OT microsegmentation that feeds your SIEM.
How to deploy OT microsegmentation as an overlay, and send the alerts, flows, and audit events straight to your SIEM. No agents, no rewiring, no downtime.
To do OT microsegmentation in practice, you add an overlay next to your network. It splits the network into small zones and controls exactly which device can talk to which, on what protocol, and when. Every session is logged and sent to your SIEM. No agents on the equipment, no rewiring, no downtime. Trout Software's Access Gate works this way.
An overlay, four jobs
Discover
Finds every device and who it normally talks to, quietly, without disturbing fragile equipment. This is the baseline for your zones.
Zone
Splits the network into logical zones (IEC 62443 zones and conduits). Each zone has clear rules: which device, read or write, which protocol, which hours. No VLAN redesign.
Enforce
Checks every connection, ties it to a person, and allows only the flows you declared. Everything else is blocked and logged.
Feed the SIEM
Sends alerts, flows, and audit events to your SIEM over syslog, so your SOC finally sees what happens inside OT.
One design choice matters: the overlay runs next to the network, not in the middle of it. If the appliance goes down, production keeps running. See IEC 62443 zones and conduits and agentless Zero Trust for OT.
How it connects to your SIEM
Access Gate sends events over TCP syslog. Splunk, Elastic, IBM QRadar, and Microsoft Sentinel accept them out of the box, with no custom connector. You pick which detection rules forward, and each event carries four fields you can filter and alert on.
Event
What happened, in plain text.
Audit trail, incident timeline.
MITRE technique
The ATT&CK technique the rule maps to.
Threat detection.
Source
Who or what triggered it.
Attribution, alerting.
Rule
The detection rule that fired.
Filtering, saved alerts.
Setup is a syslog destination on the Access Gate side and a TCP input on the SIEM side. Because the events are identity-bound, they double as audit evidence for CMMC, NERC CIP, NIS2, and the New York DOH and DEC water rules. The step-by-step guides are linked at the bottom of this page.
Architecture and SIEM, answered
You add an overlay next to your existing network. It splits the network into small logical zones (aligned to IEC 62443 zones and conduits) and controls exactly which device can reach which, on what protocol, and during which hours. Every allowed flow is spelled out, and every blocked flow is logged. Because the overlay does not renumber the network or touch the equipment, you avoid the VLAN redesign and downtime a traditional segmentation project needs.
Access Gate sends its events to your SIEM over TCP syslog (RFC 5424). Splunk, Elastic, IBM QRadar, and Microsoft Sentinel accept them out of the box, with no custom connector. You choose which detection rules forward, and each event carries four fields: the event description, the MITRE ATT&CK technique, the source, and the rule that fired. That gives the SOC the OT context it usually lacks.
No. An overlay enforces segmentation at the network layer, so it needs no software on PLCs, HMIs, or SCADA servers. That matters in OT, where most controllers cannot run an agent and cannot be taken offline for one. Access Gate is agentless and deploys without rewiring or a maintenance window.
Alerts, flows, and audit events. In practice that is access and login alerts, session and flow records with full attribution, rule detections tagged with their MITRE ATT&CK technique, and blocked-flow events. Because the events are identity-bound, they are usable directly as audit evidence for CMMC, NERC CIP, NIS2, and the New York DOH and DEC water rules, not just for alerting.
Because the overlay needs no rewiring and no agents, a standard-sized site is usually protected in about three weeks: map the network and assets, define the zones and rules, enforce them, then point the event stream at the SIEM. You get visibility from day one and harden the zones step by step, without stopping production.
Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.
OT runs through you, not around you.