Projects
CybersecurityInternal System
Sentinel Log Ingestion
Non-native telemetry into Microsoft Sentinel
January 2026 – June 2026
Microsoft SentinelKQLAzureCEFLog Analytics
Problem
Security telemetry that Sentinel does not natively understand still has to land in useful tables for detection work.
Approach
Designed DCRs, custom tables, and schemas, then a syslog pipeline for Palo Alto logs with CEF forwarding and severity-based filtering.
Outcome
Ingestion accuracy validated with KQL schema checks and cross-source correlation in Log Analytics.
- Built log ingestion pipelines in Microsoft Sentinel via DCRs, custom tables, and schemas for non-native telemetry
- Architected a syslog pipeline for Palo Alto firewall logs via CEF forwarding with severity-based filtering
- Validated ingestion accuracy via KQL schema checks and cross-source correlation in Log Analytics
Related experience: Cybersecurity Co-op · Shaw Industries