When handling a large amount of detection input with limited resources, automation and proper reproducible testing is key to staying on top of the pile of signature fodder that keeps heading your way each and every day. One of the biggest struggles with nimble SIEM detection development is quickly and easily producing event logs to use as positive and negative test cases for detection content. In this session I'll talk about how our team’s testing methodology works, how our techniques could be applied generically to any SIEM, and the tools we have developed (two of which we'll be releasing to all of you) to facilitate event log production in the land of “Logs or it didn’t happen”.