uses
A short list of what shows up most in the posts here.
## detection & log pipelines
- FortiGate syslog, normalised before it hits the index
- rsyslog as the collector/forwarder layer
- Splunk for search and detections
- Microsoft Entra ID sign-in and consent-grant logs via KQL
## languages
- Python, day to day
- C, still learning