I will set up wazuh, shuffle, iris soar for your soc
About this Gig
Tired of paying thousands for Splunk or QRadar licenses just to get basic visibility into your network? I build the same enterprise-grade monitoring using open-source tools and I actually run this stack myself, not just theory.
Here's what I set up for you: I deploy Wazuh as your central SIEM, then integrate Suricata and/or Zeek so you get real network-level detection not just endpoint logs. This means you see suspicious connections, intrusion attempts, and protocol anomalies, all correlated in one dashboard.
I also tune the decoders and rules so you're not drowning in noise from day one. A SIEM that alerts on everything is just as useless as one that alerts on nothing.
What you get:
Wazuh manager + agent deployment
Suricata and/or Zeek integration for network detection
Log forwarding and parsing setup
Custom rule/decoder tuning to reduce false positives
A working dashboard you can actually use
Who this is for:
Startups, small SOC teams, or businesses that want real network visibility without an enterprise budget. I'm also comfortable working at the infrastructure level I recently configured a full Dell PowerEdge T440 server from scratch.

