
Closed
Posted
Paid on delivery
I need a cybersecurity specialist who can design and deploy a full-featured SIEM for my strictly on-premises environment. The number-one goal is rapid threat detection and incident identification, so every decision— from log sources to correlation rules— must serve that purpose. The platform you propose (Splunk, QRadar, Elastic, Graylog, or another commercial/open-source stack) should pull logs from our firewalls, core network devices and Windows/Linux endpoints, normalize them, correlate events in real time and raise actionable alerts. I also expect intuitive dashboards for security posture, drill-down timelines for investigations, and the ability to automate first-response actions where sensible. Beyond the build itself, I’m looking for clear documentation and a knowledge-transfer session so my internal team can maintain and extend the solution later. While the current scope is 100 % on-prem, the architecture should stay flexible enough to add cloud data sources down the road without a rip-and-replace. Please send: • a brief outline of the SIEM stack you’d recommend and why • comparable projects you have delivered (links or screenshots welcome) • the milestones you foresee and the time you need for each On acceptance I will provide sample logs and network diagrams so you can refine sizing and licensing assumptions.
Project ID: 40638764
15 proposals
Remote project
Active 4 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
15 freelancers are bidding on average $523 USD for this job

Hello, I'm Sr Incident Response and have 10 years in SIEM experience. I can deploy SIEM and help you better for understanding and integration on-Prem. Contact me via chat so we can discuss price and will share all which SIEM you want to implement. Because after discuss we cna decide better to implement.
$500 USD in 15 days
5.1
5.1

Hi there! Quick question: are you planning to retain historical logs for compliance reasons, and if so, do you have a specific retention window in mind? Regardless, this is definitely something that I feel confident delivering on, given my past experience. I would love to discuss your project further! Looking forward hearing from you. kind regards, Corné
$450 USD in 7 days
3.9
3.9

Fast detection on an on-prem SIEM comes down to two things: clean log normalization at ingestion (garbage in, garbage alerts) and correlation rules tuned to your environment, not vendor defaults. Rest is plumbing. Straight on fit — 9 years full-stack + DevOps, strong on the deployment side: Elastic Stack or Graylog on-prem, Docker/K8s, Beats/Fluentd/Logstash pipelines from Windows/Linux endpoints and firewall syslog, index sizing, hot/warm/cold tiers, Kibana/Grafana dashboards. That layer I own. Honest flag: I'm not primarily a SOC analyst. Can implement standard correlation rules (brute force, lateral movement, MITRE ATT&CK-aligned starter packs), but for deeply tuned custom rules against a specific threat model, a dedicated security specialist paired with me on the infra fits better. Realistic scope in $250-750: Graylog or Elastic community stand-up + log source integration for a small environment (2-3 firewalls, 20-50 endpoints) + starter dashboards + basic docs + one knowledge-transfer session. Cloud-ready architecture (containerized) so adding cloud sources later isn't a rip-and-replace.
$400 USD in 6 days
3.3
3.3

Hi, You need an on-prem SIEM that detects threats quickly, correlates logs in real time, and supports investigations. For your project, our team will: • Design an on-prem SIEM stack around Splunk or Graylog for fast detection and flexible scaling • Connect firewall, network device, Windows, and Linux logs with normalization and correlation rules • Build security dashboards, drill-down timelines, and actionable alerting for incident response • Set up sensible automation for first-response actions where it adds operational value • Deliver clear documentation and a knowledge-transfer session so your team can maintain it confidently We work with Linux, automation, and documentation-driven delivery for security and operations environments, with architecture planning that keeps future cloud log sources in mind without forcing a rebuild. Relevant projects: I'd be happy to discuss the details and answer any questions before we get started. Looking forward to working with you. Best regards, Mubeen Web Crest
$350 USD in 4 days
1.5
1.5

Hi, I will deliver a full-featured on-prem SIEM with log correlation and alerting. I commit to a 3-day timeline within the 250-750 USD budget. Want to start with a free sample or begin now? Waiting for your response in chat! Best Regards.
$500 USD in 3 days
0.0
0.0

