Open in app
Home
Notifications
Lists
Stories

Write
Merih Bozbura
Merih Bozbura

Home

Published in Seynur

·Pinned

Risk-Based Alerting (RBA) with Splunk Enterprise Security

Alert fatigue and false-positive results are the most common problems in a Security Operation Center (SOC) environment. The correlation searches are generally based on static thresholds, and if a particular point exceeds, an alert is triggered. No matter how we try to tune these searches, sometimes this can cause the…

Splunk

5 min read

Risk-Based Alerting (RBA) with Splunk Enterprise Security
Risk-Based Alerting (RBA) with Splunk Enterprise Security

Published in Seynur

·Pinned

Splunk Data Models & CIM

In this post, you will find out what Splunk data models and CIM (Common Information Model) are and why they hold that much importance. Splunk is a scalable system that uses any machine data (all IT streaming, machine, and historical data, such as Windows event logs, web server logs, live…

Splunk

7 min read

Splunk Data Models & CIM
Splunk Data Models & CIM

Published in Seynur

·Nov 1, 2021

Restoring Archived Data with Splunk

Data retention policies help to manage organizations’ big data. Since the amount of data collected today is tremendous, establishing a retention policy is crucial as ingesting the correct data source. The retention policy is basically how long the organization wants to keep the data. …

Splunk

5 min read

Restoring Archived Data with Splunk
Restoring Archived Data with Splunk

Published in Seynur

·Jan 26, 2021

Syslog Data Collection (SC4S) for Splunk and Custom Inputs

As per Splunk Validated Architectures, Splunk Connect for Syslog (SC4S) is the current best practice recommendation to collect syslog data. This article provides instructions on how to configure custom syslog inputs (also how to filter out the data) to be ingested to Splunk. Splunk Connect for Syslog (SC4S) is a…

Splunk

3 min read

Syslog Data Collection (SC4S) for Splunk and Custom Inputs
Syslog Data Collection (SC4S) for Splunk and Custom Inputs
Merih Bozbura

Merih Bozbura

Following
  • Michael Haag

    Michael Haag

  • Deniz Kerpicci

    Deniz Kerpicci

  • David Lee

    David Lee

  • Selim Seynur

    Selim Seynur

  • xknow_infosec

    xknow_infosec

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable