<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>The Telemetry Forge</title>
    <link>https://telemetry-forge.t-security.org/</link>
    <description>Recent content on The Telemetry Forge</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 07 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://telemetry-forge.t-security.org/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Building an Edge AI Inference Pipeline for Security Operations: Architecture and Concepts (Part 1 of 4) </title>
      <link>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part1/</link>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <guid>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part1/</guid>
      <description>Architecture and concepts for building a Jetson Nano edge inference pipeline wired to Splunk ES for AI-driven security detection. Part 1 of 4.</description>
    </item>
    <item>
      <title>Building the DSDL-Native Inference Container on Jetson Nano (Part 2 of 4)</title>
      <link>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part2/</link>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <guid>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part2/</guid>
      <description>Build the ARM64 Docker inference container for Jetson Nano -- Dockerfile, DSDL-native Flask app, TLS certificates, and 4-node deployment. Part 2 of 4.</description>
    </item>
    <item>
      <title>Wiring the Pipeline: DSDL Configuration, HEC, and Splunk Integration (Part 3 of 4)</title>
      <link>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part3/</link>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <guid>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part3/</guid>
      <description>Complete DSDL 5.2.3 configuration for Splunk -- docker.conf, containers.conf, HEC cluster bundle, and end-to-end smoke tests. Part 3 of 4.</description>
    </item>
    <item>
      <title>Real Security Data: Training and Deploying Anomaly Detection Models (Part 4 of 4)</title>
      <link>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part4/</link>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <guid>https://telemetry-forge.t-security.org/posts/edge-ai-secops-part4/</guid>
      <description>Train Isolation Forest models on Zeek conn logs, DNS, and Windows auth events. Build ES correlation rules that generate AI-scored notable events. Part 4 of 4.</description>
    </item>
    <item>
      <title>About</title>
      <link>https://telemetry-forge.t-security.org/about/</link>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <guid>https://telemetry-forge.t-security.org/about/</guid>
      <description>&lt;h2 id=&#34;ted-skinner&#34;&gt;Ted Skinner&lt;/h2&gt;
&lt;p&gt;Security architect and SOC engineer with a focus on detection engineering, security telemetry, and operationalizing machine learning in security operations.&lt;/p&gt;
&lt;p&gt;The Telemetry Forge documents builds done in a real security lab &amp;ndash; not cloud demos, not toy datasets. Every post is written at the depth a senior security engineer needs to actually replicate the work, including what broke and why.&lt;/p&gt;
&lt;h2 id=&#34;lab-environment&#34;&gt;Lab Environment&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Splunk Enterprise 10.0 with Enterprise Security&lt;/li&gt;
&lt;li&gt;4-node NVIDIA Jetson Nano cluster (JetPack 4.6.6)&lt;/li&gt;
&lt;li&gt;Zeek IDS, Suricata, Splunk Stream&lt;/li&gt;
&lt;li&gt;Windows event log collection&lt;/li&gt;
&lt;li&gt;Custom edge AI inference pipeline (DSDL 5.2.3)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;topics-covered&#34;&gt;Topics Covered&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Detection engineering and SIEM architecture&lt;/li&gt;
&lt;li&gt;Edge AI and machine learning for security operations&lt;/li&gt;
&lt;li&gt;Security telemetry pipeline design&lt;/li&gt;
&lt;li&gt;Threat hunting with Splunk SPL&lt;/li&gt;
&lt;li&gt;SOC automation and workflow engineering&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;contact&#34;&gt;Contact&lt;/h2&gt;
&lt;p&gt;Reach out via &lt;a href=&#34;https://www.linkedin.com/in/tedskinnercissp/&#34;
   
    target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;LinkedIn&lt;/a&gt; or &lt;a href=&#34;https://github.com/tskinnerarlo&#34;
   
    target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;GitHub&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
