Risk-Based Alerting: The New Frontier for SIEM | Splunk
Splunk is committed to using inclusive and unbiased language. This blog post might contain terminology that we no longer use. For more information on our updated terminology and our stance on biased language, please visit our blog post. We appreciate your understanding as we work towards making our community more inclusive for everyone. If you haven't heard the gospel of risk-based alerting (RBA) in a SIEM context, by the end of this sermon you'll see why you’ll want it running in your environment yesterday, whether you're an analyst, an engineer, or in leadership. On a sunny Orlando day in 2018, Jim Apger of Splunk and Stuart McIntosh (now of Outpost Security) delivered a talk about RBA for Splunk's .conf that melted my mind onto a crappy conference room chair. The RBA methodology had been used in other contexts, but for some reason it had not yet been operationalized into a SIEM product where its capabilities could truly shine. With the flexibility of Splunk Processing Language (SPL)
Risk-Based Alerting: The New Frontier for SIEM | Splunk Risk-Based Alerting: The New Frontier for SIEM Security April 04, 2022 Haylee Mills Splunk is committed to using inclusive and unbiased language. This blog post might contain terminology that we no longer use. For more information on our updated terminology and our stance on biased language, please visit our blog post . We appreciate your understanding as we work towards making our community more inclusive for everyone. If you haven't heard the gospel of risk-based alerting (RBA) in a SIEM context, by the end of this sermon you'll see why
Explore this link on the map →saved by
related reading
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- How risk-based alerting works in Splunk Enterprise Security - Splunk Documentationdocs.splunk.com
- Securonix Documentationdocumentation.securonix.com
- Mediumdetect.fyi
- Evolving Your SIEM Detection Rules: A Journey from Simple to Sophisticated | Databricks Blogdatabricks.com
- Summit Route - How to write security alertssummitroute.com
- Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunksplunk.com
- Why did we need to build our own SIEM?rippling.com
- Exabeam Advanced SIEM and User Behavior Analytics Gives MTI a Clearer View of Risk Posture | Exabeamexabeam.com