← all publishers

tenzir

@tenzir source repo

10 published skills

  1. Tenzir Ship · tenzir bundle
    Use when adding changelog entries, creating release notes, cutting releases, and publishing them to GitHub.
    0 installs
  2. Tenzir · tenzir bundle
    Answer questions using the Tenzir documentation. Use whenever the user asks about TQL syntax, pipeline operators, functions, data parsing or transformation, normalization, OCSF mapping, enrichment, lookup tables, contexts, packages, nodes, platform setup, deployment, configuration, integrations with tools like Splunk, Kafka, S3, Elasticsearch, or any other Tenzir feature. Also use when the user asks how to collect, route, filter, aggregate, or export security data with Tenzir, or needs help writing or debugging TQL pipelines, even if they don't mention 'Tenzir' explicitly but are clearly working in a Tenzir context. Also use for questions about Tenzir the company or product, release notes and changelog, blog posts, and solution use cases.
    0 installs
  3. Tenzir Cef · tenzir bundle
    Answer questions and produce mappings for ArcSight CEF (Common Event Format), the OpenText/Micro Focus SIEM interchange format, and the ArcSight ESM event schema behind it: CEF headers, severity, escaping rules, the predefined extension dictionary, custom and flex fields (cs1-cs6, cn1-cn3, cfp1-cfp4, flexString, flexDate), user-defined extensions, date formats, and ESM data fields with script aliases. Use when generating, parsing, validating, or mapping logs to or from CEF, building ArcSight SmartConnector or FlexConnector integrations, ingesting CEF into a SIEM such as Microsoft Sentinel CommonSecurityLog, or when the user mentions CEF payloads, pipe-delimited CEF:0 headers, or ArcSight event fields.
    0 installs
  4. Tenzir Cim · tenzir bundle
    Answer questions and produce mappings for the Splunk Common Information Model (CIM), including CIM Add-on aliases such as SA-CIM, CommonInformationModel, and SA-CommonInformationModel. Use when the user mentions CIM data models/datamodels/DMs, datasets/data model objects, fields, field aliases, calculated/eval fields, tags, constraints, lookups/lookup tables, macros, normalization, mapping logs or events to CIM, CIM compliance, pytest-splunk-addon, technical add-ons/TAs, Splunk Enterprise Security/ES, data model acceleration, pivots, tstats, or datamodel searches.
    0 installs
  5. Tenzir Ecs · tenzir bundle
    Answer questions and produce mappings for Elastic Common Schema (ECS): Elastic/Elasticsearch fields, fieldsets, data types, allowed values, categorization (`event.kind`, `event.category`, `event.type`, `event.outcome`), custom fields, field reuse, normalization, and OpenTelemetry/OTel/OTLP/SemConv alignment. Use when mapping logs, security telemetry, SIEM detections, network flows, IAM/user activity, cloud/service context, threat intel, or observability metrics/traces into ECS, Elastic Security, Elastic Observability, or Elasticsearch mappings/templates.
    0 installs
  6. Tenzir Edm · tenzir bundle
    Answer questions about the FortiSIEM Event Data Model (EDM), Fortinet's normalized event attribute model. Use when the user asks about the FortiSIEM EDM, FortiSIEM event attributes, attribute types or display names, FortiSIEM data models or event categories, FortiSIEM parser attribute mapping, or mapping events into FortiSIEM.
    0 installs
  7. Tenzir Udm · tenzir bundle
    Answer questions about Google SecOps / Chronicle UDM (Unified Data Model) message/record schemas, event and entity modeling, field paths, enums, normalization guidance, and ingestion payloads. Use when the user maps logs to UDM, asks about UDM field names or field-name forms, chooses event_type or entity_type, works with YARA-L, Detect Engine, or CBN references, or mentions common UDM areas such as nouns, security_result, network, extensions, or Entity context.
    0 installs
  8. Tenzir Asim · tenzir bundle
    Answer questions about Microsoft Sentinel ASIM (Advanced Security Information Model). Use whenever the user asks about ASIM schemas, normalized Microsoft Sentinel fields, field classes, aliases, schema mapping, or mapping events and entities into ASIM.
    0 installs
  9. Tenzir Leef · tenzir bundle
    Answer questions and produce mappings for IBM LEEF (Log Event Extended Format), the QRadar event format: LEEF 1.0/2.0 headers, delimiters, predefined event attributes, custom event keys, devTime/devTimeFormat timestamps, and syslog transport. Use when generating, parsing, validating, or mapping logs to or from LEEF, building QRadar or JSA integrations and DSMs, or when the user mentions LEEF payloads, QRadar log formats, QID mapping, or key=value events with a LEEF: header.
    0 installs
  10. Tenzir Ocsf · tenzir bundle
    Answer questions about OCSF (Open Cybersecurity Schema Framework). Use when the user asks about OCSF classes, objects, attributes, profiles, extensions, or event normalization.
    0 installs