Aviz Networks details federal logging gap under OMB M-21-31
Federal agencies are being urged to supplement device and application logs with packet-derived telemetry as they work toward the event logging maturity levels outlined in OMB M-21-31 and NIST SP 800-92r1. The post argues that wire-level visibility can help address gaps left by compromised endpoints and incomplete log sources while fitting into existing SIEM and observability stacks. ## Research Overview Federal agencies have invested in SIEM platforms, log pipelines, and compliance processes, but the post says those layers alone have not prevented long-running intrusions. It links the push for stronger logging practices to OMB M-21-31 and to the SolarWinds and Microsoft Exchange incidents. The article says the memo defines three maturity levels for civilian agencies: EL1 for basic network-based events and passive DNS, EL2 for encrypted traffic visibility, and EL3 for East-West traffic and orchestration. It also notes that the implementation deadline has passed. ## Key Findings The post says device and application logs can be altered or deleted after an attacker gains control of a system, which limits their reliability as the only source of evidence. It points to MITRE ATT&CK techniques for suppressing audit records and logging. It also says packet-derived telemetry is collected off the wire, outside the control of endpoints. According to the post, this makes the data less vulnerable to tampering even if a host is compromised. ## Technical Breakdown The article describes packet brokers and wire capture as a source of telemetry that is independent of device-generated logs. It says that when traffic is captured at the wire level, metadata can still reach SIEM and observability tools even if endpoint logging is disabled or wiped. For EL1, the post ties compliance to syslog flow data and non-intrusive DNS monitoring. For EL2, it says visibility into encrypted traffic is required, and for EL3 it says the challenge is visibility into internal East-West traffic between hosts, containers, and cloud instances. ### Product Update The post says Aviz Deep Network Observability provides continuous, wire-level, packet-derived telemetry without requiring agencies to replace existing SIEM or IDS tools. It says the product ingests traffic through Tap or SPAN from datacenters, hybrid cloud, edge, and remote environments. It further says the system can send optimized raw packets to inspection tools and packet-derived metadata to SIEM and observability platforms in common formats. The post cites examples from a deployed customer environment, including East-West attacks, expired SSL certificates in encrypted traffic, unapproved AI platform usage, and anomalous DNS queries. ## Operational Impact The post says agencies that have reached EL1 or EL2 on paper but still lack East-West visibility have not fully closed the network visibility gap. It argues that logging improvements alone cannot deliver EL3 or the telemetry assurance described in NIST SP 800-92r1. It presents wire-level packet capture as a way to support both logging maturity and zero-trust efforts without displacing current tools. The post says the approach is intended to add trusted network data to existing security and observability workflows. The article centers on federal logging maturity, network visibility, and packet-derived telemetry for agencies working under OMB M-21-31 and NIST SP 800-92r1. For enterprise decision-makers in federal IT and security, the Blog Signals brief provides a fact-based summary of the vendor blog.