Elastic Stack Administration
Install, configure, and manage Elasticsearch clusters.
Administer Kibana, Logstash, Beats, Elastic Agent, and Fleet.
Configure Index Lifecycle Management (ILM).
Manage snapshots, backups, and disaster recovery processes.
Perform cluster sizing, performance tuning, and health monitoring.
Implement high availability and scalability architecture.
Security Monitoring & SIEM Operations
Deploy and administer Elastic Security solutions.
Develop and fine-tune security detection rules.
Implement SIEM use cases and threat detection scenarios.
Perform log correlation and incident analysis.
Support threat hunting and forensic investigations.
Develop dashboards for SOC operations and security reporting.
Analyze indicators of compromise (IOC) and security alerts.
Monitor network infrastructure health and availability.
Analyze network traffic, latency, bandwidth utilization, and anomalies.
Develop NOC dashboards and network alerting mechanisms.
Troubleshoot network visibility and log collection issues.
Assist in root cause analysis of security and network incidents.
Data Source Integration
Onboard and normalize logs from:
Security Devices, Network Devices, Server & Infrastructure
Log Collection & Parsing
Develop Logstash pipelines.
Design custom parsers and ingest pipelines.
Create Grok patterns for log normalization.
Configure Syslog, API-based, and Agent-based integrations.
Troubleshoot ingestion, parsing, indexing, and retention issues.
Implement data enrichment and event correlation.Role & responsibilities