Hi everyone,
I’ve recently been exploring Splunk in more depth. I managed to install UBA on my laptop, and I also worked with DSDL by adding it to Splunk. I was able to activate four models that are tied to the ES correlation rules included with the ESCU app.
Now I have a question: since I already have a background in machine learning and deep learning (and I’ve built Python projects in this area before), I’d like to understand how I can start creating practical SOC-related projects in Splunk that make use of AI.
Any guidance, examples, or suggestions would be greatly appreciated.
Thanks in advance!
Hi @Nrsch
Check out https://www.splunk.com/en_us/blog/artificial-intelligence/splunk-ai-rag-cybersecurity-detections.htm...which I think might give you some ideas along with some searches to get started.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing