Agent skill

Siem Logging

by ancoleman in ancoleman/ai-design-components

Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

MITAuto-check passedSecurity

Install Siem Logging

skills CLI
$ npx skills add ancoleman/ai-design-components --skill siem-logging -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ancoleman/ai-design-components siem-logging --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/siem-logging .claude/skills/siem-logging && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
siem-logging
GitHub stars
526
Token cost
~3.4k tokens
SKILL.md length
1,031 words
Files
19 (incl. scripts, references)
Skills in repo
75
Repo updated
First seen
Licence
MIT

At a glance

Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

  • Works in 4 steps: Detection Rule Created - Conservative… → Baseline Period (2-4 weeks) - Collect… → Tuning Phase - Add whitelisting, adjust… → …
  • Implementing centralized security logging
  • SKILL.md covers Purpose, When to Use This Skill, SIEM Platform Selection and Detection Rules, plus 9 more sections
  • Calls pip, aws and git; reaches github.com and attack.mitre.org

What it does

Siem Logging is an agent skill from ancoleman/ai-design-components. Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. Use when implementing centralized security logging, writing detection rules, or meeting audit requirements across cloud and on-premise infrastructure.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts and reference files (for example `examples/architectures/elk-stack-docker-compose.yml`, `examples/architectures/fluentd-kubernetes-daemonset.yaml` and `examples/architectures/wazuh-docker-compose.yml`).

It sits in Security, covering Security operations and Observability. It works with Microsoft Azure, Microsoft Sentinel, Amazon Web Services and Splunk. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.

When your agent uses it

  • Implementing centralized security logging
  • Writing detection rules
  • Meeting audit requirements across cloud and on-premise infrastructure

Example prompts

  • “/siem-logging”

Requirements

  • Python 3
  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Detection Rule Created - Conservative thresholds, deploy to production
  2. Baseline Period (2-4 weeks) - Collect alert data, tag true/false positives
  3. Tuning Phase - Add whitelisting, adjust thresholds, refine correlation
  4. Continuous Improvement - Weekly metrics review, monthly effectiveness review

What it can do on your machine

Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • pip
    • aws
    • git
    • docker-compose

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • attack.mitre.org

    Also links to:

    • elastic.co
    • azure.microsoft.com
    • wazuh.com
    • splunk.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Siem Logging loads about 3.4k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,031 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 1,031 words, ~3,444 tokens.

Download SKILL.mdSave it as .claude/skills/siem-logging/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
siem-logging
description
Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. Use when implementing centralized security logging, writing detection rules, or meeting audit requirements across cloud and on-premise infrastructure.

SIEM Logging

Purpose

Configure comprehensive security logging infrastructure using SIEM platforms (Elastic SIEM, Microsoft Sentinel, Wazuh, Splunk) to detect threats, investigate incidents, and maintain compliance audit trails. This skill covers platform selection, log aggregation architecture, detection rule development (SIGMA format and platform-specific), alert tuning, and retention policies for regulatory compliance (GDPR, HIPAA, PCI DSS, SOC 2).

When to Use This Skill

Use this skill when:

  • Implementing centralized security event monitoring across infrastructure
  • Writing threat detection rules for authentication failures, privilege escalation, data exfiltration
  • Designing log aggregation for multi-cloud environments (AWS, Azure, GCP, Kubernetes)
  • Meeting compliance requirements for log retention and audit trails
  • Tuning security alerts to reduce false positives and alert fatigue
  • Calculating costs for high-volume security logging (TB/day scale)
  • Integrating security logging with incident response workflows

SIEM Platform Selection

Quick Decision Framework

Choose SIEM platform based on:

Budget Considerations:

  • Unlimited budget → Splunk Enterprise Security (enterprise features, proven scale)
  • Moderate budget ($50k-$500k/year) → Microsoft Sentinel or Elastic SIEM (cloud-native, flexible)
  • Tight budget (<$50k/year) → Wazuh (free, open-source XDR/SIEM)

Infrastructure Context:

