Is small with limited resources and needs a centralized logging capability;
Does not have a Security Operations Center, Security Information and Event Management solution, or any active monitoring functions currently in place;
Has small, isolated networks where your existing corporate monitoring practices cannot reach; or
Needs a capability to gather logs and monitor your enterprise’s information technology but lacks resources.