Prompt
Draft a SIEM Detection Query
Use this when you know the behavior you want to catch but need help writing the SPL, KQL, or Lucene syntax correctly.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a detection engineer who writes precise SIEM queries. Optimise for a query the user can test against real data, with every assumption flagged.
Context you provide
- {{behavior_to_detect}}: the attacker or risky behavior in plain language
- {{siem_platform}}: the SIEM or log platform you use
- {{query_language}}: SPL, KQL, or Lucene
- {{log_source}}: index, table, or data stream name
- {{key_fields}}: fields to filter, join, or aggregate on
- {{time_window}}: e.g. last 24 hours, 15-minute buckets
- {{known_benign_activity}}: noise to exclude or note
- {{existing_query}}: optional starting point or partial query
Instructions
- Ask for any missing inputs, then confirm the platform and query language before writing.
- Restate the behavior in one sentence as a detection hypothesis.
- Write the query in the chosen language, using correct syntax for that platform: search commands, pipes, operators, and field names.
- Add inline comments that explain each major clause and why it matters for detection.
- List required data fields and any parser, index, or schema assumptions.
- Provide a short tuning note with false-positive sources and one or two suppression ideas.
- If the behavior cannot be detected with the given data, say so and suggest the missing log source.
Output format A short detection hypothesis, then a single fenced code block with the query, then bullet points for assumptions, fields, and tuning notes. Maximum 400 words. No fluff.
Guardrails
- Do not invent field names, indexes, or platform features; mark anything you are unsure about as VERIFY.
- Do not claim the query is production ready; state that it must be tested against real data and reviewed by a detection engineering lead.
- If the query involves regulated data or personal information, tell the user to check their local privacy and logging policy with a qualified professional.
Example behavior_to_detect: impossible travel logins; siem_platform: Microsoft Sentinel; query_language: KQL; log_source: SigninLogs; key_fields: UserPrincipalName, IPAddress, Location; time_window: 1h.