siem-logging

Installation
SKILL.md

SIEM Logging

Purpose

Configure comprehensive security logging infrastructure using SIEM platforms (Elastic SIEM, Microsoft Sentinel, Wazuh, Splunk) to detect threats, investigate incidents, and maintain compliance audit trails. This skill covers platform selection, log aggregation architecture, detection rule development (SIGMA format and platform-specific), alert tuning, and retention policies for regulatory compliance (GDPR, HIPAA, PCI DSS, SOC 2).

When to Use This Skill

Use this skill when:

  • Implementing centralized security event monitoring across infrastructure
  • Writing threat detection rules for authentication failures, privilege escalation, data exfiltration
  • Designing log aggregation for multi-cloud environments (AWS, Azure, GCP, Kubernetes)
  • Meeting compliance requirements for log retention and audit trails
  • Tuning security alerts to reduce false positives and alert fatigue
  • Calculating costs for high-volume security logging (TB/day scale)
  • Integrating security logging with incident response workflows

SIEM Platform Selection

Related skills

More from ancoleman/ai-design-components

Installs
37
GitHub Stars
361
First Seen
Jan 25, 2026