Elastic SIEM Setup & Training
Budget: ₹750 – ₹1,250 INR
I’m rolling out Elastic SIEM in a cloud-first architecture and need an experienced partner to accelerate the build, tune detections, and up-skill my analysts before hand-off.
Scope
• Data onboarding – configure Filebeat/Logstash or native integrations to pull AWS CloudTrail & VPC Flow, O365 audit logs, and Fortinet firewall traffic into Elasticsearch.
• Threat intelligence – wire in both open-source feeds (e.g., Abuse IPDB, AlienVault OTX) and my licensed commercial feeds so they enrich events on ingest and power correlation rules.
• SOC visibility – craft Kibana dashboards that give at-a-glance health for endpoints, perimeter, identity, and cloud resources, along with drill-downs for investigation.
• Detection engineering – map alert rules to MITRE ATT&CK, fine-tune thresholds, and set up multi-channel notifications (email, Slack, PagerDuty).
• Knowledge transfer – run live workshops and deliver concise runbooks so my team can own the platform after go-live.
Please include in your proposal:
1. Examples or screenshots of Elastic or Kibana dashboards you’ve built for similar cloud deployments.
2. A phased timeline from kickoff to production handover (my target window is four weeks but I’m flexible for quality).
3. Your commercial model—fixed fee with milestones, T&M, or a hybrid—and how you normally structure post-implementation support.
Hands-on experience with Elastic Cloud, Beats, Logstash pipelines, Kibana Lens, and Detection Rules API is essential. If you’ve previously integrated AWS and Microsoft security data or maintained Fortinet parsers, highlight that as well.
I’m ready to begin as soon as I find the right fit.
Scope
• Data onboarding – configure Filebeat/Logstash or native integrations to pull AWS CloudTrail & VPC Flow, O365 audit logs, and Fortinet firewall traffic into Elasticsearch.
• Threat intelligence – wire in both open-source feeds (e.g., Abuse IPDB, AlienVault OTX) and my licensed commercial feeds so they enrich events on ingest and power correlation rules.
• SOC visibility – craft Kibana dashboards that give at-a-glance health for endpoints, perimeter, identity, and cloud resources, along with drill-downs for investigation.
• Detection engineering – map alert rules to MITRE ATT&CK, fine-tune thresholds, and set up multi-channel notifications (email, Slack, PagerDuty).
• Knowledge transfer – run live workshops and deliver concise runbooks so my team can own the platform after go-live.
Please include in your proposal:
1. Examples or screenshots of Elastic or Kibana dashboards you’ve built for similar cloud deployments.
2. A phased timeline from kickoff to production handover (my target window is four weeks but I’m flexible for quality).
3. Your commercial model—fixed fee with milestones, T&M, or a hybrid—and how you normally structure post-implementation support.
Hands-on experience with Elastic Cloud, Beats, Logstash pipelines, Kibana Lens, and Detection Rules API is essential. If you’ve previously integrated AWS and Microsoft security data or maintained Fortinet parsers, highlight that as well.
I’m ready to begin as soon as I find the right fit.
Related categories:
Linux
Cloud Computing
Amazon Web Services
Hadoop
Workshops
Data Integration
Cloud Security
Kibana