"And the nominees are..." - Wish me luck!
top of page
Geeking out on Splunk and IT Security
Search
I have been nominated for a 2023 Splunkie Award and I am delighted to be a finalist for the Inventor Award! https://conf.splunk.com/the-s...
Gabriel Vasseur
- May 22, 2023
- 4 min
RBA: a better way to dedup risk events
In this post we’re discussing an advanced way to dedup risk events in your risk alerts (RIRs) and at the same time have the RIR results...
13 views0 comments
Gabriel Vasseur
- May 16, 2023
- 1 min
Site Map
Use this page as a quick way to find which areas of this website have value for you. My apps ES Choreographer: manage ES correlation...
10 views0 comments
Gabriel Vasseur
- May 16, 2023
- 8 min
Conf Manager
This is the documentation for the Conf Manager app on splunkbase. This app allows you to search your knowledge objects and track their...
19 views0 comments
Gabriel Vasseur
- Apr 30, 2022
- 5 min
Linux tips
This for the most part isn't splunk-specific, but if you do any amount of administration on the linux command line, you might find it...
0 views0 comments
Gabriel Vasseur
- Apr 26, 2022
- 1 min
Splunk workload optimisation
Assess your search workload with this simple dashboard. Here's a very quick dashboard to identify what uses your splunk platform...
0 views0 comments
Gabriel Vasseur
- Feb 28, 2022
- 10 min
ES-Choreographer
This is the documentation for the ES-Choreographer app on splunkbase. This app offers various frameworks to help manage and improve...
8 views0 comments
Gabriel Vasseur
- Jan 10, 2022
- 7 min
GV-Utils
This is the documentation for the GV-Utils app on splunkbase. This app offers various utilities to solve a number of problems in Splunk:...
3 views0 comments
Gabriel Vasseur
- Oct 19, 2021
- 9 min
Dashboarding Best Practices, Tips & Tricks
Splunk’s “simple XML” dashboards are reasonably simple and straightforward to create, yet they are incredibly versatile and powerful. You...
25 views0 comments
Gabriel Vasseur
- Oct 19, 2021
- 1 min
Maintaining your correlation searches with ES Choreographer
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. If you’re looking for the source code for the things...
0 views0 comments
Gabriel Vasseur
- Oct 19, 2021
- 11 min
Audit your correlation searches against your own Best Practices automatically
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is Correlation Searches Best...
4 views0 comments
Gabriel Vasseur
- Oct 19, 2021
- 1 min
Test your correlation searches end-to-end with Morning Checks
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is morning checks. Basically you...
3 views0 comments
Gabriel Vasseur
- Oct 19, 2021
- 2 min
Add an in-splunk after-the-fact Peer Review system for your correlations
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is having a simple peer review...
0 views0 comments
Gabriel Vasseur
- Oct 19, 2021
- 1 min
Add a simple TODO management system for your correlations
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is having a simple task management...
0 views0 comments
Gabriel Vasseur
- Oct 18, 2021
- 3 min
Easy yet powerful submit buttons in your simple XML dashboards
There are a number of issues with Splunk’s simple XML forms submit button: you can't have more than one you can't move it you can't hide...
11 views0 comments
Gabriel Vasseur
- Oct 31, 2018
- 1 min
Change Tracking in Splunk
Are you tracking changes in your Splunk deployment? Most people don't, unless they can justify having a custom (heavy!) process using...
0 views0 comments
Gabriel Vasseur
- Oct 31, 2017
- 1 min
Running Splunk Enterprise Security at Capacity with Data Model Acceleration
Data models and especially their acceleration are often misunderstood by Splunk users. Yet they are absolutely critical, especially for...
0 views0 comments
Gabriel Vasseur
- Oct 31, 2016
- 1 min
Regular Expressions
Regular expressions are extremely useful. They are everywhere, including in Splunk. And they are useful to everyone, not just data...
0 views0 comments
bottom of page