My Friday SIEM post!
You don’t need to know SIEM query languages anymore..
We are at time when every SIEM now has a Copilot.
If there’s one that doesn’t, let me know. 😅
The promise:
Don’t spend hours crafting queries.
Just explain what you want in plain English and get the data.
Sounds great.
But explaining things in “plain English” is not always easy.
Most people explain half of what they want and then roll the LLM dice, hoping it reads their mind.
Also in my mind whenever I ask a Copilot a new question the process should be:
Do I even have the logs?
Which data source should I trust?
What does the schema look like?
Which fields actually matter?
What is your experience does SIEM copilots always do this by default, or do you usually need to explicitly state that?
Originally posted on LinkedIn on 16 January 2026.
Read the original post and the comments.


