asp-siem-en

Explore ASP SIEM indices and fields for structured investigations.

1.1k|201|Updated Sep 7, 2025
One-click install
npx skills add https://github.com/FunnyWolf/agentic-soc-platform --skill asp-siem-en
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: asp-siem-en
Source: https://github.com/FunnyWolf/agentic-soc-platform/tree/main/PLUGINS/ClaudeCode/skills/asp-siem-en
Command: npx skills add https://github.com/FunnyWolf/agentic-soc-platform --skill asp-siem-en

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Investigate ASP SIEM data with schema exploration, keyword search, and adaptive field queries to streamline evidence discovery and incident response.

Core Features & Use Cases

  • Schema exploration to reveal available indices and fields.
  • Keyword search and adaptive queries for precise, fast investigations.
  • Structured hunts with exact filters and aggregations to produce actionable insights.

Quick Start

Use a guided SIEM workflow to start an ASP investigation with a target index, time window, and initial keywords.

Frequently Asked Questions about asp-siem-en

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I discover available indices and fields in ASP SIEM data?▼

Schema exploration discovers available ASP SIEM indices and fields to enable efficient investigations. This helps you identify data sources and interrogate them effectively before applying filters.

How do I perform time-bounded keyword searches in SIEM for incident response?▼

Time-bounded keyword searches in SIEM use adaptive query capabilities with explicit index targets to guide analysts. This allows precise, fast investigations during incident response and evidence discovery.

Can I run structured hunts with exact filters and aggregations on SIEM data?▼

Structured hunts with exact field filtering and aggregations on SIEM data produce actionable insights. You can apply explicit index targets and time-range aware queries to guide your investigation.

What is the best way to start an ASP SIEM investigation workflow?▼

The best way to start an ASP SIEM investigation is using a guided workflow with a target index, time window, and initial keywords. This approach streamlines evidence discovery and incident response.

Do I need to specify an index target before running adaptive field queries?▼

Specifying an explicit index target is necessary before running adaptive field queries to guide analysts effectively. This ensures your time-range aware queries and exact filters return accurate results.