rule writing and became significantly more expensive after a pricing model change. This combination of rising costs and operational complexity led the team to look for an alternative SIEM solution.
Jerry Trimmer, IT cybersecurity officer at Traditional Bank, described what the team was looking for:
"We wanted to be able to audit Active Directory for sure… We wanted to know when somebody was added to the main admins group or to any kind of admin group, and we also wanted to know when accounts were locked out and why they were locked out."
Choosing ManageEngine Log360
During the evaluation process, ease of use emerged as a key factor for Traditional Bank. The team needed a SIEM solution that could deliver real-time alerts and Active Directory reporting without requiring heavy customization or ongoing rule management.
Log360 provided the same core capabilities the bank relied on previously, but in a more accessible way. Alerts were easier to configure, reports were simple to pull, and the overall interface made it easy to understand what was happening in the environment without spending excessive time navigating the product.
For Trimmer’s team, the simplicity of Log360 made an immediate difference compared to the bank's previous solution.
"The two reasons we selected Log360—one was price and the other was ease of use. It seems very easy to get around, get the reports you need, and set up alerts."
Use case: Monitoring Active Directory for unexpected activity
One of the primary ways Traditional Bank uses Log360 is to identify activity that does not align with internal business processes. When employees join the bank, account creation follows a defined checklist. Any deviation from that process needs immediate attention.
With Log360 in place, the security team receives real-time alerts when accounts are created, privileges are modified, or users are added to administrative groups. If an alert matches an expected request, it can be quickly validated. If it does not, the team can investigate who performed the action and why.
This approach allows the team to focus on exceptions rather than reviewing every routine event, reducing noise while improving security response.
Trimmer explained how this visibility supports day-to-day security operations:
"If an account gets created that’s not on our checklist, the solution helps us understand things like who created it and why."
Streamlined implementation with expert guidance
Log360 was deployed on-premises and implemented in a short timeframe with the help of OnboardPro, ManageEngine's implementation service. Afshaan, the implementation manager, led the onboarding process and worked closely with the bank’s team during setup.
Rather than simply installing the product, Afshaan walked the team through each step, explaining how to add devices, configure alerts, and generate reports. This hands-on approach allowed the team to learn the platform during implementation instead of after go-live. As a result, Log360 was fully operational within just a couple of days.
Resolving early challenges during onboarding
During implementation, the team encountered a small number of issues, including a licensing concern and a certificate-related problem that affected emergency email notifications. These issues were addressed quickly with Afshaan’s support.
Because the problem was familiar to him, Afshaan was able to identify the cause and resolve it without delay, ensuring that the solution continued functioning as expected.
Trimmer recalled how the issue was handled:
"There was a bug; a certificate problem. He knew exactly what to do. He got in there, jumped in, and fixed it real quick."
Outcomes and improvements
With Log360 in place, Traditional Bank has improved both its security posture and operational efficiency. The team now receives immediate alerts for potentially risky actions, allowing technicians to respond quickly and confidently.
Instead of investigating every alert, the team focuses only on activity that does not align with approved processes. This has reduced investigation time and helped the team concentrate on real security concerns rather than routine events.
Trimmer explained how this change in alerts has improved daily operations:
"It cuts down on having to research every one of them. We just have to research the ones that don’t align with our business practices."
Overall experience and recommendation
From evaluation through implementation, the experience with Log360 and ManageEngine’s onboarding services was straightforward and efficient. The product was easy to set up, intuitive to use, and supported by responsive, knowledgeable guidance.
Based on the bank’s previous SIEM experience and current needs, Trimmer rated Log360 highly and expressed strong confidence in the solution.
Looking ahead
Traditional Bank is currently evaluating additional ManageEngine products, including Remote Access Plus. Pricing and on-premises deployment remain important factors as the bank considers expanding its IT and security tooling.
For now, Log360 plays a central role in helping the bank maintain visibility into Active Directory activity, respond quickly to anomalies, and strengthen its overall security posture.
About OnboardPro
OnboardPro is a ManageEngine service that provides solution implementation to clients upon request. This service includes the installation and customized configuration of ManageEngine solutions. It enables clients to seamlessly begin work without worrying about the complexities of product installation, deployment, and use. Every client environment is unique and requires additional support beyond the basic installation and standard features. With custom onboarding, clients have the option to engage a team of product experts to manage the installation, implementation, customization, and training based on their business needs. For more information, visit manageengine.com/onboarding/manageengine-onboardpro-iam-and-siem-professional-service.html.
About Log360
Log360 is a unified SIEM solution with integrated DLP and CASB capabilities that detects, prioritizes, investigates, and responds to security threats. Vigil IQ, the solution's TDIR module, combines threat intelligence, an analytical Incident Workbench, ML-based anomaly detection, and rule-based attack detection techniques to detect sophisticated attacks, and it offers an incident management console for effective remediation. With reengineered detection—including a centralized detection console, multi-mode rule creation, tuning insights, and object-level filters—Log360 elevates signal quality and reduces false positives. The solution provides holistic visibility across on-premises, cloud, and hybrid environments with intuitive security analytics and monitoring. For more information about Log360, visit manageengine.com/log-management/ and follow the LinkedIn page for regular updates.
Log360 is a unified SIEM solution with integrated DLP and CASB capabilities that detects, prioritizes, investigates, and responds to security threats. It combines threat intelligence, machine learning-based anomaly detection, and rule-based attack detection techniques to detect sophisticated attacks, and offers an incident management console for effectively remediating detected threats. Log360 provides holistic security visibility across on-premises, cloud, and hybrid networks with its intuitive and advanced security analytics and monitoring capabilities.
Product Documents
Others
2022 Zoho Corporation Pvt. Ltd. All rights reserved.
