Splunk Enterprise

Looking for Ideas: Applying AI/ML in SOC with Splunk

Nrsch
Explorer

Hi everyone,

I’ve recently been exploring Splunk in more depth. I managed to install UBA on my laptop, and I also worked with DSDL by adding it to Splunk. I was able to activate four models that are tied to the ES correlation rules included with the ESCU app.

Now I have a question: since I already have a background in machine learning and deep learning (and I’ve built Python projects in this area before), I’d like to understand how I can start creating practical SOC-related projects in Splunk that make use of AI.

Any guidance, examples, or suggestions would be greatly appreciated.

Thanks in advance!

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Nrsch 

Check out https://www.splunk.com/en_us/blog/artificial-intelligence/splunk-ai-rag-cybersecurity-detections.htm...which I think might give you some ideas along with some searches to get started.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...