uses

A short list of what shows up most in the posts here.

## detection & log pipelines

  • FortiGate syslog, normalised before it hits the index
  • rsyslog as the collector/forwarder layer
  • Splunk for search and detections
  • Microsoft Entra ID sign-in and consent-grant logs via KQL

## languages

  • Python, day to day
  • C, still learning