top of page
Geeking out on Splunk and IT Security
Search


Shrink your windows event logs license costs with ingest actions!
Windows events are a large part of the volume of logs ingested in a lot of splunk deployments. Wouldn't be cool if we could shrink them so they don't eat up so much precious precious license? In this post I'll walk through how I rebuilt Windows Event Logs (WELs) into a compact, Splunk-friendly format, cuting size by up to 60% without breaking field extractions. Key takeaways With a few targeted ingest actions and props/transforms tweaks, you can shrink Windows logs dramatical
Gabriel Vasseur
Oct 27, 202510 min read


ES8 findings, intermediate findings, etc confusion!
The key thing I did not appreciate when I wrote the previous version of this post is that the Risk data model is now fed from...
Gabriel Vasseur
Sep 5, 20256 min read


RBA: Aggregate user & system risks!
Since RBA is all about aggregating security events that are related to the same entity, Assets & Identities normalisation is crucial to...
Gabriel Vasseur
Jan 6, 202512 min read


Untable, xyseries, transpose clarified!
These 3 table-manipulating commands are occasionally very useful but they are also quite confusing. For years, I've relied on the...
Gabriel Vasseur
Dec 2, 20241 min read
bottom of page