Open-Source SIEM Architecture: Engineering Scalable Threat Visibility for Casinos and Critical Industries

By Jakson Winn
Cybersecurity Analyst, Doradus Labs

The modern casino floor represents one of the most complex technology environments in operation today. At any given moment, thousands of slot machines, table tracking systems, surveillance feeds, point of sale terminals, player loyalty platforms, and back office applications run side by side, processing data at speeds few other industries can match. Every transaction, every login, every network connection, every authentication request is a potential signal. The challenge is that the signal is buried beneath an enormous volume of normal operational noise. Without the right architecture in place to capture, correlate, and analyze that data, even seasoned security teams can find themselves reacting to threats long after the damage has been done.

This is precisely the problem that Security Information and Event Management, more commonly known as SIEM, was designed to solve. At Doradus Labs, we treat SIEM not as a single product to be purchased but as an engineered capability to be designed around an organization's actual operational reality. A well architected SIEM platform serves as the central nervous system of a cybersecurity program. It collects logs and telemetry from across the environment, applies detection logic, correlates events, and surfaces what matters most to the defenders who need to act on it. In high availability, high consequence environments such as casinos, hospitals, water utilities, and financial institutions, the difference between catching a threat early and discovering it after the fact can be measured in millions of dollars, regulatory exposure, and reputational harm that takes years to repair.

Over the past several months, our engineering team has been conducting structured research into open-source SIEM architectures, with a specific focus on building scalable, cost effective, and operationally sustainable solutions for Windows heavy enterprise environments and managed service provider deployments. The goal has not been to identify a single winning product. The goal has been to understand how modern open-source security tooling can be combined into modular platforms that scale gracefully, from a small property with a few dozen endpoints to a multi site enterprise managing thousands of users, servers, and network devices, without forcing organizations into expensive architectural redesigns every time their environment grows.

Why This Research Matters

The cybersecurity tooling market is saturated with commercial SIEM platforms, many of which carry licensing models priced per gigabyte of log ingestion or per endpoint monitored. For organizations operating at scale, those licensing curves quickly become punitive. A growing casino with new properties coming online, a regional hospital system expanding through acquisition, or a municipal utility extending sensors across new substations can find that the cost of visibility increases faster than the underlying operational footprint. Cost should not be the reason a critical environment lacks proper threat detection. Yet, in our experience, it often is.

Open-source SIEM technology offers an answer to that pricing problem, but only when it is engineered with discipline. The open-source ecosystem provides extraordinary capability, but capability is not the same as readiness. A pile of powerful tools is not a security platform. What separates a working SIEM from a collection of installed software is the architecture around it: the way data flows, the way detections are written, the way alerts are tuned, and the way the platform responds when an environment changes underneath it.

Design Considerations That Shaped the Work

Our research was guided by a set of operational priorities drawn directly from the realities our clients face. Endpoint visibility was the first consideration. In a Windows heavy environment, the volume and richness of data generated by workstations, servers, domain controllers, and authentication systems is enormous, and capturing it cleanly is the foundation of meaningful detection. Network based detection was the second pillar. Endpoint logs reveal a great deal, but threats that move laterally, communicate with command and control infrastructure, or exfiltrate data leave their clearest fingerprints on the wire. Forensic investigation capability followed closely. A SIEM that detects but cannot support a thorough investigation after the fact leaves defenders with only half of what they need.

Infrastructure cost and deployment complexity were treated as first class design constraints rather than afterthoughts. A platform that requires a small army of engineers to maintain may be technically impressive, but it will not survive contact with the operational realities of most organizations. Long term scalability was equally important. We deliberately favored designs that could be expanded by adding components rather than replaced wholesale. The architectural commitments made at the small business tier needed to remain valid at the enterprise tier, even as data volumes and detection requirements grew.

