#02Threat monitoring / SIEM
Talon Watch
A security event collection and correlation platform with Splunk integration and smart alert filtering.
- Python
- FastAPI
- PostgreSQL
- Redis
- Splunk
- Wireshark
Results in numbers
-
1.5M
events per minute
-
−70%
false positives
-
40 s
from event to alert
01
Challenge
The SOC team was drowning in noise: thousands of repetitive alerts a day, with real incidents lost among false positives.
02
Solution
We built a FastAPI pipeline with event normalization, correlation rules and Redis-based deduplication, plus network capture analysis and two-way Splunk integration.
03
Constraints
Data must never leave the client perimeter: everything runs on-premise with no external cloud services.
04
Result
Analysts now see grouped incidents with context instead of a flood of raw alerts, and response time dropped several-fold.
Key features
- 01 Hot-loaded YAML correlation rules
- 02 Event enrichment with asset and threat intel
- 03 PCAP analysis right from the incident card
- 04 Escalation to messengers and on-call rotations
Architecture
- Sensors agents, syslog, PCAP
- Ingest API FastAPI, normalization
- Correlator Python, rules
- Storage PostgreSQL + Redis
- Splunk SOC dashboards
Tech stack
- Python
- FastAPI
- PostgreSQL
- Redis
- Splunk
- Wireshark
Timeline
-
2 weeks
Sources & scenarios review
-
5 weeks
Ingest & normalization pipeline
-
6 weeks
Correlation & Splunk integration
-
3 weeks
Rule tuning on live traffic
Need something similar?
Describe your task in a messenger — we will come back with questions, an architecture and an estimate.