This app is archived. Learn more
This app is a companion app to the Build Correlation Searches with Splunk Enterprise Security Hands On Workshop based on the BOTS v4 data set. It is designed to be installed on top of a Splunk ES instance and contains a module for the Use Case Library, complete with an Analytic Story containing Correlation Searches that users can apply to their own ES instance. Many of these searches are derived from the SIGMA project https://github.com/Neo23x0/sigma. The decrypt app is required for the PowerShell Encoding Correlation Search and can be found here: https://splunkbase.splunk.com/app/2655/.
(0)
Categories
Created By
Contributors
Type
Downloads
Licensing
Splunk Answers
Resources