siem-log-analysis

Construct forensic timelines and detect threats from network device syslog across Splunk, ELK, and QRadar.

Updated Mar 15, 2026
One-click install
npx skills add https://github.com/vahagn-madatyan/netsec-skills-suite --skill siem-log-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: siem-log-analysis
Source: https://github.com/vahagn-madatyan/netsec-skills-suite/tree/main/skills/siem-log-analysis
Command: npx skills add https://github.com/vahagn-madatyan/netsec-skills-suite --skill siem-log-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Network-security-focused SIEM log analysis across Splunk, ELK, and QRadar platforms. Guides forensic timeline construction from network device syslog events — firewall denies, authentication failures, configuration changes, interface events, VPN tunnel state, and lateral movement indicators. Provides platform-independent diagnostic reasoning with platform-specific query syntax using [Splunk]/[ELK]/[QRadar] inline labels.

Core Features & Use Cases

  • Platform-agnostic workflow guidance for normalization, correlation, anomaly detection, and triage across Splunk, ELK, and QRadar.
  • Platform-specific query patterns and references to construct timelines, detect anomalies, and document findings.
  • Real-world use cases include incident investigation timelines, threat-hunting evidence gathering, and compliance log-review checks.

Quick Start

Run an initial forensic timeline from 7 days of network device syslog across Splunk, ELK, and QRadar.

Frequently Asked Questions about siem-log-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a forensic timeline from network device syslog in Splunk, ELK, or QRadar?

Build a forensic timeline by ingesting network device syslog into Splunk, ELK, or QRadar, then applying normalization, correlation, and anomaly detection. The Skill provides platform-specific query patterns and platform-agnostic triage guidance to construct incident timelines.

Can I analyze firewall denies and VPN tunnel state logs across different SIEM platforms?

Yes, you can analyze firewall denies, VPN tunnel state, authentication failures, and configuration changes across Splunk, ELK, and QRadar. The Skill provides platform-agnostic diagnostic reasoning with inline platform-specific query syntax for cross-platform network log forensics.

What is the best way to detect lateral movement indicators during a SIEM threat hunt?

Detect lateral movement indicators by correlating network device syslog events like authentication failures and configuration changes. The Skill guides threat hunting evidence gathering with platform-specific queries for Splunk, ELK, and QRadar to surface anomalies.

Does this SIEM log analysis approach work for compliance log reviews?

Yes, this SIEM log analysis approach works for compliance log reviews. It provides platform-agnostic workflow guidance for normalizing and correlating network syslog events across Splunk, ELK, and QRadar to document findings for compliance checks.

How do I normalize and correlate multi-vendor network logs for incident investigation?

Normalize and correlate multi-vendor network logs by applying platform-agnostic diagnostic reasoning to syslog events. The Skill provides specific query patterns for Splunk, ELK, and QRadar to triage firewall denies, interface events, and lateral movement indicators.

Do I need Splunk, ELK, or QRadar to construct a forensic timeline from network logs?

Yes, you need Splunk, ELK, or QRadar to execute the platform-specific query patterns provided by the Skill. The Skill delivers platform-agnostic normalization and correlation guidance, but relies on these SIEM platforms to query network device syslog events.