Most SIEM deployments fail not because of bad tools but because of poor configuration, untested detection rules, and log pipelines that drop data silently.
I deploy and configure SIEM infrastructure from scratch or fix what is already broken.
What I Can Deploy and Engineer:
- Elastic Stack deployment single node to multi-node cluster, Fleet server, Elastic Agents, different log sources onboarding and on demanded integration
- Wazuh deployment manager setup, agent deployment, rule tuning, demanded integration
- Log ingestion pipeline design Windows, Linux, network, cloud, and application sources
- Index lifecycle management (ILM), data tiering (Hot, Warm, Cold, Frozen), and storage reduction techniques.
- Detection rule library custom KQL, EQL, and Sigma rules for your environment
- ML jobs anomaly detection for user behavior, network traffic, and system activity
- Threat intelligence integration MISP, OpenCTI, Cortex, VirusTotal feed integration,
- Observability stack Grafana, Prometheus, Graphite, Icinga2 monitoring and dashboards.
- Asset and vulnerability management Nanitor deployment and integration
- Infrastructure automation Ansible and SaltStack configuration management