Splunk Tech Talks
Deep-dives for technical practitioners.

Risk-Based Alerting & Enterprise Security

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition,  Risk-Based Alerting & Enterprise Security 

Historically, Security Operations Centers have been noisy places. Teams have worked endlessly to craft the ‘perfect’ correlation search, to no avail. As the volume of security alerts continued to grow, it has put a disproportionate amount of the workload on analysts, as their primary job function became triage related activities. Tune in to learn how Enterprise Security with native Risk-Based Alerting functionality addresses this issue. In a series of clicks, ES users can map against their preferred cybersecurity framework (e.g. MITRE ATT&CK), start aligning analytics to quantify their cybersecurity coverage, and watch the number of alerts plummet.  

Learn how to:

  • Improve true positive rates
  • Detect complex threats faster
  • Streamline investigations with richer context

Tech Talk discussions remain open for two weeks following the live Tech Talk event. 

nwuest
Path Finder

Hi @melissap,

Thanks to you and all those who put these valuable resources together and publish them for all of us who frequent these forums!
I will definitely share these posts with my co-workers.

V/R,
nwuest

melissap
Splunk Employee
Splunk Employee

@nwuest  You are so welcome! I am glad you find them valuable. Our experts are amazing here at Splunk. I will be posting a new article soon to gain feedback on additional topics our users would like to see. Please comment there so we can plan more Tech Talks!

Aquar5
New Member

@melissap Melissa, the slides are accessible, but I'm getting "Access Denied" when trying to load this particular video:
https://conf.splunk.com/files/2020/recordings/SEC1113A.mp4

I've tried re-logging to Splunk.com multiple times. Other videos work fine.

Can you please help?

melissap
Splunk Employee
Splunk Employee

@Aquar5 

I have put in a request to the Conf team to fix that link. I will let you know when I hear back. 

Doreluss
Loves-to-Learn Lots

@melissap  

In Splunk, you can create reoccurring notable events and turn them into informational events by configuring notable event settings and using Splunk's alerting and workflow features. Notable events are events that are identified as significant or noteworthy based on predefined criteria, and you can configure them to be informational for monitoring purposes. 

 

Thats the question I have as of right due to having so much alerts pertaining to a particular alert , however Im going to review the links you provided earlier in this chat. If I have any questions I will reach out to you. Meanwhile, thanks for the information.

Contributors
Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...