Skip to content

Commit

Permalink
Update this_then_that_alerts.md
Browse files Browse the repository at this point in the history
Added Ryan Moss' analytic stories conf talk
  • Loading branch information
7thdrxn authored Apr 15, 2024
1 parent 84e26f3 commit cb043c9
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion docs/searches/this_then_that_alerts.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ index=risk sourcetype=stash search_name="Search1" OR search_name="Search2"
The benefit of not doing this in a single search is you still have the individual risk events as useful observations, and then can add more risk when observed together, or tweak risk down for noisy events without "allowlisting" altogether.
[Ryan Moss from Verizon also spoke about using Analytic Stories with RBA](https://conf.splunk.com/files/2023/recordings/SEC1402A.mp4) which is another excellent method for low volume, high fidelity chained detections.
---
<small>Authors</small>
Expand All @@ -23,4 +25,4 @@ The benefit of not doing this in a single search is you still have the individua
<img class="github-avatar" src="https://avatars.githubusercontent.com/u/12771156?v=4){ class="github-avatar"/>
</a>
<span class="zts-tooltip-text">@7thdrxn - Haylee Mills</span>
</div>
</div>

0 comments on commit cb043c9

Please sign in to comment.