← Documentation index

Engineering Log

ENG-014 — Enterprise Security Monitoring Platform Deployment

Successfully deployed the Project RedForge Enterprise Security Monitoring Platform by implementing Splunk Enterprise, centralized log collection, Universal Forwarders, indexed data sources, dashboards, and security monitoring capabilities.

Status
Implemented
Date
2026-07-30
Updated
2026-07-30
Source
ENG-014 — Enterprise Security Monitoring Platform Deployment

Objective

Engineering objective

Deploy a scalable enterprise security monitoring platform capable of collecting, indexing, searching, and visualizing security telemetry generated throughout the Project RedForge environment. Primary objectives included: Deploy Splunk Enterprise. Configure centralized log collection. Deploy Universal Forwarders. Configure enterprise indexes. Establish searchable data sources. Validate event ingestion. Build operational dashboards. Prepare the platform for future detection engineering. Establish the monitoring foundation for enterprise security operations.

Engineering summary

Work performed

Completion of Active Directory deployment established the centralized identity infrastructure required for enterprise administration.

With enterprise identity services operational, engineering efforts transitioned toward establishing centralized visibility into enterprise activity.

Enterprise environments rely on continuous monitoring to detect operational issues, authentication events, system failures, policy violations, and potential security incidents. Splunk Enterprise was selected as the primary SIEM platform due to its scalability, search capabilities, flexible data ingestion, and widespread adoption throughout enterprise security operations.

This deployment represents Project RedForge's transition from enterprise infrastructure engineering into enterprise security operations.

Deployment focused on establishing centralized enterprise visibility capable of supporting future security operations rather than simply installing SIEM software.

Splunk Enterprise was successfully deployed as the primary security monitoring platform, providing centralized event ingestion, indexing, search capabilities, dashboards, and enterprise log visibility.

Universal Forwarders were configured to transmit telemetry from enterprise systems into centralized indexes where events could be searched, analyzed, and validated through Splunk Search Processing Language (SPL).

Collectively, these engineering activities established the first enterprise security platform within Project RedForge and created the operational monitoring foundation required for future detection engineering, incident response, threat hunting, and enterprise attack simulation. ---

Project RedForge successfully completed deployment of its Enterprise Security Monitoring Platform through implementation of Splunk Enterprise as the centralized Security Information and Event Management solution.

The completed deployment provides centralized event collection, enterprise search capabilities, operational dashboards, indexed telemetry, and comprehensive visibility into enterprise activity while establishing the monitoring foundation required for detection engineering, threat hunting, incident response, and enterprise attack simulation.

Completion of this effort marks the successful deployment of the first enterprise security platform within Project RedForge, transitioning the laboratory from enterprise infrastructure engineering into enterprise security operations.

Technical decisions

Decisions and rationale

Centralize Enterprise Log Collection

Security telemetry from enterprise systems was centralized within Splunk Enterprise to eliminate fragmented logging and provide a single authoritative platform for enterprise monitoring. Centralized log collection improves visibility, accelerates investigations, and establishes consistent security telemetry across the environment.

Deploy Universal Forwarders on Enterprise Systems

Splunk Universal Forwarders were selected to securely collect and forward endpoint telemetry to the centralized Splunk server. This lightweight architecture minimizes endpoint resource utilization while ensuring consistent log collection throughout the enterprise.

Organize Data Through Dedicated Indexes

Enterprise data sources were separated into dedicated indexes to improve search efficiency, simplify administration, and prepare the environment for future detection engineering. Separating authentication, endpoint, Windows, and infrastructure logs supports scalable enterprise growth while reducing operational complexity.

Build Monitoring Before Detection Engineering

The initial deployment focused exclusively on establishing a reliable monitoring platform before implementing detection content. Future engineering efforts—including correlation searches, security detections, attack simulations, automated alerting, and threat hunting—will leverage the monitoring infrastructure established during this deployment.

Lessons learned

Engineering lessons

  • Security monitoring depends upon reliable telemetry rather than detection logic alone.
  • Centralized logging significantly improves enterprise visibility.
  • Universal Forwarders provide efficient and scalable endpoint telemetry collection.
  • Proper index design simplifies long-term administration and investigation.
  • Validation should occur immediately after every major configuration change.
  • Dashboards improve operational awareness while accelerating investigations.
  • Detection engineering should only begin after monitoring infrastructure has been fully validated.

Evidence

Reviewed engineering evidence

Verified or reviewed evidence is separated from conceptual architecture and evidence-pending material.

ENG-014 validation record

Verified evidence
  • Splunk Enterprise operational.passed
  • Enterprise indexes successfully configured.passed
  • Universal Forwarders communicating correctly.passed
  • Event ingestion functioning as expected.passed
  • Search Processing Language (SPL) queries returning valid results.passed
  • Dashboards displaying enterprise telemetry.passed
  • Windows event logging successfully centralized.passed
  • Authentication events successfully indexed.passed
  • Repository documentation completed.passed
  • Engineering evidence successfully captured.passed
Sanitized engineering recordyamlReviewed record

Documentation evidence identifying the reviewed source record. Sensitive configuration values and personal metadata are intentionally excluded.

record: ENG-014
title: Enterprise Security Monitoring Platform Deployment
status: verified
project: Project RedForge
evidenceStatus: documented

Next steps

Planned engineering actions

  1. Integrate additional enterprise endpoints into centralized monitoring.
  2. Develop enterprise detection rules and correlation searches.
  3. Engineer custom dashboards for security operations.
  4. Simulate adversary activity to validate monitoring coverage.
  5. Expand enterprise logging sources.
  6. Continue evidence-driven security engineering.