L.A.M.E. Creations has scoured the internet for guidance on the Enterprise Security SIEM from Splunk but has found most of the videos are behind a paywall. They decided to change that.
This video discusses the RBA Risk Based Approach that is available in Splunk Enterprise Security. RBA is a method of viewing alert notables across time to identify risk vs looking at the individual notables.
🎓 Free Splunk Enterprise Security Training (Concepts & Admin)
This video is part of my comprehensive "Zero to Hero" series on Splunk Enterprise Security. This playlist is designed to help you master the actual usage of ES, from understanding Data Models and CIM to implementing Risk Based Alerting (RBA) and SOAR.
📂 Watch the complete Training Playlist here: 👉 • Unlocking Splunk Enterprise Security: Expe...
What you will learn in this series: ✅ Core Concepts: Difference between Core Splunk vs. ES, and basic server setup. ✅ Data Normalization: Deep dives into Data Models, CIM Compliance, and field mapping (Web/Network). ✅ Security Operations: Incident Review, Correlation Searches, and Threat Intelligence. ✅ Advanced Features: Risk Based Alerting (RBA) and integrating SOAR.
⚠️ Note: This series covers fundamental ES concepts and earlier versions. If you are specifically looking for Splunk ES 8 Architecture & Installation, check out my new ES 8 series here: • Enterprise Security 8
Join this channel to get access to early release of videos and exclusive training videos that will help make you L.A.M.E. ninja: / @lamecreations_guides