Video

Splunk for Security: SSE - Content Introspective

Episode 1

Play Video

Video Summary

This video introduces the advanced search assistance features in Splunk Security Essentials, focusing on how they help identify unusual behaviour patterns. The session begins with a demonstration of the "Detect Spikes" feature, which identifies significant increases in activity, such as a surge in file accesses or system errors. By defining searches, grouping data, and applying threshold methods like standard deviation, users can quickly pinpoint outliers, such as a system producing an unexpected number of errors. This functionality empowers organisations to monitor and address anomalies effectively, enhancing their security visibility.

The video also explores the "Detect New Values" feature, which highlights instances where users or systems exhibit previously unseen behaviour. For example, it detects first-time system access or novel processes running on a machine. Peer group analysis is introduced to refine these detections, ensuring common activities, like new team members accessing shared systems, are excluded. Additionally, the use of lookup caches is demonstrated, allowing continuous tracking of user activity over time. This approach ensures efficient detection of genuinely new events without relying on extensive historical data. Stay tuned for more insights into leveraging Splunk Security Essentials for robust security operations.

Additional Resources

Who are Somerford?

We are a passionate group of people delivering innovation to our customers on their digital transformation journey.

Splunk Edge Hub

Effortlessly streamline the process of inegrating your data with the Splunk Edge Hub

Splunk Security Solutions

Utilise Splunk's suite of security solutions designed to provide uniefied and robust defence against cyber threads.

Get in Touch to Learn More

With specialist knowledge, skills and experience derived from supporting a broad range of FTSE 100, FTSE 250 and smaller companies Somerford Associates have a strong reputation for enabling digital transformation at scale, at pace and in budget.
Scroll to Top