#02Threat monitoring / SIEM

Talon Watch

A security event collection and correlation platform with Splunk integration and smart alert filtering.

  • Python
  • FastAPI
  • PostgreSQL
  • Redis
  • Splunk
  • Wireshark
Source code is covered by an NDA Discuss a similar project

Results in numbers

  • 1.5M

    events per minute

  • −70%

    false positives

  • 40 s

    from event to alert

01

Challenge

The SOC team was drowning in noise: thousands of repetitive alerts a day, with real incidents lost among false positives.

02

Solution

We built a FastAPI pipeline with event normalization, correlation rules and Redis-based deduplication, plus network capture analysis and two-way Splunk integration.

03

Constraints

Data must never leave the client perimeter: everything runs on-premise with no external cloud services.

04

Result

Analysts now see grouped incidents with context instead of a flood of raw alerts, and response time dropped several-fold.

Key features

  • 01 Hot-loaded YAML correlation rules
  • 02 Event enrichment with asset and threat intel
  • 03 PCAP analysis right from the incident card
  • 04 Escalation to messengers and on-call rotations

Architecture

  1. Sensors agents, syslog, PCAP
  2. Ingest API FastAPI, normalization
  3. Correlator Python, rules
  4. Storage PostgreSQL + Redis
  5. Splunk SOC dashboards

Tech stack

  • Python
  • FastAPI
  • PostgreSQL
  • Redis
  • Splunk
  • Wireshark

Timeline

  1. 2 weeks

    Sources & scenarios review

  2. 5 weeks

    Ingest & normalization pipeline

  3. 6 weeks

    Correlation & Splunk integration

  4. 3 weeks

    Rule tuning on live traffic

Need something similar?

Describe your task in a messenger — we will come back with questions, an architecture and an estimate.