Alerting

IPS/IDS use cases

PiotrAp
Path Finder

Hi,

Our firewalls generate around 1000 High and Critical alerts daily. I would like to create uses related to these notifications but not sure what will be the best way to handle its number. Could somebody advise what will be the best way to implement this please?

Labels (1)
Tags (1)
0 Karma

kprior201
Path Finder

Anytime there's a large amount of alerts or data, you just have to find a way to summarize it and then break it apart and focus on one thing at a time to see what is actually going on. I'd start by reviewing what signatures are coming in. Is it a majority of certain types? Is that type actually a concern in your environment? Are these alerts actually things that are concerning or is something set up strangely on the firewall? You will likely need to work with the firewall team to ensure that the threat detections on their side are set up in a useful way and you're not getting alerts for expected traffic. So, lots of things to do here, but start by breaking down the information into chunks. I'd focus on types of signatures and known assets/networks.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...