Telemetry Sources: Logs, Network, Endpoint, and Historian Data
Detection is only as good as the telemetry feeding it, and OT environments have data sources that a conventional IT-focused SOC often overlooks entirely -- while also lacking some sources IT security teams take for granted, like widely deployed endpoint agents on legacy controllers.
Network telemetry is usually the richest and least intrusive source in OT, because passive network monitoring (via a network tap or span port) can observe traffic and protocol behavior without touching the controllers themselves -- critical, since many legacy devices cannot safely run additional software or tolerate active scanning. Deep packet inspection tuned for industrial protocols (Modbus, DNP3, OPC, and others) can reveal specific commands, not just traffic volume, which is what enables detection use cases like 'unauthorized write command to a specific register.'
Endpoint telemetry is available where it makes sense -- engineering workstations, HMIs, SCADA servers, and jump hosts typically run modern operating systems that can support logging and, where operationally appropriate, endpoint detection agents -- but should never be assumed available on the controllers and field devices themselves.
Historian data -- the time-series process data every industrial facility already collects for operational reasons -- is an underused security asset. Because historians already record process values over time, they can reveal physical-layer consequences of a cyber event (a pressure or flow reading that deviates in a way that correlates with a suspicious network event) that no purely cyber-focused telemetry source would catch on its own. Correlating cyber telemetry with process telemetry is one of the more advanced but genuinely valuable practices a mature OT SecureOPS program can build toward.
Reading
6 minutes