
Closed
Posted
Paid on delivery
My FortiSIEM installation ingests a large volume of security logs and I need it to surface only the events that matter—specifically intrusion attempts, unauthorized access, and malware detection. Your task is to dive into these security logs, review current alerts, fine-tune thresholds, create any missing correlation rules, and build or update parsers so every useful field is captured. Here’s the workflow I have in mind: first, you’ll analyse a recent log sample and come back with a short gap-analysis that highlights noisy alerts and blind spots. Next, you’ll implement the agreed changes directly in FortiSIEM: adjust policies, write correlation rules, update regexes or parsers, and validate with fresh log traffic. Finally, you’ll provide concise documentation so I can follow exactly what was changed and why. Deliverables • Gap-analysis report covering intrusion, unauthorized access and malware events • Tuned alert policies with before/after alert counts • New or updated correlation rules (.xml or GUI-export) • Custom parsers with test logs and successful field extraction screenshots • One-page hand-off document summarising steps to roll back or extend your work Acceptance criteria • False positives on the three priority alert types reduced by at least 50 % in a 7-day sample • No critical security event missed during validation tests • All parsers pass built-in FortiSIEM validation without warnings Include a detailed project proposal when you reply so I understand your approach, tools or scripts you rely on, and the timeline you expect for each milestone.
Project ID: 40515234
4 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
4 freelancers are bidding on average ₹3,500 INR for this job

Hello, I can optimize your FortiSIEM deployment to focus on intrusion attempts, unauthorized access, and malware events while reducing noise. My approach includes log review and gap analysis, correlation rule tuning, parser improvements, and validation with fresh log samples. I will ensure accurate field extraction, lower false positives, and preserve all critical detections. Deliverables will include tuned policies with before/after metrics, updated correlation rules, working parsers, and clear rollback documentation. Timeline: 5–7 days depending on log volume and current configuration. I’m ready to start with the initial log sample review.
₹10,000 INR in 7 days
2.4
2.4

Hello there, hope you are having a fantastic day so far! FortiSIEM tuning is daily work for me, so your scope reads like a checklist I have run many times: pull a representative log sample, hand you a gap analysis that separates the real intrusion, unauthorized access and malware signal from the noise, then implement and validate inside FortiSIEM rather than just advising. Concretely I would: - Review current alert policies and rules, flagging the noisy ones with before and after counts. - Write or fix correlation rules for the three event classes you care about, exported as XML and GUI. - Build or repair parsers and regexes so every useful field is extracted, with test logs and screenshots proving the field mapping. - Leave you a one page hand-off so you can roll back or extend anything I touch. I work against fresh traffic, so you see real validation, not assumptions. Happy to start with the sample log analysis as a small first milestone so you can judge the quality before we commit to the full tuning pass. VR, Vicente Muñoz
₹1,500 INR in 5 days
1.0
1.0

Dear Hiring Manager, I am applying for the FortiSIEM Detection Engineering and Log Optimization project. I am a Cybersecurity / SOC Engineer with hands-on experience in SIEM operations, log analysis, and detection engineering. I have worked with FortiSIEM, FortiGate, FortiAnalyzer, Windows Event Logs, Active Directory, VPN, and EDR/AV solutions in enterprise environments. My experience includes onboarding and normalizing log sources, tuning parsers using regex-based field extraction, and building correlation rules aligned with MITRE ATT&CK. I regularly work on reducing false positives while ensuring critical threats such as intrusion attempts, unauthorized access, and malware activity are properly detected. I have developed and tuned detection use cases for brute force attacks, password spraying, VPN anomalies, lateral movement, internal scanning, and malware outbreaks. I also validate detections using real log traffic and controlled simulation to ensure accuracy and coverage. My approach follows a structured lifecycle: log review, gap analysis, rule and parser optimization, validation, and documentation with rollback procedures. I focus on improving signal-to-noise ratio while ensuring no critical security event is missed. I would be glad to contribute to optimizing your FortiSIEM environment and improving detection quality and operational efficiency. Kind regards, Walid Kamal
₹1,050 INR in 7 days
0.0
0.0

Hi there, Tuning FortiSIEM to cut through the noise while maintaining 100% visibility on high-priority threats (Intrusion, Unauthorized Access, Malware) is right up my alley. I specialize in SIEM engineering, log parsing, and rule optimization. Here is my target-driven approach to meet your 50% false-positive reduction criteria: Milestones & Timeline: Day 1-2: Gap Analysis: Deep dive into your log sample. I’ll map your current noisy alerts and identify visibility blind spots using a strict framework (e.g., mapping malware events to MITRE ATT&CK techniques). Day 3-5: Parser & Rule Engineering: * Custom Parsers: I will build/update FortiSIEM XML parsers using optimized regex to ensure 100% compliance with FortiSIEM's validation engine (zero warnings). Correlation Rules: I’ll write behavioral rules (e.g., brute force tracking, beaconing behavior) instead of relying solely on static thresholds. Day 6-7: Testing & Delivery: Validate with live traffic to prove the >50% noise reduction, and hand over the XML configurations alongside a clean, one-page rollback guide. Tools & Tactics: Regex101/FortiSIEM Parser Tool: For rigorous regex optimization to prevent CPU spikes on your supervisor node. CyberFlood/Custom Scripts: To safely replay test logs and validate rule triggers without missing critical events. I focus on clean execution and structured hand-offs. Let’s connect to look at your log samples and start filtering out the noise! Best regards, Bassant.
₹1,450 INR in 7 days
0.0
0.0

Greater Noida, Ghaziabad, India
Member since Aug 9, 2013
₹100-400 INR / hour
$10-30 USD
$100-250 USD
$250-750 USD
$250-750 USD
₹150000-250000 INR
₹1500-12500 INR
$750-1500 USD
$30-250 USD
$750-1500 USD
$10-30 USD
₹40000-100000 INR
$125-150 USD
$30-250 USD
₹12500-37500 INR
₹600-1500 INR
$10-30 USD
min $50 USD / hour
₹750-1250 INR / hour
$750-1500 CAD
$15-25 USD / hour