<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tuning Risk Scores and resetting score values in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252957#M1835</link>
    <description>&lt;P&gt;Yes, Splunk ES 4.0.1. Apologies, should have given that information.&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2016 08:02:51 GMT</pubDate>
    <dc:creator>sheamus69</dc:creator>
    <dc:date>2016-05-19T08:02:51Z</dc:date>
    <item>
      <title>Tuning Risk Scores and resetting score values</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252955#M1833</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm in the process of tuning our risk scores, as applied to objects (users or assets) from a correlation search.&lt;/P&gt;

&lt;P&gt;What I'm uncertain about is, once I have configured the scoring in a manner that I am happy with, can I reset all the scores currently applied to objects so as to operate from a fresh start?  The existing risk scores, being poorly configured, would presumably skew any risk analysis results going forward?&lt;/P&gt;

&lt;P&gt;Any advice given here would be gratefully recieved.&lt;/P&gt;

&lt;P&gt;Sheamus.&lt;/P&gt;

&lt;P&gt;Edit:&lt;/P&gt;

&lt;P&gt;This question is for Splunk Enterprise Security 4.0.1.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 08:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252955#M1833</guid>
      <dc:creator>sheamus69</dc:creator>
      <dc:date>2016-05-18T08:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Tuning Risk Scores and resetting score values</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252956#M1834</link>
      <description>&lt;P&gt;Is this question for splunk enterprise security?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 12:01:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252956#M1834</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-18T12:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Tuning Risk Scores and resetting score values</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252957#M1835</link>
      <description>&lt;P&gt;Yes, Splunk ES 4.0.1. Apologies, should have given that information.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 08:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252957#M1835</guid>
      <dc:creator>sheamus69</dc:creator>
      <dc:date>2016-05-19T08:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Tuning Risk Scores and resetting score values</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252958#M1836</link>
      <description>&lt;P&gt;OK, I think I've figured this out for myself.&lt;/P&gt;

&lt;P&gt;Splunk doesnt need to baseline the scores, as the scores are calculated for a given timeframe. So a systems risk score would give a different value when looked a over 24 hours as opposed to over 7 days.&lt;/P&gt;

&lt;P&gt;This effectively means that old risk values will drop out over time - which should reflect the fact that risk factors would, hopefully, get rectified once identified.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 10:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Tuning-Risk-Scores-and-resetting-score-values/m-p/252958#M1836</guid>
      <dc:creator>sheamus69</dc:creator>
      <dc:date>2016-05-20T10:56:51Z</dc:date>
    </item>
  </channel>
</rss>

