I will write custom wazuh decoders and detection rules for your log sources

Pakistan

I speak English

2 orders completed

Wazuh SIEM Deployment and SOAR Automation Engineer

I'm a DevOps and Security Operations Engineer working daily with Wazuh, QRadar, Defender XDR, and Shuffle SOAR in a live SOC. I deploy and tune Wazuh SIEM end-to-end, write custom decoders and detecti...
About this Gig

Wazuh's default ruleset doesn't know your firewall, EDR platform, hypervisor, or custom app logs, so those events get dropped as unparsed or matched incorrectly. I write decoders and rules that make Wazuh understand your log sources, tested against real samples before delivery, not shipped blind.


I do this as part of my day-to-day SOC work, building detection content for the exact devices most generic deployments skip.


What you get: 8+ device types covered, firewalls, EDR platforms, hypervisors, network gear parsed correctly instead of dropped as unknown. Zero alert noise, rules tuned against real samples so you get signal, not false positives. Documented patterns for fast onboarding of new log sources. Tested before delivery against your actual samples, confirmed parsing and alerting.


Who this is for: teams running Wazuh that keep seeing unknown or unparsed events, anyone needing detection coverage for an unsupported device, and MSPs standardizing decoder patterns across clients.

Device:

Server/Hosting

Operating system:

Linux/Unix

Also delivering:

Documentation

My Portfolio

Related tags