siem-logging

Configure centralized SIEM logging and detection-rule development across cloud and on-prem environments.

1|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/masermediagroup-stack/CursorSkills --skill siem-logging-masermediagroup-stack
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: siem-logging
Source: https://github.com/masermediagroup-stack/CursorSkills/tree/main/skills-bundle/skills/community/ai-design-components/skills/siem-logging
Command: npx skills add https://github.com/masermediagroup-stack/CursorSkills --skill siem-logging-masermediagroup-stack

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SIEM-related security logging is often fragmented across cloud and on-prem environments, leading to visibility gaps for threats and audits.

Core Features & Use Cases

  • Centralized log collection and normalization across Elastic, Microsoft Sentinel, Wazuh, and Splunk.
  • Detection-rule development using SIGMA universal format with platform-specific mappings.
  • Alert tuning and retention planning to satisfy GDPR, HIPAA, PCI DSS, and SOC 2 requirements.
  • Architectures and playbooks for multi-cloud log aggregation and compliance logging.

Quick Start

Set up a starter SIEM logging workspace, connect data sources, and deploy a basic authentication failure detector.

Frequently Asked Questions about siem-logging

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I centralize security logging across multi-cloud and on-prem environments?

Centralize security logging by deploying a unified architecture that aggregates logs across cloud and on-prem environments. This Skill formalizes platform selection, log normalization, and retention policies to eliminate visibility gaps.

What is the best way to develop SIEM detection rules for compliance audits?

Develop SIEM detection rules using the SIGMA universal format with platform-specific mappings for Elastic, Sentinel, Wazuh, and Splunk. This approach ensures consistent threat detection and satisfies audit requirements.

Does this SIEM logging approach support Splunk and Microsoft Sentinel?

Yes, this SIEM logging approach supports Splunk and Microsoft Sentinel alongside Elastic and Wazuh. It provides centralized log collection, normalization, and alert tuning tailored for each specific platform.

How do I configure log retention policies to satisfy GDPR and HIPAA requirements?

Configure log retention policies by applying alert tuning and retention planning designed to satisfy GDPR, HIPAA, PCI DSS, and SOC 2 requirements. This ensures compliance logging architectures meet regulatory standards.

Can I use KQL and EQL for detection rule development in a multi-cloud SIEM?

Yes, you can use KQL and EQL for detection rule development. This Skill provides Sigma, EQL, and KQL rule guidance to create and tune alerts across your centralized multi-cloud log aggregation deployments.