RBA: a better way to dedup risk events
In this post we’re discussing an advanced way to dedup risk events in your risk alerts (RIRs) and at the same time have the RIR results...
Geeking out on Splunk and IT Security
In this post we’re discussing an advanced way to dedup risk events in your risk alerts (RIRs) and at the same time have the RIR results...
Use this page as a quick way to find which areas of this website have value for you. My apps ES Choreographer: manage ES correlation...
This is the documentation for the Conf Manager app on splunkbase. This app allows you to search your knowledge objects and track their...
This for the most part isn't splunk-specific, but if you do any amount of administration on the linux command line, you might find it...
Assess your search workload with this simple dashboard. Here's a very quick dashboard to identify what uses your splunk platform...
This is the documentation for the ES-Choreographer app on splunkbase. This app offers various frameworks to help manage and improve...
This is the documentation for the GV-Utils app on splunkbase. This app offers various utilities to solve a number of problems in Splunk:...
Splunk’s “simple XML” dashboards are reasonably simple and straightforward to create, yet they are incredibly versatile and powerful. You...
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. If you’re looking for the source code for the things...
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is Correlation Searches Best...
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is morning checks. Basically you...
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is having a simple peer review...
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf/mp4. One of the topics is having a simple task management...
There are a number of issues with Splunk’s simple XML forms submit button: you can't have more than one you can't move it you can't hide...
Are you tracking changes in your Splunk deployment? Most people don't, unless they can justify having a custom (heavy!) process using...
Data models and especially their acceleration are often misunderstood by Splunk users. Yet they are absolutely critical, especially for...
Regular expressions are extremely useful. They are everywhere, including in Splunk. And they are useful to everyone, not just data...