<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Home on Abhishek Singh</title><link>https://abhishek-singh.dev/</link><description>Recent content in Home on Abhishek Singh</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Mon, 14 Sep 2026 15:44:51 +0530</lastBuildDate><atom:link href="https://abhishek-singh.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Logsearch</title><link>https://abhishek-singh.dev/logsearch/</link><pubDate>Mon, 14 Sep 2026 15:44:51 +0530</pubDate><guid>https://abhishek-singh.dev/logsearch/</guid><description>&lt;h3 id="logsearch-over-archived-data"&gt;LogSearch over archived data&lt;/h3&gt;
&lt;h4 id="the-full-story"&gt;The Full Story&lt;/h4&gt;
&lt;h4 id="what-problem-does-this-solve"&gt;What problem does this solve&lt;/h4&gt;
&lt;p&gt;Friction in searching over years-old data &amp;amp; bill that comes with excessive ingestion to SIEM - reduces both. It allows investigators,
detection engineers, auditors to search on deep-archive information.&lt;/p&gt;
&lt;p&gt;Saves cost by :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;eliminating need to ingest 5-years old data into SIEM for just taking a look if there could be something useful. This tool
goes to the data and brings only the filtered result.&lt;/li&gt;
&lt;li&gt;built on top of open-source projects - Apache Airflow and Dask&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="what-can-someone-do-now-that-they-couldnt-before"&gt;What can someone do now that they couldn&amp;rsquo;t before&lt;/h4&gt;
&lt;p&gt;On-demand search with few clicks, without cross-team ticket approvals process. Massive search scale - 7PB of data searched in 24 hrs.&lt;/p&gt;</description></item><item><title>My New Post</title><link>https://abhishek-singh.dev/my-new-post/</link><pubDate>Tue, 04 Aug 2026 11:23:06 +0530</pubDate><guid>https://abhishek-singh.dev/my-new-post/</guid><description>&lt;p&gt;This is a page about »My New Post«.&lt;/p&gt;</description></item><item><title>My New Page</title><link>https://abhishek-singh.dev/my-new-page/</link><pubDate>Tue, 04 Aug 2026 11:22:34 +0530</pubDate><guid>https://abhishek-singh.dev/my-new-page/</guid><description>&lt;p&gt;This is a page about »My New Page«.&lt;/p&gt;</description></item><item><title>Markdown Syntax Guide</title><link>https://abhishek-singh.dev/markdown-syntax-guide/</link><pubDate>Fri, 03 Jan 2020 00:00:00 +0000</pubDate><guid>https://abhishek-singh.dev/markdown-syntax-guide/</guid><description>&lt;p&gt;For a quick cheatsheet, check out &lt;a href="https://simplemde.com/markdown-guide"&gt;https://simplemde.com/markdown-guide&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This article offers a sample of basic Markdown syntax that can be used in Hugo content files, also it shows whether basic HTML elements are decorated with CSS in a Hugo theme.&lt;/p&gt;</description></item><item><title>Data Pipeline</title><link>https://abhishek-singh.dev/data-pipeline/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://abhishek-singh.dev/data-pipeline/</guid><description>&lt;h3 id="150tbday-security-data-pipeline"&gt;150TB/Day Security Data Pipeline&lt;/h3&gt;
&lt;h4 id="the-full-story"&gt;The Full Story&lt;/h4&gt;
&lt;p&gt;I inherited (&amp;amp; contributed ahead to development of) an Apache NiFi–based pipeline that moves security telemetry into SIEM — roughly 150TB/day,
pulled from seven different source types (S3, SQS+S3, CloudWatch, Kinesis, Splunk TAs/UFs/HEC, Kafka, REST APIs) — and evolved it into the version
running today: two active-active NiFi clusters backed by a ~5PB+ S3 data lake, with buffering &amp;amp; replay capabilities so the detection
and incident response teams downstream never lose visibility, even when something breaks.&lt;/p&gt;</description></item><item><title>Data Pipeline</title><link>https://abhishek-singh.dev/honeypots/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://abhishek-singh.dev/honeypots/</guid><description>&lt;h3 id="the-full-story"&gt;The Full Story&lt;/h3&gt;
&lt;p&gt;Zoom-bombing cases were a rising pattern during COVID — a problem worth solving for. This solution is a proactive attempt
to build a reliable way to collect repeat offenders&amp;rsquo; data &amp;amp; feed them to Trust Score, a separate system that scores users on
their behaviors so the company can act on serial offenders. This turned out to be a better approach than treating every incident like
it&amp;rsquo;s the first time.&lt;/p&gt;</description></item><item><title>Work</title><link>https://abhishek-singh.dev/work/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://abhishek-singh.dev/work/</guid><description>&lt;h4 id="at-a-glance"&gt;At a glance&lt;/h4&gt;
&lt;h3 id="150tbday-security-data-pipeline"&gt;150TB/Day Security Data Pipeline&lt;/h3&gt;
&lt;p&gt;I design &amp;amp; own pipelines that get ~150TB of security data into SIEM every day, across ~7 source types, backed with a 5PB+ datalake - designed to survive failures.
Pipeline infra is designed with buffer strategy to handle situation when downstream SIEM could go dark. I have developed custom plugins to support specific requirements;
fixed bugs to keep the solution running. Here&amp;rsquo;s how it&amp;rsquo;s built, what broke, and what I did about it. &lt;a href="https://abhishek-singh.dev/data-pipeline"&gt;————→&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>