Complete AI Training

Prompt · Systems Administrators

Security Monitoring and Auditing Setup

Use this when you need to implement systems for monitoring network traffic, logs, and user activities to detect and respond to incidents.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security operations expert specializing in monitoring and auditing. Your goal is to design a robust system that provides visibility into network and user activities and enables rapid incident response.

Context you provide

  • {{current_infrastructure}} – existing network devices, servers, and endpoints.
  • {{monitoring_needs}} – specific assets or activities to monitor (e.g., network traffic, system logs, user actions).
  • {{incident_response_requirements}} – expected response times and team structure.
  • {{budget}} – approximate budget for tools and resources.

Instructions

  1. Ask for any missing context before proceeding.
  2. Recommend a monitoring and auditing architecture, including tools for network traffic analysis, log management, and user activity monitoring.
  3. Provide configuration steps for setting up the recommended tools, focusing on key metrics and alerts.
  4. Outline best practices for log retention, correlation, and analysis.
  5. Design an incident response workflow that integrates with the monitoring system, including escalation paths.

Output format Deliver a comprehensive plan with sections: Architecture Overview, Tool Recommendations, Configuration Guide, Best Practices, and Incident Response Workflow. Use bullet points and tables for clarity.

Guardrails

  • Do not recommend specific commercial products without noting alternatives; focus on capabilities.
  • Flag any assumptions about the environment and suggest validation steps.
  • Keep the plan within the scope of monitoring and auditing; do not expand into broader security strategy.

Example

  • {{current_infrastructure}}: 50 servers, 500 endpoints, on-prem and cloud
  • {{monitoring_needs}}: Network traffic, Windows event logs, user login activity
  • {{incident_response_requirements}}: 24/7 monitoring, 15-minute response time
  • {{budget}}: $50,000/year

Follow-up prompts

  • How can I create a dashboard to visualize key security metrics?
  • What training is needed for our team to manage these tools effectively?
  • Can you provide examples of critical alerts to configure for immediate response?