Latest Version 1.0.3
August 22, 2023
The Tuning Framework is a custom framework built in Splunk to facilitate tuning detection rules to suppress false positives or adjust risk score for Risk Based Alerting. The framework implements a small number of lookups and macros to dynamically suppress events or adjust risk scores for all correlation searches based on any combination of fields within the events. For most Splunk environments, this will enhance analysts ability to quickly tune rules and greatly reduce the lift from Splunk administrators.
(0)
Categories
Created By
Source Code
Type
Downloads
Licensing
Splunk Answers
Resources