Splunk Tech Talks
Deep-dives for technical practitioners.

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WhitneySink
Splunk Employee
Splunk Employee

Screenshot 2025-01-21 at 12.15.31 PM.png

The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee Mills, Security Strategist at Splunk, as she walks through the new and improved Splunk Guide to RBA!


Join this Tech Talk to learn the power of RBA, such as how to:

  • Reduce the number of overall alerts while increasing the fidelity of alerts that arise
  • Define and produce internal threat intelligence to identify normal or anomalous behavior
  • Create high-value detections from traditionally noisy data sources, which align to popular cybersecurity frameworks
  • Develop a valuable risk library of metadata-enriched objects and behaviors for manual analysis or machine learning

Watch full Tech Talk here:

Contributors
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...