Skip to main content
false

Security Blogs

Security
3 Min Read
Announcing the availability of Cisco Talos Incident Response services to Splunk customers.

Latest Articles

Security 3 Min Read

Staff Picks for Splunk Security Reading: June 2018

A selection of presentations, white papers and blog posts you might have missed in June (or before), handpicked from the Splunk security world
Security 2 Min Read

Knowledge is Power: Guidance from ICO and NCSC on GDPR Security Outcomes

The GDPR learnings are ongoing - are you keeping up?
Security 2 Min Read

Detecting the Hidden Threat Before It’s Too Late

Unchecked, cybercriminals may establish communications channels inside your environment and send periodic beacons back to their own servers. Splunk Enterprise Security can help you stop them.
Security 4 Min Read

Staff Picks for Splunk Security Reading: May 2018

A selection of presentations, white papers and blog posts you might have missed in May (or before), handpicked from the Splunk security world
Security 3 Min Read

Boss of the SOC (BOTS) Investigation Workshop for Splunk

You've played BOTS with Splunk, now learn the how it all happened? This post discusses a new tutorial app that you can run on the BOTS v1 dataset to learn more about BOTS and have an educational workshop at home (or office)
Security 2 Min Read

The Importance of Enforcing Multifactor Authentication in Your AWS Environment

A new detection search in Splunk Enterprise Security Content Update v 1.0.15 helps you monitor for users in your AWS environment for users not being authorized by multiple factors
Security 2 Min Read

Clearer Insights and Investigations: Splunk Enterprise Security 5.1

Announcing the release of Splunk Enterprise Security 5.1, featuring a visual refresh compatible only with Splunk Enterprise 7.1
Security 2 Min Read

Boss of the SOC Scoring Server, Questions and Answers, and Dataset! Open-Sourced and Ready for Download

We have open-sourced the Boss of the SOC dataset (ver1.0) and BOT(S|N) scoring server. They can be used to run your own CTF, perform research, or train your internal users!
Security 1 Min Read

Detect and Investigate Malicious Activity in Your AWS Environment with Splunk Enterprise Security Content Update

A new Enterprise Security Content Update Analytic Story helps you monitor for suspicious events that could indicate that an adversary has compromised your cloud.
Security 3 Min Read

Splunk’s Security Story: Expand Your World

Reason #356 that Splunk rocks worlds: The ability to give multiple Aha! moments
Security 3 Min Read

Staff Picks for Splunk Security Reading: April 2018

A selection of presentations, white papers and blog posts you might have missed in April (or before), handpicked from the Splunk security world
Security 1 Min Read

Sneak Preview of the Enterprise Security Content Update for March 28, 2018 (Part 2)

A second look at the highlights of what's included in the Enterprise Security Content Update for March 28, 2018
Security 3 Min Read

Staff Picks for Splunk Security Reading: March 2018

A selection of presentations, white papers and blog posts you might have missed in March, handpicked from the Splunk security world
Security 1 Min Read

Strengthen Your SIEM And Be Ready For The GDPR

When facing the GDPR, your SIEM solution can be a great support for your organisation's compliance strategy, but if not strengthened - it can also be your downfall.
Security 3 Min Read

Staff Picks for Splunk Security Reading: February 2018

A monthly series of picked content from the Splunk security world. Each month will have a new selection of Splunk security presentations, white papers, or blog posts that you might have missed.
Security 2 Min Read

Use Investigation Workbench to Reduce Time to Contain and Time to Remediate

The latest version of Splunk Enterprise Security v 5.0 introduces Investigation Workbench, which streamlines investigations and accelerates incident response
Security 4 Min Read

Being Your Own Detective with SA-Investigator

This post of the Back to Basics Hunting series with Splunk discusses how to use the new SA-Investigator add-on for Enterprise Security to dig deep into your datamodels and find the evil lurking within.
Security 2 Min Read

Splunk Named in Gartner 2017 Critical Capabilities for SIEM Report

Splunk was named in the Gartner 2017 Critical Capabilities for Security Information and Event Management report and received the highest score in the Basic Security Monitoring Use Case