flâneur — a map of the web's best reading

How risk-based alerting works in Splunk Enterprise Security - Splunk Documentation

docs.splunk.com · 3,224 words · saved by 1 readers

With risk-based alerting (RBA), analysts receive risk notables from risk incident rules, which surface from multiple risk events. RBA uses the existing Splunk Enterprise Security correlation search framework to collect all risk events into a single risk index. Events collected in the risk index create a single risk notable when they meet a specific criterion, which warrants an investigation. For example, suppose a single system creates five risk events from several risk rules. Each of these risk events have a low risk score. However, when taken together these risk event surpass the risk score threshold, pertain to specific MITRE ATT&CK techniques, and are associated with unique data sources over multiple time frames. RBA can pick up on this threat even when the system generates only a single risk notable because it performs correlated alerting that tells a high-fidelity security story, which analysts can investigate. Similarly, RBA effectively helps to detect complex behavior over a "p

How risk-based alerting works in Splunk Enterprise Security - Splunk Documentation You are using an outdated browser. Please upgrade your browser to improve your experience. Splunk ® Enterprise Security Use Splunk Enterprise Security Risk-based Alerting Splunk Cloud Platform ™ Splunk ® Enterprise Splunk ® Universal Forwarder Splunk ® Data Stream Processor (EOS) Splunk ® Cloud Services Splunk ® Attack Analyzer Splunk ® App for Splunk Attack Analyzer Splunk ® Add-on for Splunk Attack Analyzer Splunk ® Asset and Risk Intelligence Splunk ® Asset and Ri

Explore this link on the map →

related reading