Install the "siem-logging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/siem-logging into .claude/skills/siem-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "siem-logging", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill siem-logging -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "siem-logging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/siem-logging into .agents/skills/siem-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "siem-logging", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill siem-logging -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "siem-logging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/siem-logging into .cursor/skills/siem-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "siem-logging", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill siem-logging -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "siem-logging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/siem-logging into .gemini/skills/siem-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "siem-logging", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add ancoleman/ai-design-components --skill siem-logging -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "siem-logging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/siem-logging into .github/skills/siem-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "siem-logging", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill siem-logging -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "siem-logging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/siem-logging into .opencode/skills/siem-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "siem-logging", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
siem-logging
GitHub stars
526
Token cost
~3.4k tokens
SKILL.md length
1,031 words
Files
19 (incl. scripts, references)
Skills in repo
75
Repo updated
First seen
Licence
MIT
At a glance
Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.
Works in 4 steps: Detection Rule Created - Conservative… → Baseline Period (2-4 weeks) - Collect… → Tuning Phase - Add whitelisting, adjust… → …
Implementing centralized security logging
SKILL.md covers Purpose, When to Use This Skill, SIEM Platform Selection and Detection Rules, plus 9 more sections
Calls pip, aws and git; reaches github.com and attack.mitre.org
What it does
Siem Logging is an agent skill from ancoleman/ai-design-components. Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. Use when implementing centralized security logging, writing detection rules, or meeting audit requirements across cloud and on-premise infrastructure.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts and reference files (for example `examples/architectures/elk-stack-docker-compose.yml`, `examples/architectures/fluentd-kubernetes-daemonset.yaml` and `examples/architectures/wazuh-docker-compose.yml`).
It sits in Security, covering Security operations and Observability. It works with Microsoft Azure, Microsoft Sentinel, Amazon Web Services and Splunk. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.
When your agent uses it
Implementing centralized security logging
Writing detection rules
Meeting audit requirements across cloud and on-premise infrastructure
Example prompts
“/siem-logging”
Requirements
Python 3
Docker
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Detection Rule Created - Conservative thresholds, deploy to production
2Baseline Period (2-4 weeks) - Collect alert data, tag true/false positives
Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
pip
aws
git
docker-compose
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
attack.mitre.org
Also links to:
elastic.co
azure.microsoft.com
wazuh.com
splunk.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Siem Logging loads about 3.4k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,031 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~71
When it runs· the whole SKILL.md, loaded when a task matches
~3.4k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~15k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/siem-logging/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
siem-logging
description
Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. Use when implementing centralized security logging, writing detection rules, or meeting audit requirements across cloud and on-premise infrastructure.
SIEM Logging
Purpose
Configure comprehensive security logging infrastructure using SIEM platforms (Elastic SIEM, Microsoft Sentinel, Wazuh, Splunk) to detect threats, investigate incidents, and maintain compliance audit trails. This skill covers platform selection, log aggregation architecture, detection rule development (SIGMA format and platform-specific), alert tuning, and retention policies for regulatory compliance (GDPR, HIPAA, PCI DSS, SOC 2).
When to Use This Skill
Use this skill when:
Implementing centralized security event monitoring across infrastructure
Writing threat detection rules for authentication failures, privilege escalation, data exfiltration
Designing log aggregation for multi-cloud environments (AWS, Azure, GCP, Kubernetes)
Meeting compliance requirements for log retention and audit trails
Tuning security alerts to reduce false positives and alert fatigue
Calculating costs for high-volume security logging (TB/day scale)
Integrating security logging with incident response workflows
Microsoft/Azure expertise → Microsoft Sentinel (Azure ecosystem)
Generalists or limited resources → Wazuh (easiest learning curve)
Platform Comparison Summary
Platform
Cost
Deployment
Best For
Elastic SIEM
$$$
Cloud/Self-Hosted
Multi-cloud, customization needs, DevOps teams
Microsoft Sentinel
$$$
Cloud (Azure)
Azure-heavy orgs, built-in SOAR, cloud-first
Wazuh
Free
Self-Hosted
Cost-conscious, SMBs, compliance requirements
Splunk ES
$$$$$
Cloud/On-Prem
Large enterprises, massive scale, unlimited budget
For detailed feature comparison, see references/platform-comparison.md.
Detection Rules
Universal Format: SIGMA Rules
SIGMA provides a universal detection rule format that compiles to any SIEM query language (Elastic EQL, Splunk SPL, Microsoft KQL).