Elastic Stack is the right choice here, so it is the one I would pick. It handles log ingestion and real-time correlation well. I will build the SIEM by setting up Elasticsearch for log storage and search, Logstash to ingest and parse logs from your firewalls, core network devices, and Windows/Linux endpoints, and Kibana for dashboards and investigations. I’ll configure collectors on your devices to send logs to Logstash. The part that is hard is ensuring the correlation rules actually catch threats and do not create noise, so I will write custom rules focused on attack patterns and known vulnerabilities. I will test these rules against simulated events. What is the primary vendor for your firewalls and core network devices? Preferred Freelancer here, and I have not missed a deadline or gone over an agreed price yet. I will deliver clear documentation and a knowledge-transfer session. In the first day or two, I will have the basic Elastic Stack installed and configured on your chosen hardware, also have initial log sources from one type of device flowing into Kibana.
$600 USD in 21 days
0.0
0.0

Hi, I read your project "On-Prem SIEM Deployment Project". I'm a senior engineer (11+ yrs) specialized in workflow automation (n8n / Make / custom Python) and API integration — exactly what this needs. I've shipped my own products end to end and focus on reliable, maintainable delivery. How I'd approach it: 1) Quick chat to lock the exact scope and edge cases 2) Build in small, testable steps so you see progress early 3) Clean handover with docs Ready to begin immediately; I work async and communicate via chat. Ask me anything. Best, Chris
$452 USD in 8 days
0.0
0.0

This project immediately caught my attention because it is exactly the type of work I do best. Your focus on rapid threat detection and incident identification aligns perfectly with my expertise. I understand the importance of a clean, professional, and user-friendly SIEM solution that integrates seamlessly with your existing infrastructure while allowing for automated first-response actions. While I am new to freelancer, I have tons of experience and have done other projects off site. I specialize in deploying SIEM solutions like Splunk and QRadar, ensuring real-time event correlation and intuitive dashboards for your security posture. If this sounds like what you're looking for, I'd love to hear more about your project. Regards, Warrick Van Eeden
$350 USD in 7 days
0.0
0.0

Hi, I'd recommend Wazuh as your SIEM platform — open-source, so no licensing costs as you scale, and built for exactly what you need: real-time log correlation, endpoint monitoring (Windows/Linux), and syslog ingestion from firewalls and network devices. Its OpenSearch/Kibana dashboards give you posture views and drill-down timelines, and it can ingest cloud sources later without a rip-and-replace — fitting your on-prem-first, scale-ready requirement. Background: I work hands-on with open-source security/monitoring (Wazuh, Zabbix) and networking (Cisco, Juniper CLI) — important here since accurate SIEM correlation depends on properly parsing firewall/network logs, not just endpoint agents. I run EkikaranIT, built around open-source adoption for businesses, so deployment + documentation + training your team is core to how we work. Milestones: Discovery & sizing — review logs/diagrams, confirm sources, size hardware/storage Core deployment — Wazuh manager + indexer, agent rollout, firewall/network log forwarding Correlation rules & alerting — tuned to your environment, automated first-response scoped where sensible Dashboards & investigation views — posture overview + drill-down Documentation & knowledge transfer — runbook + live session for your team
$700 USD in 10 days
0.0
0.0

An on-prem SIEM lives or dies on log source coverage and correlation tuning, not the platform badge - a well-tuned Elastic stack will outperform a poorly configured Splunk deployment for rapid threat detection every time. That decision should come before licensing cost or dashboard aesthetics. Given budget and on-prem constraints, Elastic Stack (Elasticsearch, Logstash, Kibana) or Wazuh are the pragmatic choices - no per-GB licensing pressure, full control over retention, and solid ingestion via Beats/Winlogbeat for endpoints, syslog for network gear. If the scope is not fully settled, I can give you a free 15-minute scoping consultation here on Freelancer before award, with no payment or commitment required. Which system is the source of truth, and is sandbox access available? Kind regards, Dixon
$700 USD in 7 days
0.0
0.0

Mumbai Suburban, India
Member since Aug 10, 2026
$70 USD
$250-750 USD
$30-250 USD
$10-70 USD
$70 USD
£250-750 GBP
€8-30 EUR
$750-1500 USD
₹1500-12500 INR
$2500 USD
$250-750 USD
₹12500-37500 INR
₹12500-37500 INR
₹1500-12500 INR
$25-100 USD
₹750-1250 INR / hour
₹1500-12500 INR
$250-750 USD
$2500 USD
₹1500-12500 INR