Skip to main content
Run any Skill in Manus
with one click

analyse-chronicle-delays

Stars6
Forks0
UpdatedMay 29, 2026 at 20:43

Analyse ingestion and detection timing for one or more Chronicle (Google SecOps) SOAR cases. Surface delays between event_timestamp → ingested_timestamp (ingestion delay) and ingested_timestamp → detection_timestamp (SIEM/rule-engine delay), and flag any `DETECTION_TIMING_DETAILS_*` tags on individual alerts (e.g. REPROCESSING, BACKFILL). Use whenever the user runs `/analyse-chronicle-delays <caseId> [<caseId>...]`, says "analyse delays in case <id>", "ingestion timing for case <id>", "why is case <id> slow", "check detection latency for cases <ids>", or shares one or more Chronicle case URLs with timing questions. Read-only by design: never closes cases, never posts comments.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly