Splunk Tech Talks
Deep-dives for technical practitioners.

Risk-Based Alerting & Enterprise Security

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition,  Risk-Based Alerting & Enterprise Security 

Historically, Security Operations Centers have been noisy places. Teams have worked endlessly to craft the ‘perfect’ correlation search, to no avail. As the volume of security alerts continued to grow, it has put a disproportionate amount of the workload on analysts, as their primary job function became triage related activities. Tune in to learn how Enterprise Security with native Risk-Based Alerting functionality addresses this issue. In a series of clicks, ES users can map against their preferred cybersecurity framework (e.g. MITRE ATT&CK), start aligning analytics to quantify their cybersecurity coverage, and watch the number of alerts plummet.  

Learn how to:

  • Improve true positive rates
  • Detect complex threats faster
  • Streamline investigations with richer context

Tech Talk discussions remain open for two weeks following the live Tech Talk event. 

Contributors
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

[Puzzles] Solve, Learn, Repeat: Family Trees

This puzzle (first published here is based on finding grandparents and grandchildren (inspired by a question ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...