siem-log-analysis

Construct forensic timelines and detect threats from network device syslog across Splunk, ELK, and QRadar.

Updated Mar 15, 2026
One-click install
npx skills add https://github.com/vahagn-madatyan/netsec-skills-suite --skill siem-log-analysis
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: siem-log-analysis
Source: https://github.com/vahagn-madatyan/netsec-skills-suite/tree/main/skills/siem-log-analysis
Command: npx skills add https://github.com/vahagn-madatyan/netsec-skills-suite --skill siem-log-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Network-security-focused SIEM log analysis across Splunk, ELK, and QRadar platforms. Guides forensic timeline construction from network device syslog events — firewall denies, authentication failures, configuration changes, interface events, VPN tunnel state, and lateral movement indicators. Provides platform-independent diagnostic reasoning with platform-specific query syntax using [Splunk]/[ELK]/[QRadar] inline labels.

Core Features & Use Cases

  • Platform-agnostic workflow guidance for normalization, correlation, anomaly detection, and triage across Splunk, ELK, and QRadar.
  • Platform-specific query patterns and references to construct timelines, detect anomalies, and document findings.
  • Real-world use cases include incident investigation timelines, threat-hunting evidence gathering, and compliance log-review checks.

Quick Start

Run an initial forensic timeline from 7 days of network device syslog across Splunk, ELK, and QRadar.

Frequently Asked Questions about siem-log-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a forensic timeline from network device syslog in Splunk, ELK, or QRadar?▼

Build a forensic timeline by ingesting network device syslog into Splunk, ELK, or QRadar, then applying normalization, correlation, and anomaly detection. The Skill provides platform-specific query patterns and platform-agnostic triage guidance to construct incident timelines.

Can I analyze firewall denies and VPN tunnel state logs across different SIEM platforms?▼

Yes, you can analyze firewall denies, VPN tunnel state, authentication failures, and configuration changes across Splunk, ELK, and QRadar. The Skill provides platform-agnostic diagnostic reasoning with inline platform-specific query syntax for cross-platform network log forensics.

What is the best way to detect lateral movement indicators during a SIEM threat hunt?▼

Detect lateral movement indicators by correlating network device syslog events like authentication failures and configuration changes. The Skill guides threat hunting evidence gathering with platform-specific queries for Splunk, ELK, and QRadar to surface anomalies.

Does this SIEM log analysis approach work for compliance log reviews?▼

Yes, this SIEM log analysis approach works for compliance log reviews. It provides platform-agnostic workflow guidance for normalizing and correlating network syslog events across Splunk, ELK, and QRadar to document findings for compliance checks.

How do I normalize and correlate multi-vendor network logs for incident investigation?▼

Normalize and correlate multi-vendor network logs by applying platform-agnostic diagnostic reasoning to syslog events. The Skill provides specific query patterns for Splunk, ELK, and QRadar to triage firewall denies, interface events, and lateral movement indicators.

Do I need Splunk, ELK, or QRadar to construct a forensic timeline from network logs?▼

Yes, you need Splunk, ELK, or QRadar to execute the platform-specific query patterns provided by the Skill. The Skill delivers platform-agnostic normalization and correlation guidance, but relies on these SIEM platforms to query network device syslog events.