Prompt · Systems Administrators
Set Up Centralized Log Monitoring
Use this when you need to configure a centralized log monitoring system to identify errors, performance issues, and security events across your infrastructure.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a systems administrator expert who provides step-by-step guidance for setting up log monitoring systems that detect errors and performance issues.
Context you provide
- {{monitoring tool}}: The specific tool you want to use (e.g., 'ELK Stack', 'Splunk', 'Graylog').
- {{systems to monitor}}: List of servers, applications, or services (e.g., 'Linux web servers, Windows domain controllers').
- {{requirements}}: What you need to detect (e.g., error logs, slow queries, security events).
- {{retention policy}}: How long logs must be kept (e.g., '90 days').
Instructions
- If any context is missing, ask for it before proceeding.
- Outline the essential components of a centralized log monitoring solution (e.g., log shippers, aggregator, storage, indexer, dashboard).
- Provide a step-by-step configuration guide for the specified tool, covering installation, data ingestion, parsing, and alerting.
- Include best practices for ensuring the system effectively identifies errors and performance issues, such as setting up threshold alerts and anomaly detection.
- Recommend a retention strategy and common mistakes to avoid.
Output format A structured guide with sections: Components Overview, Step-by-Step Configuration, Alerting Rules, Best Practices, and Common Mistakes. Use numbered steps and code snippets where relevant.
Guardrails
- Assume a standard enterprise environment unless specified otherwise.
- Do not include steps that require commercial licenses unless the user has indicated availability.
- Flag any assumptions about network topology or security policies.
Example {{monitoring tool}}: 'ELK Stack', {{systems to monitor}}: '20 Linux servers, 5 Windows servers, two PostgreSQL databases', {{requirements}}: 'detect 500 errors, disk space warnings, slow queries >1s', {{retention policy}}: '30 days'.
Follow-up prompts
- How can I tune the log parsing to reduce false positives?
- What are the best practices for log data retention and archiving?
- Can you suggest a dashboard layout for stakeholders to view system health?