top of page
Geeking out on Splunk and IT Security
Search


RBA: Aggregate user & system risks!
Since RBA is all about aggregating security events that are related to the same entity, Assets & Identities normalisation is crucial to...
Gabriel Vasseur
Jan 612 min read
156 views
0 comments


Untable, xyseries, transpose clarified!
These 3 table-manipulating commands are occasionally very useful but they are also quite confusing. For years, I've relied on the...
Gabriel Vasseur
Dec 2, 20241 min read
55 views
0 comments
Use Ingest Actions to shrink your ingest and make the most of your license!
On the 18th of September 2024 I gave a talk on this topic at the London Splunk User Group meetup. Ingest Actions are a simple feature of...
Gabriel Vasseur
Sep 20, 20241 min read
54 views
0 comments

"And the nominees are..." - Wish me luck!
I have been nominated for a 2023 Splunkie Award and I am delighted to be a finalist for the Inventor Award! https://conf.splunk.com/the-s...
Gabriel Vasseur
Jul 3, 20231 min read
7 views
0 comments

RBA: a better way to dedup risk events
In this post we’re discussing an advanced way to dedup risk events in your risk alerts (RIRs) and at the same time have the RIR results...
Gabriel Vasseur
May 22, 20234 min read
204 views
0 comments
Site Map
Use this page as a quick way to find which areas of this website have value for you. My apps ES Choreographer : manage ES correlation...
Gabriel Vasseur
May 16, 20231 min read
36 views
0 comments

Conf Manager
This is the documentation for the Conf Manager app on splunkbase. This app allows you to search your knowledge objects and track their...
Gabriel Vasseur
May 16, 202310 min read
156 views
0 comments
Linux tips
This for the most part isn't splunk-specific, but if you do any amount of administration on the linux command line, you might find it...
Gabriel Vasseur
Apr 30, 20225 min read
7 views
0 comments

Splunk workload optimisation
Assess your search workload with this simple dashboard. Here's a very quick dashboard to identify what uses your splunk platform...
Gabriel Vasseur
Apr 26, 20221 min read
10 views
0 comments

ES-Choreographer
This is the documentation for the ES-Choreographer app on splunkbase. This app offers various frameworks to help manage and improve...
Gabriel Vasseur
Feb 28, 202210 min read
141 views
0 comments

GV-Utils
This is the documentation for the GV-Utils app on splunkbase. This app offers various utilities to solve a number of problems in Splunk:...
Gabriel Vasseur
Jan 10, 20228 min read
62 views
0 comments

Dashboarding Best Practices, Tips & Tricks
Splunk’s “simple XML” dashboards are reasonably simple and straightforward to create, yet they are incredibly versatile and powerful. You...
Gabriel Vasseur
Oct 19, 20219 min read
54 views
0 comments

Maintaining your correlation searches with ES Choreographer
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . If you’re looking for the source code for the...
Gabriel Vasseur
Oct 19, 20211 min read
10 views
0 comments

Audit your correlation searches against your own Best Practices automatically
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is Correlation Searches Best...
Gabriel Vasseur
Oct 19, 202111 min read
38 views
0 comments

Test your correlation searches end-to-end with Morning Checks
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is morning checks. Basically you...
Gabriel Vasseur
Oct 19, 20211 min read
13 views
0 comments

Add an in-splunk after-the-fact Peer Review system for your correlations
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is having a simple peer review...
Gabriel Vasseur
Oct 19, 20212 min read
3 views
0 comments

Add a simple TODO management system for your correlations
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is having a simple task...
Gabriel Vasseur
Oct 19, 20211 min read
3 views
0 comments

Easy yet powerful submit buttons in your simple XML dashboards
There are a number of issues with Splunk’s simple XML forms submit button: you can't have more than one you can't move it you can't hide...
Gabriel Vasseur
Oct 18, 20213 min read
36 views
0 comments

Change Tracking in Splunk
Are you tracking changes in your Splunk deployment? Most people don't, unless they can justify having a custom (heavy!) process using...
Gabriel Vasseur
Oct 31, 20181 min read
28 views
0 comments

Running Splunk Enterprise Security at Capacity with Data Model Acceleration
Data models and especially their acceleration are often misunderstood by Splunk users. Yet they are absolutely critical, especially for...
Gabriel Vasseur
Oct 31, 20171 min read
23 views
0 comments
bottom of page