← All Tools
SIEM Query Template Library
30 SOC query templates, each written for QRadar AQL, Splunk SPL and Microsoft Sentinel KQL. Filter, switch platform, copy.
No templates match these filters.
How it works
- Each template solves one SOC question (failed logins, beaconing, lateral movement, credential dumping...) and exists in all three query languages. Switch the platform tabs to see the same hunt in AQL, SPL or KQL.
- Values in [BRACKETS] are parameters: replace them with your user, IP, threshold or time window before running the query. AQL time windows are in milliseconds (
NOW() - [HOURS] * 3600000). - Index names, sourcetypes, log source types and QRadar category IDs differ between deployments. Treat every query as a starting point and check it against your own schema and log sources before using it in production or in a scheduled rule.
- Everything runs in your browser: no query, filter or export is sent to a server. Filters and the selected platform are kept in the page URL so you can share a filtered view.
Official documentation
IBM QRadar AQL
AQL Reference Guide
Splunk SPL
SPL Search Reference
Microsoft Sentinel KQL
KQL Reference