Splunk Tech Talks
Deep-dives for technical practitioners.

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WhitneySink
Splunk Employee
Splunk Employee

Screenshot 2025-01-21 at 12.15.31 PM.png

The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee Mills, Security Strategist at Splunk, as she walks through the new and improved Splunk Guide to RBA!


Join this Tech Talk to learn the power of RBA, such as how to:

  • Reduce the number of overall alerts while increasing the fidelity of alerts that arise
  • Define and produce internal threat intelligence to identify normal or anomalous behavior
  • Create high-value detections from traditionally noisy data sources, which align to popular cybersecurity frameworks
  • Develop a valuable risk library of metadata-enriched objects and behaviors for manual analysis or machine learning

Watch full Tech Talk here:

Contributors
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...