Tuesday, November 7, 2023

Project 3 - Bayer SOC Environment [Feb. 2021 to Jul. 2022] Role- Senior Security Consultant

·         Integrated Splunk with Pega Cloud, Splunk DB Connect, and Splunk App for Infrastructure.

·         Performed log analysis and troubleshooting for suspicious traffic. Developed regex expression to extract the data.

·         Normalized the data using the Common Information Model. Identified the incident's root cause and mitigated it.

·         Onboarded data to Splunk using Syslog, Agent-based, API, DB Connect, HTTP Event Collector

·         Administered Universal Forwarders using Splunk Deployment Server, created server class


No comments:

Post a Comment

35 Use Cases using Splunk SIEM to reduce False Positives

Use Case Name 1. BRUTE FORCE ATTACK DETECTION ON WINDOWS SYSTEMS Goal Excludes routine status cod...