Skip to content
fernet.consultores

HomeMethod

A project shaped like a trace.

We organise it the way we organise the systems we observe: phases with a visible start, duration and dependencies. At every point you know what's being done, what comes next and what you'll get.

Before touching a single configuration, we understand what questions your organisation needs answered and what data you already have to answer them.

Who's involved
Operations and security leads and, at least once, someone from the business.
What we do
  • Short interviews per team
  • Inventory of sources, volumes and retention
  • Review of existing alerts and searches
You get
A map of sources and questions, showing what's queried today and what isn't.

45-minute sessions with each team. We ask which incidents cost them the most, and what data would have saved them time.

We cross-check licence usage against actual searches to see what's being indexed that nobody looks at. It's usually the project's first saving.

We decide what to measure and, above all, what to leave out. Every signal has a reason, an owner and a retention period.

What we do
  • Service-level indicators (SLIs) per critical service
  • Security use cases prioritised by risk
  • Naming conventions and shared attributes
You get
A prioritised signal catalogue and a phased instrumentation plan.

The longest phase, and the one that sets the pace of the project. It starts before the map is finished, because the first sources are already clear.

What we do
  • OpenTelemetry Collector in agent and gateway mode
  • Universal and Heavy Forwarders with official add-ons
  • Filtering and routing pipelines at source
You get
The platform in production, with all its configuration versioned in your repository.

Forwarders, collectors and filtering rules. Anything that doesn't add value is dropped or summarised before it reaches the index.

Auto-instrumentation with OpenTelemetry for Java, .NET, Node.js and Python, plus manual spans wherever the business needs them.

An alert nobody acts on is just noise with a different name. Here every signal becomes a decision: who acts, when and how.

What we do
  • SLOs with an error budget
  • Services, KPIs and episodes in ITSI
  • Security detections tested with simulations
You get
An alert catalogue with an owner, severity and response procedure for each one.

We measure success by how little you need us afterwards. Handover is part of the plan from day one, not an afterthought to be squeezed in if time allows.

What we do
  • Hands-on training with your own data
  • Supported on-call shifts
  • Architecture and operations documentation
You get
A team that operates, extends and defends the platform without us.

Indicative durations for a mid-sized platform. In red, the critical path: the phase that determines the delivery date.

Three ways to get started.

Express review

We review your platform, your ingestion costs and your alerts, and hand you a report with the highest-impact actions, ranked by effort.

For those who need to know where to start

Project

The five phases above, planned and approved one by one so that every stage has its own deliverable.

For deploying, migrating or rebuilding a platform

Ongoing support

A monthly block of architecture hours to review changes, refine detections and answer your team's questions, with no lock-in.

For teams already operating who want a second opinion

What you can expect from us.

A single technical point of contact

The person who designs the architecture is the same one who deploys it and explains it to you. No sales layer between your team and whoever touches the platform.

Everything in your repository

Configuration for collectors, forwarders, searches and alerts as code, versioned in your repository. What isn't written down isn't done.

Open standards before proprietary pieces

We use OpenTelemetry and the Common Information Model wherever possible. If you switch tools tomorrow, your instrumentation still works.

A planned exit

Handover is part of the plan from the first week. If we ever stop working together, your platform keeps running and your team knows why.

Start with listening.

A first thirty-minute conversation, no strings attached, to understand your context and tell you honestly whether we can help.

Request a conversation