SIGMA Rule Structure:
yaml
title: Multiple Failed Login Attempts from Single Source
id: 8a9e3c7f-4b2d-4e8a-9f1c-2d5e6f7a8b9c
status: stable
description: Detects potential brute force attacks (10+ failed logins in 10 minutes)
author: Security Team
date: 2025/12/03
references:
- https://attack.mitre.org/techniques/T1110/
tags:
- attack.credential_access
- attack.t1110
logsource:
category: authentication
product: linux
detection:
selection:
event.type: authentication
event.outcome: failure
timeframe: 10m
condition: selection | count() by source.ip > 10
level: high
Compile SIGMA to Platform-Specific:
bash
# Install SIGMA compiler
pip install sigma-cli
# Compile to Elastic EQL
sigmac -t es-eql sigma_rule.yml
# Compile to Splunk SPL
sigmac -t splunk sigma_rule.yml
# Compile to Microsoft KQL
sigmac -t kusto sigma_rule.yml
Platform-Specific Detection Formats
Elastic EQL (Event Query Language):
eql
sequence by user.name with maxspan=5m
[process where process.name == "powershell.exe" and
process.args : ("Invoke-WebRequest", "iwr", "wget")]
[process where process.parent.name == "powershell.exe"]
Microsoft Sentinel KQL:
kql
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != 0 // Failed login
| summarize FailedAttempts=count() by UserPrincipalName, IPAddress
| where FailedAttempts >= 10
Splunk SPL:
spl
index=web_logs sourcetype=access_combined
| rex field=uri "(?<sql_keywords>union|select|insert|update|delete)"
| where isnotnull(sql_keywords)
| stats count by src_ip, uri
| where count > 5
# Instead of: Single event alert
- alert_on: "Failed authentication"
# Use: Correlated pattern
- alert_on:
- "Failed authentication (5+ times)"
- AND "From new IP address"
- AND "Successful authentication follows"
- WITHIN: 30 minutes
Target Alert Metrics
Metric
Target
Total Alerts/Day
<100
True Positive Rate
>30%
Mean Time to Investigate
<15 min
False Positive Rate
<50%
Critical Alerts/Day
<10
For comprehensive alert tuning strategies, see references/alert-tuning-strategies.md.
Quick Start
Deploy Wazuh:git clone https://github.com/wazuh/wazuh-docker.git && cd wazuh-docker/single-node && docker-compose up -d (see examples/architectures/wazuh-docker-compose.yml)
Create SIGMA Rule: See examples/sigma-rules/brute-force-detection.yml for SSH brute force detection template
Elastic Cloud: Sign up at cloud.elastic.co, create Security tier deployment, install Elastic Agent on endpoints
Integration with Related Skills
observability skill:
Route security logs to SIEM, performance logs to observability platform
Siem Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Siem Logging compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Siem Logging this skillancoleman/ai-design-components
Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…
Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps…
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e.
Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.
Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. Siem Logging is an agent skill from ancoleman/ai-design-components. Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.
When should I use Siem Logging?
Siem Logging fits situations like: implementing centralized security logging; writing detection rules; meeting audit requirements across cloud and on-premise infrastructure.
How do I install Siem Logging in Claude Code?
Run `npx skills add ancoleman/ai-design-components --skill siem-logging -a claude-code`. Or copy the skill folder (skills/siem-logging in ancoleman/ai-design-components) into .claude/skills/siem-logging in your project. Claude Code loads it when a task matches its description.
How do I install Siem Logging in Codex?
Run `npx skills add ancoleman/ai-design-components --skill siem-logging -a codex`. Or copy the skill folder (skills/siem-logging in ancoleman/ai-design-components) into .agents/skills/siem-logging in your project. Codex loads it when a task matches its description.
Can I use Siem Logging in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill siem-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/siem-logging, .gemini/skills/siem-logging, .github/skills/siem-logging and .opencode/skills/siem-logging in your project.
What does Siem Logging need to run?
Going by SKILL.md and its folder, Siem Logging needs the command-line tools its instructions call (pip, aws, git and docker-compose). Our summary lists: Python 3; Docker.
Does Siem Logging access the network?
SKILL.md names 6 domains. In commands or code: github.com and attack.mitre.org; the agent is likely to contact these when it follows the instructions. As links in the text: elastic.co, azure.microsoft.com, wazuh.com and splunk.com. This is read from the text; nothing was executed.
Is Siem Logging safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Siem Logging use?
Siem Logging is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Siem Logging use?
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.
What are the alternatives to Siem Logging?
Skills that share tags, products or a category with Siem Logging: Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Cloud Siem With Sentinel (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Ecs Operation Review (aws/tools-for-devops-agent, 100 stars) and Hunting For Living Off The Cloud Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Siem Logging?
ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.