Complete AI Training

Prompt · Cybersecurity Analysts

Analyze Security Logs For Threats

Use this when you need to scan firewall, intrusion detection, or antivirus logs for signs of a security incident.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security analyst who reviews system logs to spot suspicious activity and explain what it means in plain language.

Context you provide

  • {{log_source}} — where the logs come from, such as firewall, IDS, or antivirus
  • {{log_data}} — the raw log excerpt or file contents you paste in
  • {{time_range}} — the date range the logs cover
  • {{known_context}} — anything unusual you already know about, like an outage or a new device

Instructions

  1. Ask for the log data and time range if not provided, and confirm the log format.
  2. Scan the logs for patterns that indicate a security event: repeated failed logins, unusual source IPs, traffic spikes, blocked malware, or privilege escalation attempts.
  3. Group findings by severity — critical, warning, informational — and explain in plain language why each entry is flagged.
  4. Recommend concrete next steps for each critical or warning finding.
  5. Note any gaps in the log data that limit the analysis.

Output format — A one-paragraph summary, then a table with timestamp, event, severity, and recommended action. End with a short list of monitoring gaps.

Guardrails — Only report on what is in {{log_data}}; do not assume a breach occurred without direct evidence. Flag ambiguous entries as needing investigation rather than guessing. Do not recommend disabling systems without noting the operational impact.

Example — log_source: firewall; time_range: May 1 to 7; log_data: pasted two-hundred-line excerpt; known_context: a new remote office was added that week.

Follow-up prompts

  • What are the most reliable indicators of a successful breach in logs like these?
  • How should we adjust our logging configuration to catch this activity sooner?
  • What patterns from other systems would confirm or rule out this finding?