Independent enterprise technology-change research

PT-2026-097 · dossier edition · 23 July 2026

PlatformTrace

Enterprise platform migrations, examined in public.

security platform migration · Completed SIEM transition · High confidence

OMV replaces legacy on-premises SIEM with Microsoft Sentinel

OMV replaced its legacy on-premises SIEM with Microsoft Sentinel as the SOC foundation.

Organisation
OMV Aktiengesellschaft
Predecessor
Legacy on-premises SIEM unable to meet scale and threat-landscape requirements
Destination
Microsoft Sentinel integrated with Defender XDR and Azure Data Explorer
Workload
Enterprise security monitoring, detection, investigation, incident response and more than 5 TB of daily security data
Stage
Completed SIEM transition
Retirement status
The legacy on-premises SIEM was replaced for the named SOC scope; its product name and exact retirement date are not published.
Confidence
High
Next trigger
A named predecessor disclosure or later AI, Zero Trust or DLP production milestone.
Evidence boundary: The source supports replacement of the legacy SIEM for the named SOC scope. It does not complete later AI, Zero Trust or data-loss-prevention initiatives.

Programme context

OMV replaced its legacy on-premises SIEM with Microsoft Sentinel as the SOC foundation.

Why this matters: The record identifies a named organisation, an explicit predecessor and destination platform, and a bounded workload and lifecycle stage.

Migration timeline

Date or stageMilestoneWhat changedEvidence status
Legacy constraintMigration milestoneThe on-premises SIEM could not keep pace with required scale and the threat landscape.Source-stated source state
Production transitionMigration milestoneMicrosoft Sentinel became the SOC foundation.Source-stated completed state
13 Jan 2026Migration milestoneMicrosoft published the current customer account.Dated primary evidence

Workload migration matrix

WorkloadPredecessorDestinationStatus by 23 Jul 2026
Enterprise security monitoring, detection, investigation, incident response and more than 5 TB of daily security dataLegacy on-premises SIEM unable to meet scale and threat-landscape requirementsMicrosoft Sentinel integrated with Defender XDR and Azure Data ExplorerCompleted SIEM transition

Implementation and architecture

  • Microsoft Sentinel provides the SOC foundation.
  • Defender XDR and Azure Data Explorer support investigation and security-data processing.
  • AI, Zero Trust and data-loss-prevention initiatives remain separate later work.

Known unknowns and contradictions

  • The predecessor SIEM product name.
  • The exact cutover and retirement date.
  • Residual legacy monitoring components outside the named SOC scope.

No missing fact is inferred to broaden the source-supported migration claim.

PlatformTrace analysis

The source supports replacement of the legacy SIEM for the named SOC scope. It does not complete later AI, Zero Trust or data-loss-prevention initiatives.

Performance, cost, uptime and operational outcomes remain attributed source claims unless independently stated otherwise.

Evidence ledger

  1. Microsoft customer story, 13 January 2026

    Named OMV personnel identify the legacy on-premises SIEM, Sentinel target, Defender and Azure Data Explorer integration and current 5 TB-plus daily operating scale.

Approval: Issue #47 standing-authority publication queue.

Corrections and updates

23 July 2026 — Initial Verified dossier published from the complete five-lane overnight intake and corrected central adjudication. Later milestones will be appended rather than silently replacing this state.