- Organisation
- OMV Aktiengesellschaft
- Predecessor
- Legacy on-premises SIEM unable to meet scale and threat-landscape requirements
- Destination
- Microsoft Sentinel integrated with Defender XDR and Azure Data Explorer
- Workload
- Enterprise security monitoring, detection, investigation, incident response and more than 5 TB of daily security data
- Stage
- Completed SIEM transition
- Retirement status
- The legacy on-premises SIEM was replaced for the named SOC scope; its product name and exact retirement date are not published.
- Confidence
- High
- Next trigger
- A named predecessor disclosure or later AI, Zero Trust or DLP production milestone.
Programme context
OMV replaced its legacy on-premises SIEM with Microsoft Sentinel as the SOC foundation.
Why this matters: The record identifies a named organisation, an explicit predecessor and destination platform, and a bounded workload and lifecycle stage.
Migration timeline
| Date or stage | Milestone | What changed | Evidence status |
|---|---|---|---|
| Legacy constraint | Migration milestone | The on-premises SIEM could not keep pace with required scale and the threat landscape. | Source-stated source state |
| Production transition | Migration milestone | Microsoft Sentinel became the SOC foundation. | Source-stated completed state |
| 13 Jan 2026 | Migration milestone | Microsoft published the current customer account. | Dated primary evidence |
Workload migration matrix
| Workload | Predecessor | Destination | Status by 23 Jul 2026 |
|---|---|---|---|
| Enterprise security monitoring, detection, investigation, incident response and more than 5 TB of daily security data | Legacy on-premises SIEM unable to meet scale and threat-landscape requirements | Microsoft Sentinel integrated with Defender XDR and Azure Data Explorer | Completed SIEM transition |
Implementation and architecture
- Microsoft Sentinel provides the SOC foundation.
- Defender XDR and Azure Data Explorer support investigation and security-data processing.
- AI, Zero Trust and data-loss-prevention initiatives remain separate later work.
Known unknowns and contradictions
- The predecessor SIEM product name.
- The exact cutover and retirement date.
- Residual legacy monitoring components outside the named SOC scope.
No missing fact is inferred to broaden the source-supported migration claim.
PlatformTrace analysis
The source supports replacement of the legacy SIEM for the named SOC scope. It does not complete later AI, Zero Trust or data-loss-prevention initiatives.
Performance, cost, uptime and operational outcomes remain attributed source claims unless independently stated otherwise.
Evidence ledger
- Microsoft customer story, 13 January 2026
Named OMV personnel identify the legacy on-premises SIEM, Sentinel target, Defender and Azure Data Explorer integration and current 5 TB-plus daily operating scale.
Corrections and updates
23 July 2026 — Initial Verified dossier published from the complete five-lane overnight intake and corrected central adjudication. Later milestones will be appended rather than silently replacing this state.