Splunk Tech Talks
Deep-dives for technical practitioners.

Simplifying the Analyst Experience with Finding-based Detections

DayaSCanales
Splunk Employee
Splunk Employee

Screenshot 2026-02-26 152600.png

 

 

Splunk invites you to an engaging Tech Talk focused on streamlining security operations with finding-based detections and contextual alerts. This session is designed for security professionals seeking to minimize alert fatigue, speed up investigations, and gain clearer insight into complex incidents.

You’ll discover how finding-based detections enable analysts to quickly understand and respond to security events. Learn how this feature identifies multi-stage attacks, dynamically groups duplicate and related findings using RBA best practices, and delivers a comprehensive view of priority incidents with essential context.

What’s in Store:

  • See how finding-based detections reduce alert overload and investigation time.
  • Explore dynamic grouping for duplicate and related findings, powered by RBA.
  • Understand how contextual alerts deliver the information analysts need to respond to advanced threats.
  • Bring your questions and join the interactive discussion!

Don’t miss out—watch on demand!

DayaSCanales
Splunk Employee
Splunk Employee
DayaSCanales
Splunk Employee
Splunk Employee

Here are a few top of mind questions from the live Tech Talk

 

Q. Is FBD in Security Enterprise only? If so, what about Security Essentials for smaller infrastructures or installations in "closed" networks?

A. Finding-based detection (FBD) is a feature of Enterprise Security and available with Enterprise Security Essentials edition at no additional cost if you have that edition.

DayaSCanales_0-1772822462052.png

 

Q. It is worth mentioning that these finding-based detections are just boosting what the risk intermediate alerts do as they can also add findings?

A. Yes, this is true. FBD's group both findings and intermediate findings that have common entities.

DayaSCanales_1-1772822477156.png

 

Q. What is the time complexity of detect cycle?

A. FBDs run every 5 minutes by default and are fairly lightweight. By default the time window (max append time) is 7 days or 24 hours. That is how long the group keeps getting new findings and intermediate findings grouped together into that common group.

DayaSCanales_2-1772822527719.png

 

Q. So the Event-based Detections that are displayed under the Findings-based Detection in Mission Control, are those pulling only Findings, Intermediate Findings, or both? 

A. An FBD can consume either or both Findings or Intermediate Findings. Both are consumed by default. 

DayaSCanales_3-1772822541659.png

 

Q. If I have FBD's that I created and started using during the Beta stage. Will those work now with ES 8.4 with FBD being GA?

A. Any FBD's that were in the product or customized FBD's that were created during the Beta stage will no longer work in ES 8.4.  This is because the underlying macros that FBD's use and rely on were refactored to simplify the base FBD search and enhance scalability.

DayaSCanales_4-1772822555774.png

 

Q. Do we need an initial event-based detection to be generated to have a finding-based detection created?

A. The Event-based detections are the first stage of detections. The output of event-based detections are the inputs into finding-based detections which have the responsibility of grouping those outputs into a common finding group.

DayaSCanales_5-1772822569306.png

 

Q. Does every time a finding group reopen does the max append time get reset? Or is this based on when the group initial opened?

A. No, the max append time does not reset. The time depends on when it initially started. The Finding Group that is reopened is the same finding group that was initially opened with all the same grouped stuff and just growing context. 

DayaSCanales_6-1772822588470.png

 

Q. Can you show how you drill downed into intermediate findings again? 

A. The intermediate findings are accessible anywhere you can click in to see the risk-event timeline. This is from the intermediate findings count on the Analyst Queue, and from within an Investigation too. 

DayaSCanales_7-1772822601121.png

 

Q. Can you expand intermediate in finding groups?

A. Yes intermediate findings are visually see in the Risk event timeline that Jerald demo'ed, and also in the Investigation view if the finding group is promoted to an investigation.

DayaSCanales_8-1772822624278.png

 

 

Contributors
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...