  • Heavy Azure investment → Microsoft Sentinel (native integration, built-in SOAR)
  • Heavy AWS investment → AWS Security Lake + OpenSearch (AWS-native)
  • Multi-cloud or on-premise → Elastic SIEM or Wazuh (platform-agnostic)

Data Volume:

  • >1 TB/day → Splunk or Elastic Cloud (proven at scale)
  • 100 GB - 1 TB/day → Microsoft Sentinel or Elastic SIEM
  • <100 GB/day → Wazuh or Sentinel 50 GB tier

Team Expertise:

  • Elasticsearch experience → Elastic SIEM (familiar tooling)
  • Microsoft/Azure expertise → Microsoft Sentinel (Azure ecosystem)
  • Generalists or limited resources → Wazuh (easiest learning curve)
Platform Comparison Summary
PlatformCostDeploymentBest For
Elastic SIEM$$$Cloud/Self-HostedMulti-cloud, customization needs, DevOps teams
Microsoft Sentinel$$$Cloud (Azure)Azure-heavy orgs, built-in SOAR, cloud-first
WazuhFreeSelf-HostedCost-conscious, SMBs, compliance requirements
Splunk ES$$$$$Cloud/On-PremLarge enterprises, massive scale, unlimited budget

For detailed feature comparison, see references/platform-comparison.md.

Detection Rules

Universal Format: SIGMA Rules

SIGMA provides a universal detection rule format that compiles to any SIEM query language (Elastic EQL, Splunk SPL, Microsoft KQL).

SIGMA Rule Structure:

yaml
title: Multiple Failed Login Attempts from Single Source
id: 8a9e3c7f-4b2d-4e8a-9f1c-2d5e6f7a8b9c
status: stable
description: Detects potential brute force attacks (10+ failed logins in 10 minutes)
author: Security Team
date: 2025/12/03
references:
  - https://attack.mitre.org/techniques/T1110/
tags:
  - attack.credential_access
  - attack.t1110
logsource:
  category: authentication
  product: linux
detection:
  selection:
    event.type: authentication
    event.outcome: failure
  timeframe: 10m
  condition: selection | count() by source.ip > 10
level: high

Compile SIGMA to Platform-Specific:

bash
# Install SIGMA compiler
pip install sigma-cli

# Compile to Elastic EQL
sigmac -t es-eql sigma_rule.yml

# Compile to Splunk SPL
sigmac -t splunk sigma_rule.yml

# Compile to Microsoft KQL
sigmac -t kusto sigma_rule.yml
Platform-Specific Detection Formats

Elastic EQL (Event Query Language):

eql
sequence by user.name with maxspan=5m
  [process where process.name == "powershell.exe" and
   process.args : ("Invoke-WebRequest", "iwr", "wget")]
  [process where process.parent.name == "powershell.exe"]

Microsoft Sentinel KQL:

kql
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != 0  // Failed login
| summarize FailedAttempts=count() by UserPrincipalName, IPAddress
| where FailedAttempts >= 10

Splunk SPL:

spl
index=web_logs sourcetype=access_combined
| rex field=uri "(?<sql_keywords>union|select|insert|update|delete)"
| where isnotnull(sql_keywords)
| stats count by src_ip, uri
| where count > 5

For comprehensive detection rule examples, see:

  • examples/sigma-rules/ - Universal SIGMA detection rules
  • examples/elastic-eql/ - Elastic-specific queries
  • examples/microsoft-kql/ - Microsoft Sentinel queries
  • examples/splunk-spl/ - Splunk searches
  • references/detection-rules-guide.md - Complete guide

Log Aggregation Architecture

Centralized Architecture

Single SIEM instance for all logs. Use when:

  • Single region deployment
  • Small to medium volumes (<1 TB/day)
  • Single cloud provider or on-premise
  • Limited security team (1-10 analysts)

Architecture:

Application Servers → Log Shippers (Filebeat/Fluentd)
                   ↓
              Log Aggregator (Logstash/Fluentd)
                   ↓
          SIEM Platform (Elasticsearch/Splunk/Sentinel)
                   ↓
            Security Analysts (Dashboard/Alerts)
Distributed Architecture (Multi-Region)

Regional SIEM instances with global aggregation. Use when:

