<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk as a SIEM Best Practices for Security Professionals in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413959#M9876</link>
    <description>&lt;P&gt;Keep in mind that Splunk Enterprise Security and Splunk Security Essentials are two different things.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/263/"&gt;Splunk Enterprise Security&lt;/A&gt; - Splunk Enterprise Security is the nerve center of the security ecosystem, giving teams the insight to quickly detect and respond to internal and external attacks, simplify threat management minimizing risk. &lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/3435/"&gt;Splunk Security Essentials&lt;/A&gt; - Showcase of many security examples possible with Splunk&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 29 Jul 2019 16:25:34 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2019-07-29T16:25:34Z</dc:date>
    <item>
      <title>Splunk as a SIEM Best Practices for Security Professionals</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413957#M9874</link>
      <description>&lt;P&gt;Just curious if there is any documentation to help understand the best practices to use Splunk Enterprise as a SIEM for Security Professionals / SOC analysts.&lt;/P&gt;

&lt;P&gt;Or if anyone has any input, that would be appreciated as well. &lt;/P&gt;

&lt;P&gt;I have been evaluating Splunk Security Essentials, which I've been using to create dashboards.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 17:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413957#M9874</guid>
      <dc:creator>aking76</dc:creator>
      <dc:date>2019-07-25T17:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a SIEM Best Practices for Security Professionals</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413958#M9875</link>
      <description>&lt;P&gt;You might find some relevant information about best practices and use cases in the recordings of previous Splunk user conference sessions: &lt;A href="https://conf.splunk.com/watch/conf-online.html?search=siem#/"&gt;https://conf.splunk.com/watch/conf-online.html?search=siem#/&lt;/A&gt; .&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 17:20:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413958#M9875</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2019-07-25T17:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a SIEM Best Practices for Security Professionals</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413959#M9876</link>
      <description>&lt;P&gt;Keep in mind that Splunk Enterprise Security and Splunk Security Essentials are two different things.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/263/"&gt;Splunk Enterprise Security&lt;/A&gt; - Splunk Enterprise Security is the nerve center of the security ecosystem, giving teams the insight to quickly detect and respond to internal and external attacks, simplify threat management minimizing risk. &lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/3435/"&gt;Splunk Security Essentials&lt;/A&gt; - Showcase of many security examples possible with Splunk&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Jul 2019 16:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413959#M9876</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-07-29T16:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a SIEM Best Practices for Security Professionals</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413960#M9877</link>
      <description>&lt;P&gt;Lots of splunk searches, explanations, and mappings to MITRE ATT&amp;amp;CK here: &lt;A href="https://splunkbase.splunk.com/app/3449/"&gt;https://splunkbase.splunk.com/app/3449/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;the app is updated regularly by splunk's security research team.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 19:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413960#M9877</guid>
      <dc:creator>mmerza_splunk</dc:creator>
      <dc:date>2019-07-29T19:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a SIEM Best Practices for Security Professionals</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413961#M9878</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Enrich your data  with asset &amp;amp; user information where possible (Enterprise Security has this built in)&lt;/LI&gt;
&lt;LI&gt;Build alerts with a specific use case in mind - mmerza mentioned MITRE ATT&amp;amp;CK and rightfully so, but it doesn't contain all uses cases you may want to look for&lt;/LI&gt;
&lt;LI&gt;Use the CIM &amp;amp; datamodel acceleration&lt;/LI&gt;
&lt;LI&gt;Link alerts to playbooks/response plans&lt;/LI&gt;
&lt;LI&gt;It's only as good as the data you feed it but don't just put data in without an idea of how it will be used&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I guess the overall theme is whatever you do, do it with a plan.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 21:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-SIEM-Best-Practices-for-Security-Professionals/m-p/413961#M9878</guid>
      <dc:creator>wenthold</dc:creator>
      <dc:date>2019-07-29T21:16:15Z</dc:date>
    </item>
  </channel>
</rss>

