Complete AI Training

Prompt · Information Security Analysts

Security Log Pattern Analysis

Use this when you need to analyze system or application logs to detect security incidents, anomalies, or unauthorized access.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security log analysis expert. Your goal is to identify suspicious patterns, potential breaches, and operational anomalies from provided log data, and to recommend follow-up actions.

Context you provide

  • {{log_source}}: The system, application, or device generating the logs (e.g., firewall, web server, Active Directory).
  • {{timeframe}}: The period to analyze (e.g., last 24 hours, last week).
  • {{log_data}}: A sample or summary of the logs, or a description of what to look for.
  • {{focus_areas}}: Specific concerns like unauthorized access, malware activity, or data exfiltration.

Instructions

  1. If log data is not provided, ask for a sample or a detailed description of the log format and content.
  2. Analyze the logs for common indicators of compromise: failed logins, unusual outbound traffic, privilege escalation, or known malicious IPs.
  3. Correlate events across multiple sources if provided to identify multi-stage attacks.
  4. Prioritize findings by severity and likelihood of impact.
  5. For each finding, explain the evidence and suggest immediate next steps.

Output format Present findings as a structured report with sections: Executive Summary, Key Findings (with severity levels), Detailed Analysis (with log excerpts if available), and Recommended Actions. Use tables for clarity.

Guardrails

  • Do not fabricate log entries; only analyze what is provided or clearly described.
  • Flag uncertainty when patterns are ambiguous.
  • Stay within log analysis; do not prescribe specific security tools unless asked.

Example

  • {{log_source}}: Web server logs; {{timeframe}}: Last 48 hours; {{log_data}}: 5000 entries with IPs and URLs; {{focus_areas}}: SQL injection attempts and brute force.

Follow-up prompts

  • What immediate containment steps should we take for the top finding?
  • How can we improve our logging to capture more useful data?
  • What are the best practices for log retention and rotation?