  • Multi-region global deployments
  • Data residency requirements (GDPR, sovereignty)
  • High volumes (>1 TB/day per region)
  • Low-latency requirements for regional analysis

Architecture:

Global SIEM (Correlation, Threat Intelligence)
    ↓
Regional SIEM (US-East) | Regional SIEM (EU-West) | Regional SIEM (APAC)
    ↓                        ↓                          ↓
Local Logs               Local Logs                 Local Logs
Cloud-Native Architecture

Leverage managed cloud services. Use when:

  • Cloud-first organization (AWS/Azure/GCP)
  • Want to avoid managing infrastructure
  • Elastic workloads with variable log volumes
  • Budget for cloud service costs

AWS Example:

CloudTrail + VPC Flow Logs + GuardDuty
              ↓
       AWS Security Lake (S3 Data Lake)
              ↓
    OpenSearch (Analysis) | Athena (SQL Queries)

For deployment examples, see:

  • examples/architectures/elk-stack-docker-compose.yml
  • examples/architectures/fluentd-kubernetes-daemonset.yaml
  • examples/architectures/aws-security-lake-terraform/
  • examples/architectures/wazuh-docker-compose.yml
  • references/cloud-native-logging.md

Log Aggregation Tools

Fluentd (Cloud-Native): CNCF project for Kubernetes and multi-cloud environments. Use for containerized applications.

Logstash (Elastic Stack): Native Elasticsearch integration. Use for advanced parsing (grok patterns) and data enrichment.

For complete configuration examples, see examples/logstash-pipelines/ and references/cloud-native-logging.md.

Log Retention and Compliance

Compliance Requirements
FrameworkMinimum RetentionHot StorageWarm StorageCold Storage
GDPR30-90 days7 days30 days60 days
HIPAA6 years30 days180 days6 years
PCI DSS1 year90 days180 days1 year
SOC 21 year30 days90 days1 year
Storage Tiering Strategy

Hot Tier (SSD, Real-Time):

  • Last 7-30 days
  • Real-time indexing and fast queries
  • Most expensive ($0.10/GB/month)

Warm Tier (HDD, Recent):

  • 30-90 days
  • Read-only indices, occasional searches
  • Moderate cost ($0.05/GB/month)

Cold Tier (S3/Blob, Archive):

  • 90 days to retention limit
  • Searchable snapshots, rare queries
  • Cheapest ($0.01/GB/month)

Example Cost Optimization:

500 GB/day log volume, 1-year retention

Hot (30 days):   15 TB @ $0.10/GB = $1,500/month
Warm (60 days):  30 TB @ $0.05/GB = $1,500/month
Cold (275 days): 137.5 TB @ $0.01/GB = $1,375/month

Total: $4,375/month = $52,500/year

vs. Hot-only: $18,250/month = $219,000/year
Savings: 76% ($166,500/year)

For detailed retention policies and cost optimization, see:

  • references/log-retention-policies.md
  • references/cost-optimization.md
  • scripts/cost-calculator.py
Show full SKILL.md (417 more words)Show less

What to Log (Security Events)

Critical Events (MUST LOG):

  • Authentication: Login attempts, MFA, password changes, privilege escalation
  • Authorization: Permission changes, role modifications, access denials
  • Data Access: Sensitive database/file access, API calls, exports
  • Network: Connections, firewall denials, VPN, DNS queries
  • System: Service changes, configuration modifications, software installations

Severity Levels: Failed auth (3+): HIGH alert | Privilege escalation: CRITICAL alert | Data export: HIGH alert | Config change: MEDIUM (no alert)

Alert Tuning and Noise Reduction

Alert Lifecycle
  1. Detection Rule Created - Conservative thresholds, deploy to production
  2. Baseline Period (2-4 weeks) - Collect alert data, tag true/false positives
  3. Tuning Phase - Add whitelisting, adjust thresholds, refine correlation
  4. Continuous Improvement - Weekly metrics review, monthly effectiveness review
Noise Reduction Techniques

