<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/668323#M65</link>
    <description>&lt;P class=""&gt;&lt;STRONG&gt;Here are some other questions from the session (check the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Are there plans to integrate into ES the ability so when a notable is closed as a false positive (by disposition), to be able to automatically lower the risk score of the associated objects to remove the risk modifier from the correlation search in question?&lt;/LI&gt;&lt;LI&gt;Where do people start with scoring their risk...is it really as "eyballing it" as I think?&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;E.g. Let's just start with a risk of 100, and something I think is more risk I make 150 or 200, and something less risk is 50.&lt;/LI&gt;&lt;LI&gt;Is it Splunk's expectation/best practice to only triage RBA notables and only close/resolve those and to ignore *from a workflow resolution standpoint) non-RBA notables?&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Sat, 11 Nov 2023 16:01:28 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2023-11-11T16:01:28Z</dc:date>
    <item>
      <title>Security: Risk-Based Alerting (RBA) - 11/08/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/653799#M46</link>
      <description>&lt;P data-unlink="true"&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://splunk.zoom.us/meeting/register/tJIkcOuqqTwtE9zPBBRPmFW13ZqAiXHcC3kB" target="_blank" rel="noopener"&gt;Register here&lt;/A&gt;.&lt;/STRONG&gt;&amp;nbsp;This thread is for the Community Office Hours session on&lt;/SPAN&gt;&lt;STRONG&gt;&amp;nbsp;Splunk Enterprise Security: RBA&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;on &lt;/SPAN&gt;&lt;STRONG&gt;Wed, November 8, 2023 at 1pm PT / 4pm ET.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is your opportunity to ask questions related to your specific challenge or use case using Splunk Enterprise Security Risk-Based Alerting. Including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Implementing RBA in Splunk Enterprise Security&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Best practices for proper creation of risk rules, modifiers, etc.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Troubleshooting and optimizing your environment for successful implementation&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Anything else you’d like to learn!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration or as comments below.&lt;/STRONG&gt;&lt;SPAN&gt; You can also head to &lt;/SPAN&gt;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; user Slack channel to ask questions (request access &lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will go in order of the questions posted below, then will open the floor up to live Q&amp;amp;A with meeting participants. If there’s a quick answer available, we’ll post as a direct reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 16:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/653799#M46</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-11-11T16:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security: Risk-Based Alerting (RBA) - 11/08/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/668322#M64</link>
      <description>&lt;P class=""&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q1: What’s the best way to manage risk scores?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Navigate to &lt;A href="https://research.splunk.com/" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;https://research.splunk.com/&lt;/SPAN&gt;&lt;/A&gt; and check out the detections under the detections tab.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Scroll down to the section called “RBA,” where you’ll see a risk score that comes along with each of the detections. It uses the formula:&amp;nbsp;&lt;/LI&gt;&lt;UL class=""&gt;&lt;LI&gt;Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;You can also add risk factors (multipliers &amp;amp; modifiers) to make risk scores more dynamic. For example “if this account is a service account, or if this user is a privileged user, then multiply by 2”&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q2: Does Splunk have best practices for setting and adjusting risk scores as our implementation improves?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Best practice at the start is to just &lt;STRONG&gt;pick a risk score and stay consistent with it&lt;/STRONG&gt; for a while until you have had some time to curate the risk in your environment, and &lt;STRONG&gt;see if rules excessively add risk or not&lt;/STRONG&gt;, make adjustments and tune your rules as needed to insure excessive risk isn’t being added.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;With that said, the &lt;STRONG&gt;default risk score threshold of 100 &lt;/STRONG&gt;for alerts and each triggered rule adjusting risk by adding 1 to the score each time works just fine. You may have to &lt;STRONG&gt;adjust risk factors and tune rules&lt;/STRONG&gt; to keep things reasonable.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I think the &lt;STRONG&gt;main guidance is to not constantly adjust your risk scoring on a frequent basis&lt;/STRONG&gt;. If you need to adjust it for your environment, make your adjustment, then let it bake for a little while and see how it reflects in your environment.&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q3: When working with ES's Assets &amp;amp; Identities with RBA, how would you handle things such as the SYSTEM account, or 'Unknown' from TA's not mapping properly, so that RBA wouldn't trigger on it?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;For unknown field contents, you need to &lt;STRONG&gt;address the data onboarding for the relevant datasource&lt;/STRONG&gt;.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;When onboarding data for use in ES, it &lt;STRONG&gt;needs to be CIM compliant &lt;/STRONG&gt;(if applicable, which means that it maps to one of the CIM data models), all fields required need to be extracted correctly to rid yourself of the “unknowns”&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/7.2.0/Admin/Dashboardrequirements" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;Dashboard requirements matrix for Splunk Enterprise Security&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 11 Nov 2023 16:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/668322#M64</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-11-11T16:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security: Risk-Based Alerting (RBA) - 11/08/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/668323#M65</link>
      <description>&lt;P class=""&gt;&lt;STRONG&gt;Here are some other questions from the session (check the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Are there plans to integrate into ES the ability so when a notable is closed as a false positive (by disposition), to be able to automatically lower the risk score of the associated objects to remove the risk modifier from the correlation search in question?&lt;/LI&gt;&lt;LI&gt;Where do people start with scoring their risk...is it really as "eyballing it" as I think?&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;E.g. Let's just start with a risk of 100, and something I think is more risk I make 150 or 200, and something less risk is 50.&lt;/LI&gt;&lt;LI&gt;Is it Splunk's expectation/best practice to only triage RBA notables and only close/resolve those and to ignore *from a workflow resolution standpoint) non-RBA notables?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 11 Nov 2023 16:01:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Security-Risk-Based-Alerting-RBA-11-08-23/ec-p/668323#M65</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-11-11T16:01:28Z</dc:date>
    </item>
  </channel>
</rss>

