Wazuh & Splunk Log Management

Job ID: 40196282

Budget: ₹12,500 – ₹37,500 INR

I’m building out a small SOC stack and need an expert to wire Wazuh and Splunk together so I get clean, searchable logs from my firewalls. The core goal is streamlined log management—no SIEM correlation rules, threat-hunting work, or incident-response playbooks at this stage—just reliable collection, parsing, and visualization.

Here’s what I need done:
• Deploy or fine-tune Wazuh agents/managers to ingest all firewall events (the devices are already exporting Syslog today).
• Configure Splunk inputs, indexes, and props/transforms so the data is correctly tagged, timestamped, and CIM-compliant.
• Build a starter dashboard and a couple of saved searches that prove the data is landing and searchable.
• Hand over concise documentation: major config snippets, any custom field extractions, and step-by-step instructions so I can replicate the setup in staging.

Success to me is simple: I can reboot a firewall, see the logs pour into Wazuh, watch them appear in real time inside Splunk, and run a search that returns the event within seconds.

If you’ve connected Wazuh feeds to Splunk before, this should be a quick engagement—let’s get it done.