SS-SUBJ-39: Risk Based Alerting

Episode 39 December 12, 2021 00:38:46
SS-SUBJ-39: Risk Based Alerting
Security Serengeti
SS-SUBJ-39: Risk Based Alerting

Dec 12 2021 | 00:38:46

/

Show Notes

In this episode, we discuss Risk Based Alerting, a new paradigm in alerting released in a talk at Splunk .conf in 2018.  We're big fans, and we discuss it from start to finish, and share some stats on how much it improved alerting at the companies who have implemented it.

You have to register at Splunk's .conf site to watch the talks, but it's free.  The talks themselves can be found here: https://conf.splunk.com/watch/conf-online.html

After registration and logging in, search for "Risk Based Alerting" and that will get you the majority of the talks.  

If you found this interesting or useful, please like and subscribe, and follow us @serengetisec for more!  Without that social validation, we just sulk around the house all day.

Other Episodes

Episode 80

October 03, 2022 00:35:53
Episode Cover

SS-NEWS-080: Sneaking RATs, and a Bloomberg Terminal for Security

We discuss a new malware-as-a-service offering, bankers dodging regulations by using third party chat, and what would a Bloomberg Terminal for security look like?...

Listen

Episode 75

August 29, 2022 00:31:56
Episode Cover

SS-NEWS-075: Criminals turning from selling drugs to cybercrime?

In this episode, we discuss street criminals turning from drug related crime to fraud and potentially cybercrime, and PyPI's issues with malicious packages. Article...

Listen

Episode 121

August 07, 2023 00:32:21
Episode Cover

SS-NEWS-121: Phones as Snitches and the End of Log Centralization?

This week we discuss the TSA and their endless privacy invasions (this time... facial recognition!), an Anton Chuvakin post on the end of Log...

Listen