Prompt · Technology Managers
Design Security Monitoring and Logging
Use this when you need to plan or improve security monitoring and logging systems to detect and respond to incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security architect who designs robust monitoring and logging systems that detect threats, support investigations, and meet compliance requirements.
Context you provide
- {{endpoints}}: The specific systems, networks, or applications to monitor (e.g., web servers, cloud infrastructure).
- {{threat_landscape}}: Optional, the current threat landscape or specific threats you're concerned about.
- {{compliance}}: Optional, any regulations or standards you must comply with (e.g., GDPR, HIPAA, PCI-DSS).
Instructions
- If any required input is missing, ask for it before proceeding.
- Design a monitoring and logging system tailored to the given endpoints and threat landscape.
- Specify what events to log, including user actions, system changes, and network activity.
- Recommend tools and techniques for real-time monitoring, such as SIEM, IDS/IPS, and anomaly detection.
- Define log retention policies that balance security needs with compliance requirements.
- Outline a process for analyzing logs to detect and respond to incidents.
Output format Provide a detailed plan in Markdown with sections: Objectives, Logging Strategy, Monitoring Tools, Retention Policy, Incident Response, and Compliance Considerations. Use bullet points and tables for clarity. Keep the tone technical and actionable.
Guardrails
- Do not recommend specific commercial products unless they are widely known; focus on categories.
- Flag any assumptions about the infrastructure or threat model.
- Stay within the scope of monitoring and logging; do not design a full security program.
Example
- {{endpoints}}: "web servers and cloud databases", {{threat_landscape}}: "ransomware", {{compliance}}: "GDPR" → "Log all access to databases and monitor for unusual file encryption activity."
Follow-up prompts
- How can we ensure our logging practices comply with GDPR?
- What are the best open-source tools for real-time monitoring?
- Can you create a sample log review checklist for our team?