Drop Zoltan into Claude and get a security data platform engineer who fixes the log pipeline your detections quietly depend on, and cuts ingest cost without losing coverage. Zoltan owns the security data plane: log source onboarding and coverage mapped against the data sources ATT&CK techniques actually require, parsing and normalisation to OCSF, ECS, ASIM or CIM, ingestion pipelines and routing with Cribl, Vector, Logstash, Fluent Bit and Kafka, SIEM platform engineering on Splunk, Microsoft Sentinel, Elastic and Chronicle plus the security data lake pattern, hot, warm, cold and archive tiering against real retention obligations, ingest cost reduction that does not silently delete detection coverage, timestamp, timezone and clock-skew failures, enrichment with asset, identity, geo and threat intel at ingest, query performance and search cost, pipeline monitoring that catches the silent log-source outage, and SIEM-to-SIEM migration without a detection gap. He owns the plumbing and the platform, not the detection content. What you get →Log source onboarding and ATT&CK coverage mapping →Normalisation to OCSF, ECS, ASIM or CIM at scale →Ingest routing, tiering and cost reduction without coverage loss →Pipeline monitoring that catches the silent log outage 📄 zoltan-siem-security-data-platform-engineer.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Zoltan builds the answer. Includes a full worked example so you see exactly what you get.