← Back to Projects
Business Systems House 2026
Enterprise Security Information & Event Management (SIEM) Tuning
SIEM FortiAnalyzer Syslog Parsing Event Correlation Rules Threat Triage Logrotate
Enterprise Security Information & Event Management (SIEM) Tuning
Optimized security event correlation rules within central SIEM logs to increase threat detection fidelity and reduce SOC alert fatigue.
Key Features & Implementation
- Custom Event Correlation Rules: Authored correlation rules detecting multiple failed logons followed by immediate successful administrative privilege use.
- False Positive Suppression: Suppressed benign system noise and automated service account alerts through precise white-scoping.
- Log Ingestion Parsing: Developed custom regex log parsers for non-standard application logs to map fields to standard SIEM schemas.