siem-quickstart
Security monitoring and SIEM setup with Elastic Security
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Security monitoring and SIEM setup with Elastic Security
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
Debug and analyze LLM eval runs — view traces, compare runs, investigate failures, track costs. Use when debugging @kbn/evals failures, comparing eval runs, or analyzing LLM performance.
Start your security session with a personalized briefing — attacks, alerts, cases, rules, threat intel. Use as the first thing when starting security work.
Guide users from zero to a working Elastic cluster — Cloud or on-prem, connection config, first queries, and next steps.
Interactive guide for creating an APM service overview dashboard — discovers service data, presents metrics, and creates a tailored dashboard.
Interactive guide for creating SLOs from discovered APM and metric data — identifies candidates, lets user configure targets, and creates SLOs.
Create, configure, and manage Elasticsearch indices — mappings, settings, templates, data streams, and lifecycle policies.
| name | siem-quickstart |
| description | Security monitoring and SIEM setup with Elastic Security |
Use when the user wants to set up security monitoring or SIEM with Elastic.
discover_security_data to auto-detect existing security data sources (Endpoint, Auditbeat, cloud logs, network data).get_security_summary to get a security posture assessment with coverage gaps and MITRE ATT&CK mapping.create_cloud_project; for on-prem: use the Docker stack in examples/on-prem-docker/ (ES, Kibana, Fleet, APM server, agents). Ensure Security is enabled (default in Cloud; for Docker it's in the stack).siem_quickstart, then kibana_api for detection rule management.discover_security_data again to confirm agents are reporting.get_security_summary to verify detection coverage and alert flow.