asp-siem-en

Explore ASP SIEM indices and fields for structured investigations.

1.1k|201|Updated Sep 7, 2025
One-click install
npx skills add https://github.com/FunnyWolf/agentic-soc-platform --skill asp-siem-en
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: asp-siem-en
Source: https://github.com/FunnyWolf/agentic-soc-platform/tree/main/PLUGINS/ClaudeCode/skills/asp-siem-en
Command: npx skills add https://github.com/FunnyWolf/agentic-soc-platform --skill asp-siem-en

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Investigate ASP SIEM data with schema exploration, keyword search, and adaptive field queries to streamline evidence discovery and incident response.

Core Features & Use Cases

  • Schema exploration to reveal available indices and fields.
  • Keyword search and adaptive queries for precise, fast investigations.
  • Structured hunts with exact filters and aggregations to produce actionable insights.

Quick Start

Use a guided SIEM workflow to start an ASP investigation with a target index, time window, and initial keywords.

Frequently Asked Questions about asp-siem-en

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I discover available indices and fields in ASP SIEM data?

Schema exploration discovers available ASP SIEM indices and fields to enable efficient investigations. This helps you identify data sources and interrogate them effectively before applying filters.

How do I perform time-bounded keyword searches in SIEM for incident response?

Time-bounded keyword searches in SIEM use adaptive query capabilities with explicit index targets to guide analysts. This allows precise, fast investigations during incident response and evidence discovery.

Can I run structured hunts with exact filters and aggregations on SIEM data?

Structured hunts with exact field filtering and aggregations on SIEM data produce actionable insights. You can apply explicit index targets and time-range aware queries to guide your investigation.

What is the best way to start an ASP SIEM investigation workflow?

The best way to start an ASP SIEM investigation is using a guided workflow with a target index, time window, and initial keywords. This approach streamlines evidence discovery and incident response.

Do I need to specify an index target before running adaptive field queries?

Specifying an explicit index target is necessary before running adaptive field queries to guide analysts effectively. This ensures your time-range aware queries and exact filters return accurate results.