TroutTrout

OT microsegmentation that feeds your SIEM.

How to deploy OT microsegmentation as an overlay, and send the alerts, flows, and audit events straight to your SIEM. No agents, no rewiring, no downtime.

The short answer

To do OT microsegmentation in practice, you add an overlay next to your network. It splits the network into small zones and controls exactly which device can talk to which, on what protocol, and when. Every session is logged and sent to your SIEM. No agents on the equipment, no rewiring, no downtime. Trout Software's Access Gate works this way.

The architecture

An overlay, four jobs

Discover

Finds every device and who it normally talks to, quietly, without disturbing fragile equipment. This is the baseline for your zones.

Zone

Splits the network into logical zones (IEC 62443 zones and conduits). Each zone has clear rules: which device, read or write, which protocol, which hours. No VLAN redesign.

Enforce

Checks every connection, ties it to a person, and allows only the flows you declared. Everything else is blocked and logged.

Feed the SIEM

Sends alerts, flows, and audit events to your SIEM over syslog, so your SOC finally sees what happens inside OT.

One design choice matters: the overlay runs next to the network, not in the middle of it. If the appliance goes down, production keeps running. See IEC 62443 zones and conduits and agentless Zero Trust for OT.

SIEM integration

How it connects to your SIEM

Access Gate sends events over TCP syslog. Splunk, Elastic, IBM QRadar, and Microsoft Sentinel accept them out of the box, with no custom connector. You pick which detection rules forward, and each event carries four fields you can filter and alert on.

Event

What happened, in plain text.

Audit trail, incident timeline.

MITRE technique

The ATT&CK technique the rule maps to.

Threat detection.

Source

Who or what triggered it.

Attribution, alerting.

Rule

The detection rule that fired.

Filtering, saved alerts.

Setup is a syslog destination on the Access Gate side and a TCP input on the SIEM side. Because the events are identity-bound, they double as audit evidence for CMMC, NERC CIP, NIS2, and the New York DOH and DEC water rules. The step-by-step guides are linked at the bottom of this page.

Questions

Architecture and SIEM, answered

You add an overlay next to your existing network. It splits the network into small logical zones (aligned to IEC 62443 zones and conduits) and controls exactly which device can reach which, on what protocol, and during which hours. Every allowed flow is spelled out, and every blocked flow is logged. Because the overlay does not renumber the network or touch the equipment, you avoid the VLAN redesign and downtime a traditional segmentation project needs.

Access Gate sends its events to your SIEM over TCP syslog (RFC 5424). Splunk, Elastic, IBM QRadar, and Microsoft Sentinel accept them out of the box, with no custom connector. You choose which detection rules forward, and each event carries four fields: the event description, the MITRE ATT&CK technique, the source, and the rule that fired. That gives the SOC the OT context it usually lacks.

No. An overlay enforces segmentation at the network layer, so it needs no software on PLCs, HMIs, or SCADA servers. That matters in OT, where most controllers cannot run an agent and cannot be taken offline for one. Access Gate is agentless and deploys without rewiring or a maintenance window.

Alerts, flows, and audit events. In practice that is access and login alerts, session and flow records with full attribution, rule detections tagged with their MITRE ATT&CK technique, and blocked-flow events. Because the events are identity-bound, they are usable directly as audit evidence for CMMC, NERC CIP, NIS2, and the New York DOH and DEC water rules, not just for alerting.

Because the overlay needs no rewiring and no agents, a standard-sized site is usually protected in about three weeks: map the network and assets, define the zones and rules, enforce them, then point the event stream at the SIEM. You get visibility from day one and harden the zones step by step, without stopping production.

The second layer of value

Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.

OT runs through you, not around you.