flâneur — a map of the web's best reading

Writing Practical Splunk Detection Rules — Part 2 | by Vit Bukac | Medium

medium.com · saved by 1 readers

In Part 1 of this series we defined requirements for good alerts and started our journey together to create a solid detection rule in Splunk that satisfy the requirements. This time we will correlate multiple alerts into a single incident with Aggregation and Deduplication. We will also reorganize the ticket description to improve both readability and flexibility in the future. Our second rule iteration looks like this: We added 2 new sections to the rule and made major update to one more: The second iteration of our detection rule creates incidents that are certainly more pleasing to the eye. Even more importantly, we started to form incident structure which will be valuable later when we add more contextual information both to the alert and to affected organization assets. Timeline evals Top two lines generate bulk of our timeline. From each raw record that matched our filter we take fields _time, category, url and useragent. The fields are subsequently concatenated into a string wit

In Part 1 of this series we defined requirements for good alerts and started our journey together to create a solid detection rule in Splunk that satisfy the requirements. This time we will correlate multiple alerts into a single incident with Aggregation and Deduplication. We will also reorganize the ticket description to improve both readability and flexibility in the future. Our second rule iteration looks like this: We added 2 new sections to the rule and made major update to one more: The second iteration of our detection rule creates incidents that are certainly more pleasing to the eye.

Explore this link on the map →