performing-log-source-onboarding-in-siem
mukul975/Anthropic-Cybersecurity-Skills
This guide details the comprehensive process of onboarding new log sources into Security Information and Event Management (SIEM) platforms. It covers critical steps including data source discovery, configuring collectors (e.g., Syslog, Splunk UF, CloudTrail), building parsers, normalizing fields to a common schema, and validating data quality. This systematic approach is essential for achieving complete security visibility and effective threat detection across the enterprise.