OpenSearch Deployment for Firewall Logs & VPN Traffic Analytics (Palo Alto, ASA, OVPN)
Budget: $250 – $750 USD
We're seeking a freelancer to help us stand up an OpenSearch (or Elasticsearch) logging and analytics solution that ingests firewall and VPN data from four different sites, consolidating into one searchable interface.
Phase 1: Setup + Ingestion
Deploy OpenSearch (preferred) or ElasticStack
Ingest logs via API from Palo Alto NGFW (PAN-OS) — multiple tenants
Ingest syslog/NetFlow or similar logs from 1 Cisco ASA device
Normalize logs for multi-site environment
Parse traffic logs to extract key data:
Top source IPs generating traffic
Internet usage per IP or per subnet
Application breakdown if available
Visualize via OpenSearch Dashboards or Kibana
Phase 2: VPN Audit Support
Track OpenVPN logs (we run a custom OpenVPN server stack with log output to file)
Parse and extract session details:
Username/IP mapping
Connect/disconnect time
Total session duration
Reconnect behavior
Ideal Skills:
Experience with OpenSearch or ELK deployments
Familiarity with Palo Alto API log ingestion (Panorama or individual firewalls)
Regex/Logstash/Pipeline work for parsing ASA logs and OpenVPN output
Dashboards for security/network metrics
Experience with multi-site log architecture a plus
Phase 1: Setup + Ingestion
Deploy OpenSearch (preferred) or ElasticStack
Ingest logs via API from Palo Alto NGFW (PAN-OS) — multiple tenants
Ingest syslog/NetFlow or similar logs from 1 Cisco ASA device
Normalize logs for multi-site environment
Parse traffic logs to extract key data:
Top source IPs generating traffic
Internet usage per IP or per subnet
Application breakdown if available
Visualize via OpenSearch Dashboards or Kibana
Phase 2: VPN Audit Support
Track OpenVPN logs (we run a custom OpenVPN server stack with log output to file)
Parse and extract session details:
Username/IP mapping
Connect/disconnect time
Total session duration
Reconnect behavior
Ideal Skills:
Experience with OpenSearch or ELK deployments
Familiarity with Palo Alto API log ingestion (Panorama or individual firewalls)
Regex/Logstash/Pipeline work for parsing ASA logs and OpenVPN output
Dashboards for security/network metrics
Experience with multi-site log architecture a plus