EmberSec

Security engineering that takes work off your analysts.

EmberSec builds log pipelines, detection rules and security automation for SOC teams, MSPs and small businesses. Based in New Zealand, working remotely.

Email Jonathan See what I do

One example: from raw log line to searchable fields

Raw syslog
Oct  4 09:12:44 fw01 %ASA-6-302013: Built inbound TCP connection 4811 for outside:203.0.113.45/51514 (203.0.113.45/51514) to inside:10.0.4.21/443 (10.0.4.21/443)
Parsed fields
@timestamp
2026-10-04T09:12:44
observer.name
fw01
event.code
302013
event.action
connection-built
network.direction
inbound
network.transport
tcp
source.ip
203.0.113.45
source.port
51514
destination.ip
10.0.4.21
destination.port
443

One example of the work: turning a raw firewall log into fields your SIEM can search. It uses documentation IP addresses, and the field names follow the Elastic Common Schema.

What I do

Log ingestion and parsing

Logstash pipelines, grok and dissect patterns, and collectors on Linux, including RHEL 9. I build parsers for the sources your SIEM doesn't understand yet, and fix the ones that drop fields or break when a vendor changes its log format.

  • Parsers for firewall, network and application logs
  • Field normalisation, so one search works across sources
  • Pipeline testing against your sample logs

SIEM engineering and tuning

Onboarding sources into Microsoft Sentinel, then writing and tuning the analytic rules and KQL queries that run on them. The aim is fewer, better alerts instead of a queue your analysts learn to ignore.

  • Data connector and log source onboarding
  • New analytic rules and KQL queries
  • Tuning noisy rules against your real data

Automation and integrations

Azure Logic Apps and custom REST API endpoints that join your security tools together and remove manual steps. Enrichment, ticketing and reporting can run on their own, with the results landing where your analysts already work.

  • Logic Apps for enrichment, triage steps and notification
  • Custom REST API endpoints and integrations
  • Documentation and handover, so your team can run it

Also available on request: security architecture reviews, risk assessment, compliance support, and general scripting and Linux engineering.

One engineer from first call to handover.

I do the design, the build and the handover myself, so there is no hand-off to lose detail in. You deal with the person doing the work.

  • Logstash
  • Microsoft Sentinel
  • KQL
  • Azure Logic Apps
  • REST APIs
  • RHEL 9

How it works

  1. Tell me what you're dealing with

    Email a short description of the problem and, if you can, a few sanitised samples such as logs or alerts. I'll reply with questions or a scoped proposal.

  2. I build and test

    I develop against your samples, then test on your real data. You see progress as it happens, not only at the end.

  3. You get a handover

    You receive the working pipeline, rules or automation, plus short documentation so your team can maintain them.

Fixed-scope projects or ongoing support, all done remotely.

About

EmberSec is a one-person consultancy run by Jonathan, a security engineer who builds log pipelines, detection rules and security automation for SOC teams. EmberSec Limited is a registered New Zealand company.

Tell me what you need

Email jonathan@embersec.nz or use the form. A few sentences about the problem is enough to start.

Please don't include sensitive logs in your first message. We'll agree how to share samples once we've talked.