import { Zap, MessageSquare, FileText, Code2 } from 'lucide-react' const STEPS = [ { icon: FileText, title: '1. Grab a log sample', desc: 'Copy 10–50 representative lines from the new log source. Include edge cases — errors, different event types, varying field presence.', }, { icon: MessageSquare, title: '2. Paste into Claude Code', desc: 'Open Claude Code and say: "Onboard this log source for SentinelOne SDL" then paste the sample. Mention the source type if known (e.g. "Palo Alto firewall").', }, { icon: Code2, title: '3. Get your artefacts', desc: 'Claude returns an SDL parser (augmented-JSON), field mappings to the SDL schema, starter STAR detection rules, and parser test assertions.', }, { icon: Zap, title: '4. Deploy', desc: 'Drop the parser JSON into your /logParsers/ path. Paste the STAR rules into the AI-SIEM rule editor. Run the test assertions to validate extraction.', }, ] const PROMPT = `Onboard this log source for SentinelOne SDL. Please generate: 1. An SDL parser skeleton in augmented-JSON format (/logParsers/ format) 2. Field mappings from raw fields to the SDL common schema 3. 2–3 starter STAR detection rules for common threats from this source type 4. 5 parser test assertions (input line → expected field → expected value) Log source: [describe source, e.g. "Palo Alto PAN-OS firewall"] Raw log sample: [paste your log lines here]` export default function OnboardingPage() { return (
Use Claude Code directly — no API key required
{PROMPT}