Register here . This thread is for the Community Office Hours session with the Security topic: Get More Out of Your Security Practice with a SIEM - Part II (Advanced Use Cases) on Wed, Aug 21, 2024 at 1pm PT / 4pm ET.
This is your opportunity to connect with technical Splunk experts, who will guide you through solutions to your security use case questions and engage in live discussions about how to best leverage Splunk Enterprise Security as your SIEM solution. This session, Part II, will focus on adding context to your detections to fuel more meaningful investigations. We will focus on key use cases such as Risk-Based Alerting to prioritize alerts for faster response to more critical tasks, enriching threat context with threat intelligence, leveraging cyber frameworks to manage risks, and more. These use cases will help improve mean time to detect (MTTD) and mean time to response (MTTR).
In the session, you can discuss with our experts for
Please submit your questions at registration or as comments below. You can also head to the #office-hours user Slack channel to ask questions (request access here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
Look forward to connecting!
Here are a few questions from the session (get the full Q&A deck and live recording in the #office-hours Slack channel)
Q1: How can one hone threat detection skills by setting up projects for threat detection and incident response at home? What are the recommended steps?
Previous BOTS have their data out on github (i.e. https://github.com/splunk/botsv3) that can be used for this purpose.
Alternatively, on the BOTS site (https://bots.splunk.com) there are multiple self-paced scenarios for learning where you can learn as well.
Defcon Blue Team Village recordings https://www.youtube.com/watch?v=-upNhwmNGp8&list=PL9fPq3eQfaaDdj_DjG61x9Iz9O8mfC4mJ
Read up on the PEAK framework https://www.splunk.com/en_us/blog/security/peak-threat-hunting-framework.html
If you work in a SOC ask for 5%
Q2: What is the best practice of Data Parsing?
Q3: Can we create ML used queries in correlation search alerting? How to incorporate ML based threat hunting using Splunk?
Other Questions (check the #office-hours Slack channel for responses):