OpenSearch Deployment for Firewall Logs & VPN Traffic Analytics (Palo Alto, ASA, OVPN)

Job ID: 39554271

Budget: $250 – $750 USD

We're seeking a freelancer to help us stand up an OpenSearch (or Elasticsearch) logging and analytics solution that ingests firewall and VPN data from four different sites, consolidating into one searchable interface.

Phase 1: Setup + Ingestion

Deploy OpenSearch (preferred) or ElasticStack

Ingest logs via API from Palo Alto NGFW (PAN-OS) — multiple tenants

Ingest syslog/NetFlow or similar logs from 1 Cisco ASA device

Normalize logs for multi-site environment

Parse traffic logs to extract key data:

Top source IPs generating traffic

Internet usage per IP or per subnet

Application breakdown if available

Visualize via OpenSearch Dashboards or Kibana

Phase 2: VPN Audit Support

Track OpenVPN logs (we run a custom OpenVPN server stack with log output to file)

Parse and extract session details:

Username/IP mapping

Connect/disconnect time

Total session duration

Reconnect behavior

Ideal Skills:
Experience with OpenSearch or ELK deployments

Familiarity with Palo Alto API log ingestion (Panorama or individual firewalls)

Regex/Logstash/Pipeline work for parsing ASA logs and OpenVPN output

Dashboards for security/network metrics

Experience with multi-site log architecture a plus