Invisible data
Telemetry reaches Elasticsearch but never appears in the analyst workflows that depend on it.
Elastic Security · SIEM · Platform Reliability
I help security teams improve the health, visibility, and reliability of their Elastic Security environments—from ingestion and Fleet to datastreams, Data Views, architecture, and automation.
The hidden problem
Security platforms grow over time. Integrations are added, policies change, agents disappear, and operational gaps become harder to see.
Telemetry reaches Elasticsearch but never appears in the analyst workflows that depend on it.
Offline agents, policy drift, and version inconsistencies quietly reduce coverage over time.
Manual checks, unclear ownership, and lifecycle issues turn routine work into recurring incidents.
I identify these gaps and turn them into a prioritized, evidence-backed remediation plan.
Primary service
An independent technical assessment focused on platform health, data visibility, operational gaps, and opportunities for improvement.
Multiple active datastreams contain security-relevant data but are not included in the Data Views used by analysts.
Data may be ingested successfully while remaining difficult or impossible to discover through standard workflows.
Extend existing patterns or create dedicated Data Views for the affected datasets.
What you receive
Actionable results—not a loose list of technical observations.
Issues, affected components, impact, evidence, and recommended remediation.
↗A concise overview of the most important findings for technical leadership.
↗Every issue classified as Critical, High, Medium, or Low by operational impact.
↗A practical sequence of improvements, starting with the highest-value fixes.
↗A working session to review evidence, answer questions, and align on next steps.
↗Additional services
Hands-on engineering and troubleshooting for Elastic Security environments.
Reduce repetitive Security and IT work through practical automation and workflow orchestration.
I design automation ranging from individual scripts and API integrations to complete SOAR workflows that collect and enrich signals, apply decision logic, orchestrate multiple systems, and automate operational actions.
Examples include
Beyond traditional SOC automation
I have designed a SOAR-based fraud investigation workflow that combined signals and context from multiple security and enterprise systems, including identity and access management platforms, endpoint security telemetry, internal APIs, and interactive collaboration applications.
The workflow enriched incoming signals with additional identity and endpoint context, applied automated decision logic, and used interactive messaging to involve analysts or other stakeholders when human validation was required.
Based on the collected context and response, the workflow could continue through different branches and trigger the appropriate automated actions across integrated systems.
Open source / Labs
Tools, experiments, and automation focused on SIEM operations and platform engineering.
Finds active Elastic datastreams that may not be covered by existing Data Views.
Python · Elasticsearch API · Kibana APICollects and analyzes Elastic Agent and Fleet health information automatically.
Python · Fleet API · Elastic SecurityFocused experiments that remove repetitive work from security platform operations.
Python · APIs · Security Engineering · SOARHow it works
We map your environment, current challenges, and the assessment scope.
I evaluate the agreed components for health, visibility, and operational gaps.
You receive evidence-backed findings, impact, priority, and recommendations.
We walk through the results and identify the highest-value improvements.
If useful, implementation can be scoped as a separate engagement.
About
I’m a Security Engineer with more than five years of experience across Security Operations, SIEM infrastructure, cloud, and security platform engineering.
My work focuses on the systems behind security operations: making sure telemetry is collected correctly, data stays usable, platform components remain healthy, and operational processes can scale.
Explore my GitHub ↗Elastic Security, Kibana, Fleet, Agent, integrations, datastreams, Data Views, ECS.
AWS security fundamentals, IAM, EC2, S3, Security Groups, CloudTrail, AWS Config.
Python, PowerShell, Bash, REST APIs, and operational security workflows.
FAQ
Have a different question? Reach out and tell me about your environment.
Not necessarily. Read-only or limited access can often support significant portions of the review. The exact level depends on scope.
Yes. The service is designed to be delivered remotely, and I can work under NDA.
Yes. Remediation and hands-on engineering can be scoped separately after the assessment.
No. The Health Check focuses on SIEM platform health, visibility, configuration, architecture, and operations.
Yes. The scope can focus on Fleet, Agents, integrations, ingestion, datastreams, Data Views, lifecycle management, or operations.
Start with visibility
Get an independent technical review of your Elastic Security environment and identify gaps before they become operational problems.
Remote engagements · NDA available · Fixed-scope assessments