top of page
Geeking out on Splunk and IT Security
Search
Gabriel Vasseur
Jan 612 min read
RBA: Aggregate user & system risks!
Since RBA is all about aggregating security events that are related to the same entity, Assets & Identities normalisation is crucial to...
58 views0 comments
Gabriel Vasseur
Dec 2, 20241 min read
Untable, xyseries, transpose clarified!
These 3 table-manipulating commands are occasionally very useful but they are also quite confusing. For years, I've relied on the...
32 views0 comments
Gabriel Vasseur
May 22, 20234 min read
RBA: a better way to dedup risk events
In this post we’re discussing an advanced way to dedup risk events in your risk alerts (RIRs) and at the same time have the RIR results...
124 views0 comments
Gabriel Vasseur
Apr 30, 20225 min read
Linux tips
This for the most part isn't splunk-specific, but if you do any amount of administration on the linux command line, you might find it...
5 views0 comments
Gabriel Vasseur
Apr 26, 20221 min read
Splunk workload optimisation
Assess your search workload with this simple dashboard. Here's a very quick dashboard to identify what uses your splunk platform...
5 views0 comments
Gabriel Vasseur
Oct 19, 20219 min read
Dashboarding Best Practices, Tips & Tricks
Splunk’s “simple XML” dashboards are reasonably simple and straightforward to create, yet they are incredibly versatile and powerful. You...
48 views0 comments
Gabriel Vasseur
Oct 19, 202111 min read
Audit your correlation searches against your own Best Practices automatically
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is Correlation Searches Best...
28 views0 comments
Gabriel Vasseur
Oct 19, 20211 min read
Test your correlation searches end-to-end with Morning Checks
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is morning checks. Basically you...
6 views0 comments
Gabriel Vasseur
Oct 19, 20212 min read
Add an in-splunk after-the-fact Peer Review system for your correlations
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is having a simple peer review...
2 views0 comments
Gabriel Vasseur
Oct 19, 20211 min read
Add a simple TODO management system for your correlations
I did a talk at Splunk .conf21 about how to maintain correlation searches: pdf / mp4 . One of the topics is having a simple task...
2 views0 comments
Gabriel Vasseur
Oct 18, 20213 min read
Easy yet powerful submit buttons in your simple XML dashboards
There are a number of issues with Splunk’s simple XML forms submit button: you can't have more than one you can't move it you can't hide...
34 views0 comments
bottom of page