Alerting

IPS/IDS use cases

PiotrAp
Path Finder

Hi,

Our firewalls generate around 1000 High and Critical alerts daily. I would like to create uses related to these notifications but not sure what will be the best way to handle its number. Could somebody advise what will be the best way to implement this please?

Labels (1)
Tags (1)
0 Karma

kprior201
Path Finder

Anytime there's a large amount of alerts or data, you just have to find a way to summarize it and then break it apart and focus on one thing at a time to see what is actually going on. I'd start by reviewing what signatures are coming in. Is it a majority of certain types? Is that type actually a concern in your environment? Are these alerts actually things that are concerning or is something set up strangely on the firewall? You will likely need to work with the firewall team to ensure that the threat detections on their side are set up in a useful way and you're not getting alerts for expected traffic. So, lots of things to do here, but start by breaking down the information into chunks. I'd focus on types of signatures and known assets/networks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...