Deployed a SIEM solution (Wazuh/ELK/Graylog) to monitor security logs, detect threats, and respond to incidents.
- Wazuh
- ELK Stack (Elasticsearch, Logstash, Kibana)
- Graylog (Optional)
- Splunk Free (Optional for demo)
- Set up SIEM server.
- Configure log collection from endpoints, firewalls, and servers.
- Develop correlation rules for brute force, malware, lateral movement.
- Build dashboards for threat monitoring.
- Detected multiple test attacks from simulated tools.
- Enhanced visibility into network activity.
- siem-architecture.png
- sample-log-data.json
- correlation-rules.yaml
- dashboards-screenshot.png
- SIEM-deployment-guide.md