I will create splunk es detections and siem security use cases
Over deze dienst
Need help creating Splunk Enterprise Security detections or SIEM security use cases?
I am a Senior Splunk Engineer with 10+ years of IT experience and 8+ years of hands-on Splunk experience.
I specialize in Splunk Enterprise Security, security content engineering, detection engineering, SPL development and detection tuning.
I can help you build, troubleshoot and improve Splunk ES security detections based on your security requirements.
My Splunk ES services include:
Splunk ES detection creation
SIEM security use-case development
Correlation search development
Security detection engineering
Detection logic development
SPL development and optimization
Detection tuning
False-positive reduction
Scheduled security searches
Alert configuration
Risk-based detection logic
Data model and tstats-based detections
Lookup-based detections
Field extraction and validation
Security monitoring use cases
Existing detection troubleshooting
Detection documentation
I can work with security use cases involving:
AWS
CloudTrail
Microsoft/Azure
Windows
Linux
Network security
Firewall logs
Authentication activity
Endpoint security
Identity and access activity
Data exfiltration etc
Veelgestelde vragen
What information do you need to create a Splunk ES detection?
Please provide the detection requirement, expected behavior, relevant data source, available fields, sample events and any existing SPL or detection logic if available.
Can you create a Splunk ES detection from scratch?
Yes. I can develop detection logic and SPL based on your security requirement, available data and expected detection behavior.
Can you tune an existing Splunk ES detection?
Yes. I can review existing detection logic and help improve SPL efficiency, filtering and false-positive handling.
Can you create multiple security use cases?
Yes. Multiple detections can be included depending on the selected package. For larger detection projects, please contact me before ordering.
Can you work with Splunk data models and tstats?
Yes. I can develop detections using Splunk data models and tstats where the required data model and fields are available.
Do you need access to my Splunk environment?
Not necessarily. Many detections can be developed using requirements, sample events and field information. If environment access is required, a test or development environment is preferred.
Can you help reduce false positives?
Yes. I can review detection logic and recommend filtering, thresholds, exclusions and other tuning approaches based on the available event data.