Whitelisting (Known-Safe Patterns):

yaml
# Example: Allow scanner IPs
- rule_id: brute_force_detection
  whitelist:
    - source_ip: "10.0.0.100"  # Security scanner
    - user_agent: "Nagios"      # Monitoring system

Threshold Tuning:

yaml
# Before: Too sensitive (500 alerts/day, 5% true positive rate)
- rule: failed_login_attempts
  threshold: 3 attempts in 5 minutes

# After: Tuned (50 alerts/day, 40% true positive rate)
- rule: failed_login_attempts
  threshold: 10 attempts in 10 minutes

Multi-Event Correlation:

yaml
# Instead of: Single event alert
- alert_on: "Failed authentication"

# Use: Correlated pattern
- alert_on:
    - "Failed authentication (5+ times)"
    - AND "From new IP address"
    - AND "Successful authentication follows"
    - WITHIN: 30 minutes
Target Alert Metrics
MetricTarget
Total Alerts/Day<100
True Positive Rate>30%
Mean Time to Investigate<15 min
False Positive Rate<50%
Critical Alerts/Day<10

For comprehensive alert tuning strategies, see references/alert-tuning-strategies.md.

Quick Start

Deploy Wazuh: git clone https://github.com/wazuh/wazuh-docker.git && cd wazuh-docker/single-node && docker-compose up -d (see examples/architectures/wazuh-docker-compose.yml)

Create SIGMA Rule: See examples/sigma-rules/brute-force-detection.yml for SSH brute force detection template

Elastic Cloud: Sign up at cloud.elastic.co, create Security tier deployment, install Elastic Agent on endpoints

observability skill:

  • Route security logs to SIEM, performance logs to observability platform
  • Shared log aggregation infrastructure (Fluentd/Logstash)
  • Different analysis purposes (security vs. performance)

incident-management skill:

  • SIEM alerts trigger incident response workflows
  • Integration with PagerDuty, Opsgenie, ServiceNow
  • Automated incident creation for critical security events

security-hardening skill:

  • SIEM monitors security configurations and compliance
  • Detect configuration drift from CIS benchmarks
  • Alert on security policy violations

building-ci-pipelines skill:

  • Log CI/CD security events (deployments, secrets access)
  • GitHub Actions/GitLab CI integration with SIEM
  • Supply chain security monitoring

secret-management skill:

  • Audit all secrets access operations
  • HashiCorp Vault/AWS Secrets Manager logs to SIEM
  • Detect unauthorized secrets access attempts

Reference Documentation

Detailed Guides
  • references/platform-comparison.md - Comprehensive SIEM platform feature comparison
  • references/detection-rules-guide.md - Detection rule formats (SIGMA, EQL, KQL, SPL)
  • references/log-retention-policies.md - Compliance requirements and retention strategies
  • references/cloud-native-logging.md - AWS, Azure, GCP, Kubernetes logging setup
  • references/alert-tuning-strategies.md - False positive reduction and alert optimization
  • references/cost-optimization.md - Storage tiering and cost management
Working Examples
  • examples/sigma-rules/ - Universal SIGMA detection rules (10+ examples)
  • examples/elastic-eql/ - Elastic Event Query Language queries
  • examples/microsoft-kql/ - Microsoft Sentinel Kusto queries
  • examples/splunk-spl/ - Splunk Search Processing Language
  • examples/architectures/ - Complete deployment examples (Docker, Kubernetes, Terraform)
  • examples/logstash-pipelines/ - Logstash pipeline configurations
Utility Scripts
  • scripts/sigma-to-elastic.sh - Convert SIGMA rules to Elastic EQL
  • scripts/cost-calculator.py - Estimate SIEM costs based on volume and retention

Official Documentation

© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts, references) in skills/siem-logging of ancoleman/ai-design-components.

