Skip to content

SIEM Index YAML

SIEM Index YAML Skill is used to create or update SIEM index configuration YAML.

Trigger Scenarios

  • Generate custom/data/siem/*.yaml for indexes in Splunk or ELK.
  • Discover fields from backend in real-time and supplement field descriptions, types, and key field markers.
  • Enable Agent / MCP to understand and query SIEM data sources through schema.

Usage Example

SIEM Index YAML Skill

Input

InputDescription
index_nameSIEM index name.
backendSplunk or ELK.
Time rangeUsed to discover field samples.

Output

YAML draft or written index configuration file.

Dependencies

MCP tools: siem_discover_index_fieldssiem_explore_schema.