What problem does it solve? Setting up centralized security logging is complex: teams must choose a SIEM platform, write detection rules in different query languages, design log aggregation pipelines, and meet compliance retention requirements without overspending on storage. This Skill provides decision frameworks, ready-to-use detection rules, deployment architectures, and cost calculators to implement security monitoring correctly. ## Core Features & Use Cases - SIEM Platform Selection: Decision frameworks and feature comparisons for Elastic SIEM, Microsoft Sentinel, Wazuh, Splunk, and AWS Security Lake based on budget, data volume, and team expertise. - Detection Rule Development: SIGMA universal rules plus platform-specific formats (Elastic EQL, Sentinel KQL, Splunk SPL) mapped to MITRE ATT&CK techniques like brute force, privilege escalation, and data exfiltration. - Log Aggregation & Retention: Architecture patterns (centralized, distributed, cloud-native), Fluentd/Logstash configurations, hot/warm/cold storage tiering, and compliance mappings for GDPR, HIPAA, PCI DSS, and SOC 2. - Use Case: A security engineer needs to deploy Wazuh for a small team, write brute-force detection rules, and estimate storage costs for 500 GB/day with one-year retention. This Skill provides the Docker Compose deployment, a ready SIGMA rule, and a cost calculator script showing 76% savings with tiered storage. ## Quick Start Ask the AI to help you choose a SIEM platform and generate a SIGMA detection rule for failed login attempts with a cost estimate for your daily log volume.