Splunk Tech Talks
Deep-dives for technical practitioners.

Operationalizing TDIR: Building a More Resilient, Scalable SOC

DayaSCanales
Splunk Employee
Splunk Employee

Screenshot 2025-08-15 at 4.04.52 PM.png

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response (TDIR).

(view in My Videos)

 

Key Takeaways:

  • Automation: Reduce manual effort and alert fatigue through operationalized automation.
  • Context-Driven Insights: Gain visibility across hybrid environments for more effective investigations.
  • Data-Enriched Prioritization: Use asset, identity, and threat intelligence to focus on high-priority incidents.
  • Modernizing Workflows: Improve legacy SOC processes without replacing existing tools.

This session offered actionable steps to enhance SOC efficiency, empower analysts, and stay ahead of evolving threats.


Contributors
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...