Building on the Splunk Enterprise Security platform, the Outpost Risk Based Alerting (RBA) Splunk application allows you to enter a new future with your SOC program. By breaking the cycle of 1 event creates 1 alert, you will reduce noise and gain a richer view of the threats your organization is facing. Since delivering the very first talk on RBA at .conf in 2018, we have aggregated our RBA experience at Fortune 500 organizations (hundreds of detections generating thousands of alerts) to create this Splunk app. With customization features such as suppression and self-aware alerting, along with our consultive implementation program, your organization will achieve an enterprise built and tuned RBA program, scaled to reflect your environment and culture around threats. Why spend over a year building out your RBA program? By leveraging OutpostRBA, you can realize the benefit of a risk based approach with 60% true positive rates and 50% fewer alerts in as little as 8 weeks
(0)
Categories
Created By
Type
Downloads
Splunk Answers
Resources