Log collection
OT logs flowing from firewalls, switches, servers, a jump host, SCADA and historian systems and an OT network IDS into a log collector and a sender proxy inside the OT network, across a one-way hardware data diode with no reverse connection, to a DMZ receiver proxy, a SIEM and security analyst review, with the log protocols (syslog over TLS on TCP 6514, legacy UDP 514, vendor agent over TLS).