The Casino Industry as a Proving Ground

The casino industry provides one of the most demanding proving grounds for SIEM design that exists anywhere in the technology landscape. The reasons are structural. Casinos operate continuously, often for years at a time, with no maintenance windows in the conventional sense. They are subject to layered regulatory regimes that vary by jurisdiction and require strict controls over how systems are accessed, audited, and maintained. They process enormous volumes of financial transactions in real time. They integrate operational technology such as surveillance and floor systems with traditional information technology environments, creating a hybrid landscape that few other industries deal with at comparable scale. And they are persistent, attractive targets for adversaries ranging from opportunistic criminals to organized groups with significant resources.

Designing a SIEM architecture that succeeds in a casino environment means designing for uptime, for regulatory defensibility, for high data volume, and for hybrid IT and OT visibility from the very first whiteboard sketch. A platform that can hold its own on a casino floor is, almost by definition, a platform capable of serving other critical environments well.

Lessons That Extend Beyond Gaming

Although our research has been informed by deep operational experience in the gaming sector, the architectural patterns it has produced apply directly to several other industries that face similar pressures. Healthcare organizations operate around the clock, manage extraordinarily sensitive data, and must comply with strict regulatory frameworks. A hospital that loses visibility into its endpoints during a ransomware campaign is in the same operational position as a casino that loses visibility into its floor systems during a coordinated attack. The technical answer is much the same. Centralize the telemetry, write detections that reflect the real threat models, and ensure that defenders can act on what they see.

Financial institutions face their own version of the same problem. The combination of transaction velocity, regulatory scrutiny, and adversary interest places them in a category where the cost of poor visibility is measured not only in losses but in fines, audit findings, and lost customer trust. Critical infrastructure operators, including water utilities, energy providers, and transportation networks, increasingly find that their operational technology environments are exposed in ways they were never designed to handle, and that traditional IT security tools were not built for OT protocols, asset behaviors, or uptime expectations. A modular open-source SIEM architecture, engineered with these realities in mind, can extend meaningful visibility into environments that have historically been treated as too specialized for conventional monitoring.

Manufacturing, government, and education environments round out the list of sectors that benefit from this work. Each carries its own combination of constraints, threats, and regulatory expectations, but the underlying engineering questions are remarkably consistent. How do we collect the right data without overwhelming the platform? How do we write detections that produce signal rather than noise? How do we make the platform sustainable in the long run without trapping the organization into licensing models that punish growth? The answers we have developed for casinos translate, with thoughtful tailoring, to all of these industries.

Modularity as a Strategic Advantage

One of the most consistent findings from this research has been the value of modularity as a strategic principle. Security needs change. Environments grow. Threats evolve. A SIEM platform that has been designed as a monolith, with tightly coupled components and assumptions baked in at every layer, will eventually become an obstacle to the very security program it was meant to support. The modular architectures we have developed treat each functional layer, including log collection, event normalization, detection logic, alerting, storage, and investigation tooling, as a component that can be upgraded, replaced, or scaled independently of the others.

This approach has practical consequences that matter to organizations of every size. A small property can begin with a focused deployment that delivers strong endpoint and network visibility without significant initial investment. As the organization grows, additional components can be added, additional data sources brought online, and additional detection content layered in, all without forcing a return to the drawing board. The platform grows with the organization rather than against it.

What Comes Next

The next phase of our work involves deeper testing of the architectures we have designed, including validation against real world adversary techniques, refinement of detection content tuned for casino specific systems and processes, and continued evaluation of how these platforms perform under sustained operational load. We are also developing reference deployments for adjacent industries, beginning with water infrastructure and other operational technology environments where Doradus Labs has been deepening its presence.

Open-source SIEM is not a magic bullet. No technology is. But when it is engineered with discipline, deployed with care, and operated by professionals who understand the environment they are defending, it becomes one of the most powerful tools available to the modern security program. At Doradus Labs, we believe that strong visibility should not be a privilege reserved for the largest enterprises with the deepest pockets. It should be a baseline capability available to any organization that operates in a high consequence environment, regardless of size.

The casino floor is a uniquely demanding training ground. The lessons it teaches apply far beyond it. Our research will continue, and we look forward to sharing more as it advances.