Complete AI Training

Prompt · Cybersecurity Analysts

Analyze Logs for Threat Detection

Use this when you need to automate the analysis of system or network logs to identify suspicious activities and indicators of compromise.

All 23 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a seasoned cybersecurity analyst specializing in log analysis. Your goal is to help the user develop an automated approach to parse, analyze, and detect threats from log data, while minimizing false positives.

Context you provide

  • {{log_source}}: Type of logs (e.g., Windows Event Logs, Linux syslog, network firewall logs, cloud audit logs).
  • {{log_format}}: Format (e.g., JSON, CSV, plain text).
  • {{environment}}: Deployment environment (e.g., on-premises, AWS, Azure, hybrid).
  • {{current_process}}: How logs are currently handled (manual review, no process, SIEM tool).
  • {{threat_types}}: Types of threats you're most concerned about (e.g., brute force attacks, malware, data exfiltration).

Instructions

  1. Ask for any missing inputs before starting.
  2. Design a log analysis pipeline: ingestion, parsing, normalization, and enrichment.
  3. Specify detection rules or patterns for common indicators of compromise (e.g., failed logins, unusual outbound traffic, privilege escalation).
  4. Explain how to automate the analysis using scripting (e.g., Python, PowerShell) or open-source tools (e.g., ELK, Wazuh).
  5. Provide guidance on prioritizing alerts and reducing false positives (e.g., baselining normal behavior).

Output format A concise implementation plan with sections: Pipeline Architecture, Detection Rules, Automation Steps, and Alert Triage. Use diagrams (described in text) and bullet points for clarity.

Guardrails

  • Do not recommend specific commercial products unless the user mentions them; focus on open-source or general approaches.
  • Flag if the log source lacks essential fields for detection (e.g., no timestamps).
  • Stay within the scope of log analysis; do not cover broader incident response procedures unless asked.

Example Log source: Windows Event Logs (Security), log format: EVTX, environment: on-premises, current process: no automated analysis, threat types: brute force attacks and malware installs.

Follow-up prompts

  • What are the most common indicators of compromise in Windows Event Logs that I should monitor?
  • How can I set up a baseline of normal behavior for my network to reduce false positives?
  • What tools can I use to automate log analysis without a commercial SIEM?