Back to Projects
Business Systems House 2026

Enterprise Security Information & Event Management (SIEM) Tuning

Enterprise Security Information & Event Management (SIEM) Tuning
SIEM FortiAnalyzer Syslog Parsing Event Correlation Rules Threat Triage Logrotate

Enterprise Security Information & Event Management (SIEM) Tuning

Optimized security event correlation rules within central SIEM logs to increase threat detection fidelity and reduce SOC alert fatigue.

Key Features & Implementation

  • Custom Event Correlation Rules: Authored correlation rules detecting multiple failed logons followed by immediate successful administrative privilege use.
  • False Positive Suppression: Suppressed benign system noise and automated service account alerts through precise white-scoping.
  • Log Ingestion Parsing: Developed custom regex log parsers for non-standard application logs to map fields to standard SIEM schemas.
ROOT ACCESS GRANTED