- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi,
I'm in the process of tuning our risk scores, as applied to objects (users or assets) from a correlation search.
What I'm uncertain about is, once I have configured the scoring in a manner that I am happy with, can I reset all the scores currently applied to objects so as to operate from a fresh start? The existing risk scores, being poorly configured, would presumably skew any risk analysis results going forward?
Any advice given here would be gratefully recieved.
Sheamus.
Edit:
This question is for Splunk Enterprise Security 4.0.1.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

OK, I think I've figured this out for myself.
Splunk doesnt need to baseline the scores, as the scores are calculated for a given timeframe. So a systems risk score would give a different value when looked a over 24 hours as opposed to over 7 days.
This effectively means that old risk values will drop out over time - which should reflect the fact that risk factors would, hopefully, get rectified once identified.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

OK, I think I've figured this out for myself.
Splunk doesnt need to baseline the scores, as the scores are calculated for a given timeframe. So a systems risk score would give a different value when looked a over 24 hours as opposed to over 7 days.
This effectively means that old risk values will drop out over time - which should reflect the fact that risk factors would, hopefully, get rectified once identified.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Is this question for splunk enterprise security?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Yes, Splunk ES 4.0.1. Apologies, should have given that information.
