Splunk Tech Talks
Deep-dives for technical practitioners.

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WhitneySink
Splunk Employee
Splunk Employee

Screenshot 2025-01-21 at 12.15.31 PM.png

The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee Mills, Security Strategist at Splunk, as she walks through the new and improved Splunk Guide to RBA!


Join this Tech Talk to learn the power of RBA, such as how to:

  • Reduce the number of overall alerts while increasing the fidelity of alerts that arise
  • Define and produce internal threat intelligence to identify normal or anomalous behavior
  • Create high-value detections from traditionally noisy data sources, which align to popular cybersecurity frameworks
  • Develop a valuable risk library of metadata-enriched objects and behaviors for manual analysis or machine learning

Watch full Tech Talk here:

Contributors
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...