Splunk Tech Talks
Deep-dives for technical practitioners.

Splunk Intelligence Management for Splunk SOAR

LesediK
Splunk Employee
Splunk Employee

Security Edition

Splunk Intelligence Management for Splunk SOAR

(view in My Videos)

Analysts and security engineers are burdened with an onslaught of security alerts, disparate threat intelligence data formats, and too much repetitive, manual review of indicator enrichment. While Splunk SOAR playbooks automate security actions, they become even more powerful and easy to use with the addition of Splunk Intelligence Management (formerly TruSTAR).

Tune in  to this Tech Talk to learn how to:

  • Obtain prepared and normalized intelligence from internal and external sources for faster triage and more streamlined playbooks.
  • Automate based on IOC enrichment from Splunk Intelligence Management.
Contributors
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...