asp-siem-zh

Explore schemas, search keywords, and run adaptive queries on ASP SIEM data.

1.1k|201|Updated Sep 7, 2025
One-click install
npx skills add https://github.com/FunnyWolf/agentic-soc-platform --skill asp-siem-zh
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: asp-siem-zh
Source: https://github.com/FunnyWolf/agentic-soc-platform/tree/main/PLUGINS/ClaudeCode/skills/asp-siem-zh
Command: npx skills add https://github.com/FunnyWolf/agentic-soc-platform --skill asp-siem-zh

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

提供在 ASP SIEM 平台中进行调查的结构化工作流,帮助分析师快速发现证据、制定搜索策略并提升证据可追溯性。

Core Features & Use Cases

  • Schema 探索: 快速发现可用的索引和字段结构,以降低初步摸索成本。
  • 关键词搜索: 针对关键字进行精准日志检索、证据聚合与定位。
  • 自适应查询: 在已知目标索引时执行精确字段过滤和聚合分析。
  • 工作流指引: 提供从发现到证据落地的端到端 SOP,帮助用户按步骤推进调查。

Quick Start

在 ASP SIEM 调查中输入目标关键词与时间范围,然后按照 SOP 启动结构化调查。

Frequently Asked Questions about asp-siem-zh

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I explore SIEM schema to find available fields for log investigations?

Exploring SIEM schema involves discovering available indices and field structures to lower initial setup costs. You can use schema exploration features to identify relevant evidence sources before applying keyword searches or adaptive queries to isolate events.

What is the best way to perform keyword searches across SIEM data for evidence collection?

Performing keyword searches across SIEM data allows precise log retrieval, evidence aggregation, and event location. By inputting target keywords and time ranges, analysts can execute structured investigations to isolate relevant logs and ensure evidence traceability.

How do I run adaptive queries for SIEM investigations when I know the target index?

Running adaptive queries in SIEM investigations applies precise field filtering and aggregation analysis when the target index is already known. This approach isolates relevant events effectively by combining known time windows with specific field filters.

Do I need to know the target index and time window before starting a SIEM investigation?

Yes, starting a SIEM investigation requires knowledge of the target index, time window, and field filters. Having these prerequisites ensures that schema exploration, keyword searches, and adaptive queries can successfully isolate relevant events.

How to follow an end-to-end SOP for structured SIEM investigations?

Following an end-to-end SOP for structured SIEM investigations guides analysts from schema discovery through evidence retrieval. The workflow progresses by exploring schemas, executing keyword searches, and running adaptive queries to ensure complete evidence traceability.

Why use schema-driven SIEM investigations instead of basic log searches?

Schema-driven SIEM investigations provide a structured workflow that reduces initial摸索 costs by discovering indices first. Unlike basic log searches, this approach applies adaptive queries with specific field filters to precisely isolate relevant events and improve evidence traceability.