Administración de Sistemas
Audit & SIEM Skill
Use this skill to collect, forward, and query audit logs and security events from cloud infrastructure, Kubernetes, and application layers into a SIEM. Triggers: any request to set up audit logging, query who accessed secrets, vault access, audit who accessed, accessed secrets, configure log forwarding to Sentinel or Splunk, investigate a security event, search audit logs for suspicious activity, generate a SOC compliance evidence package, configure detection rules, or produce an audit trail for a specific user/resource/time.