SIEM engineering

A SIEM is only as good as what you put into it.

Architecture, data engineering and detection content for Splunk, Microsoft Sentinel and Cribl. Built by the people who will be on the call when it matters.

SplunkMicrosoft SentinelCribl

Where the money usually goes wrong

Licence cost follows data volume, and data volume follows decisions nobody revisited. We have found a single device generating four hundred thousand log entries a day, and an application writing every database query twice. Both were invisible until someone looked.

Architecture and sizing

Indexer and search head sizing, multi-site and disaster recovery, retention tiers, and a licence model that matches how you actually use the platform.

Data pipeline engineering

Cribl Stream between your sources and your SIEM: parse, enrich, mask and route. Send what is useful to the expensive tier and the rest to cheap storage you can still search.

Detection engineering

Content mapped to the Essential Eight and MITRE ATT&CK, tuned against your environment. A detection that fires constantly is the same as no detection.

What you are left with

  • As-built documentation that a different engineer could pick up
  • Infrastructure as code where the platform supports it, so the build is repeatable
  • Detection content you own, in your repository, not locked in a vendor's console
  • A handover session with the person who did the work

Masking is a design decision, not a setting. If sensitive data should not reach your SIEM, that has to be handled at the pipeline, before it lands. Retro-fixing it afterwards means reprocessing everything you have already stored.

Paying for ingest you are not using?

A short conversation is usually enough to work out whether we can help, and what it would cost.