FortiSIEM Log Review & Tuning

Job ID: 40515234

Budget: ₹600 – ₹1,500 INR

My FortiSIEM installation ingests a large volume of security logs and I need it to surface only the events that matter—specifically intrusion attempts, unauthorized access, and malware detection. Your task is to dive into these security logs, review current alerts, fine-tune thresholds, create any missing correlation rules, and build or update parsers so every useful field is captured.

Here’s the workflow I have in mind: first, you’ll analyse a recent log sample and come back with a short gap-analysis that highlights noisy alerts and blind spots. Next, you’ll implement the agreed changes directly in FortiSIEM: adjust policies, write correlation rules, update regexes or parsers, and validate with fresh log traffic. Finally, you’ll provide concise documentation so I can follow exactly what was changed and why.

Deliverables
• Gap-analysis report covering intrusion, unauthorized access and malware events
• Tuned alert policies with before/after alert counts
• New or updated correlation rules (.xml or GUI-export)
• Custom parsers with test logs and successful field extraction screenshots
• One-page hand-off document summarising steps to roll back or extend your work

Acceptance criteria
• False positives on the three priority alert types reduced by at least 50 % in a 7-day sample
• No critical security event missed during validation tests
• All parsers pass built-in FortiSIEM validation without warnings

Include a detailed project proposal when you reply so I understand your approach, tools or scripts you rely on, and the timeline you expect for each milestone.