TriageMTTR

Log analysis

Converts a vague question about whether something happened into a scoped search with a written answer, its sources, and its limits.

Tools

Splunk, Microsoft Sentinel, Graylog, Elastic Security

Outcomes

Every question answered from a logged search • Searches recorded with sources and time range • Retention gaps named before they hide a result • One shared timeline per investigation

Documentation

Instruction-ready detail below

An investigation usually arrives as a question rather than a dataset, and the real work is working out which log source holds the answer, how far back it reaches, and what a negative result would look like. This workflow takes the question as written, names the systems and accounts involved, and turns it into a scoped search with an explicit time range and list of sources, so the scope is agreed before anyone starts reading. It runs the search across the collected sources, adds the context a raw result needs to be read, such as which users sit in an admin group, and writes every query and source into the case as it goes. If a source the question depends on has no data covering the period, the answer says so rather than returning a clean empty result. The finding is written as a short summary with its confidence and its limits, attached to one timeline other responders can pick up. A human still decides whether an absence of evidence is acceptable, and who else should see the answer.

Problem this workflow solves

Most investigations arrive as a question from outside security that no single console can answer, and the analyst spends a day working out which log source holds the answer before starting the real search. By the time the result is written up, the shortest retention window has rolled over and the honest answer becomes no evidence found, which travels upstream as nothing having happened. The work product is a paragraph of prose with no record of what was searched.

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download