  • SKILL.md
  • examples/architectures/elk-stack-docker-compose.yml
  • examples/architectures/fluentd-kubernetes-daemonset.yaml
  • examples/architectures/wazuh-docker-compose.yml
  • examples/detection-rules/brute-force-detection.yaml
  • examples/detection-rules/privilege-escalation.yaml
  • examples/sigma-rules/brute-force-detection.yml
  • examples/sigma-rules/data-exfiltration.yml
  • examples/sigma-rules/lateral-movement.yml
  • examples/sigma-rules/privilege-escalation.yml
  • outputs.yaml
  • references/alert-tuning-strategies.md
  • references/cloud-native-logging.md
  • references/cost-optimization.md
  • references/detection-rules-guide.md
  • references/log-retention-policies.md
  • … and 3 more

Open the folder on GitHubat commit 76551b7

Compare with similar skills

Siem Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Siem Logging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Siem Logging this skillancoleman/ai-design-components526—~3.4kAutomated safety check: PassMIT
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Building Cloud Siem With Sentinelmukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.0
Ecs Operation Reviewaws/tools-for-devops-agent100—~4.8kAutomated safety check: PassApache-2.0
Hunting For Living Off The Cloud Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~925Automated safety check: PassApache-2.0
Analyzing Azure Activity Logs For Threatsmukul975/Anthropic-Cybersecurity-Skills34k—~609Automated safety check: PassApache-2.0

Similar skills

  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Cloud Siem With Sentinel

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps…

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    100 GitHub stars~4.8k tokensUpdated today
    SecurityAuto-check passed
  • Hunting For Living Off The Cloud Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e.

    34k GitHub stars~925 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Azure Activity Logs For Threats

    mukul975/Anthropic-Cybersecurity-Skills

    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

    34k GitHub stars~609 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Detection Rules With Sigma

    mukul975/Anthropic-Cybersecurity-Skills

    Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ancoleman/ai-design-components

All 75 skills in this repo
  • Building AI Chat

    ancoleman/ai-design-components

    Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.

    526 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check passed
  • Building Forms

    ancoleman/ai-design-components

    Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.

    526 GitHub stars~3.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Tables

    ancoleman/ai-design-components

    Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.

    526 GitHub stars~1.8k tokensUpdated 10 mo ago
    Auto-check passed
  • Creating Dashboards

    ancoleman/ai-design-components

    Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    Auto-check passed
  • Designing Layouts

    ancoleman/ai-design-components

    Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.

    526 GitHub stars~1.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Displaying Timelines

    ancoleman/ai-design-components

    Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.

    526 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed

Categories

Questions about Siem Logging

What does Siem Logging do?

Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. Siem Logging is an agent skill from ancoleman/ai-design-components. Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

When should I use Siem Logging?

Siem Logging fits situations like: implementing centralized security logging; writing detection rules; meeting audit requirements across cloud and on-premise infrastructure.

How do I install Siem Logging in Claude Code?

Run `npx skills add ancoleman/ai-design-components --skill siem-logging -a claude-code`. Or copy the skill folder (skills/siem-logging in ancoleman/ai-design-components) into .claude/skills/siem-logging in your project. Claude Code loads it when a task matches its description.

How do I install Siem Logging in Codex?

Run `npx skills add ancoleman/ai-design-components --skill siem-logging -a codex`. Or copy the skill folder (skills/siem-logging in ancoleman/ai-design-components) into .agents/skills/siem-logging in your project. Codex loads it when a task matches its description.

Can I use Siem Logging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill siem-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/siem-logging, .gemini/skills/siem-logging, .github/skills/siem-logging and .opencode/skills/siem-logging in your project.

What does Siem Logging need to run?

Going by SKILL.md and its folder, Siem Logging needs the command-line tools its instructions call (pip, aws, git and docker-compose). Our summary lists: Python 3; Docker.

Does Siem Logging access the network?

SKILL.md names 6 domains. In commands or code: github.com and attack.mitre.org; the agent is likely to contact these when it follows the instructions. As links in the text: elastic.co, azure.microsoft.com, wazuh.com and splunk.com. This is read from the text; nothing was executed.

Is Siem Logging safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Siem Logging use?

Siem Logging is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Siem Logging use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Siem Logging?

Skills that share tags, products or a category with Siem Logging: Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Cloud Siem With Sentinel (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Ecs Operation Review (aws/tools-for-devops-agent, 100 stars) and Hunting For Living Off The Cloud Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Siem Logging?

ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.

Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.