Splunk Enterprise

Looking for Ideas: Applying AI/ML in SOC with Splunk

Nrsch
Explorer

Hi everyone,

I’ve recently been exploring Splunk in more depth. I managed to install UBA on my laptop, and I also worked with DSDL by adding it to Splunk. I was able to activate four models that are tied to the ES correlation rules included with the ESCU app.

Now I have a question: since I already have a background in machine learning and deep learning (and I’ve built Python projects in this area before), I’d like to understand how I can start creating practical SOC-related projects in Splunk that make use of AI.

Any guidance, examples, or suggestions would be greatly appreciated.

Thanks in advance!

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Nrsch 

Check out https://www.splunk.com/en_us/blog/artificial-intelligence/splunk-ai-rag-cybersecurity-detections.htm...which I think might give you some ideas along with some searches to get started.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...