Siem Query

SIEM query-builder workflow — Splunk SPL, Microsoft Sentinel/Defender KQL, Elastic EQL/KQL, with cross-translation patterns, performance tuning (data models, summary indexes, CCS), and query-by-detection-need. Source layer for detection-engineer, log-triage, and threat-hunt.

roodlicht c539987 11.0 KB Updated

File contents

roodlicht/accans-sec-skills/tree/main/skills/siem-query commit c5399873fa

Frequently asked questions

npx skillmds@latest add roodlicht/siem-query