Talk With an Expert

SIEM Detection Logic Conversion with LLMs

SIEM Detection Logic Conversion with LLMs (PDF, 0.56MB)Published: 02 May, 2025
Created by:
David Wolverton

Migrations of mature security information and event management (SIEMs) can be overwhelming due to the sheer volume of detection logic and log sources that must be translated between platforms and query languages. This research explores how Large Language Models (LLMs) and automation scripts can expedite the translation of detection logic between SIEMs, converting detections in minutes instead of hours. Multiple tests can be conducted to optimize translation results, test various LLM parameters, and increase the successful output of the conversion. This translation process can be automated by utilizing scripting and API integrations, significantly reducing the manual effort involved in SIEM migrations.