security-audit-logging

Implement comprehensive security audit logging for compliance, forensics, and SIEM integration. Use when building audit trails, compliance logging, or security…

INSTALLATION
npx skills add https://github.com/aj-geddes/useful-ai-prompts --skill security-audit-logging
Run in your project or agent environment. Adjust flags if your CLI version differs.

SKILL.md

Security Audit Logging

Table of Contents

  • [Overview](#overview)
  • [When to Use](#when-to-use)
  • [Quick Start](#quick-start)
  • [Reference Guides](#reference-guides)
  • [Best Practices](#best-practices)

Overview

Implement comprehensive audit logging for security events, user actions, and system changes with structured logging, retention policies, and SIEM integration.

When to Use

  • Compliance requirements (SOC 2, HIPAA, PCI-DSS)
  • Security monitoring
  • Forensic investigations
  • User activity tracking
  • System change auditing
  • Breach detection

Quick Start

Minimal working example:

// audit-logger.js

const winston = require("winston");

const { ElasticsearchTransport } = require("winston-elasticsearch");

class AuditLogger {

  constructor() {

    this.logger = winston.createLogger({

      level: "info",

      format: winston.format.combine(

        winston.format.timestamp(),

        winston.format.json(),

      ),

      transports: [

        // File transport

        new winston.transports.File({

          filename: "logs/audit.log",

          maxsize: 10485760, // 10MB

          maxFiles: 30,

          tailable: true,

        }),

        // Elasticsearch transport for SIEM

        new ElasticsearchTransport({

          level: "info",

          clientOpts: {

// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
Node.js Audit LoggerNode.js Audit Logger
Python Audit Logging SystemPython Audit Logging System
Java Audit LoggingJava Audit Logging

Best Practices

✅ DO

  • Log all security events
  • Use structured logging
  • Include timestamps (UTC)
  • Log user context
  • Implement log retention
  • Encrypt sensitive logs
  • Monitor log integrity
  • Send to SIEM
  • Include request IDs

❌ DON'T

  • Log passwords/secrets
  • Log sensitive PII unnecessarily
  • Skip failed attempts
  • Allow log tampering
  • Store logs insecurely
  • Ignore log analysis
BrowserAct

Let your agent run on any real-world website

Bypass CAPTCHA & anti-bot for free. Start local, scale to cloud.

Explore BrowserAct Skills →

Stop writing automation&scrapers

Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.

Start free
free · no credit card