Building Correlation Searches With Splunk Enterprise Security Takeaway
Building Correlation Searches With Splunk Enterprise Security Takeaway
Thank you for attending our Building Correlation Searches with Splunk Enterprise Security
workshop. We hope you found it helpful. Below are links referenced during the workshop as
well as some other helpful links to use.
Apps Referenced
Search Foundations
Search Reference -
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/WhatsInThisManual
Conf17 Talk: Searching Fast: How To Start using tstats and Other Acceleration Techniques -
https://conf.splunk.com/files/2017/slides/searching-fast-how-to-start-using-tstats-and-other-
acceleration-techniques.pdf
© 2020 Splunk 1
Cisco ASA TA Documentation Example -
https://docs.splunk.com/Documentation/AddOns/released/CiscoASA/Description
Add-on Builder -
https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/UseTheApp
Conf17 Talk: Searching Fast: How To Start using tstats and Other Acceleration Techniques -
https://conf.splunk.com/files/2017/slides/searching-fast-how-to-start-using-tstats-and-other-
acceleration-techniques.pdf
tstats command -
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Tstats
Splexicon - https://docs.splunk.com/Splexicon
© 2020 Splunk 2
Sigma Detection for Exercises #4-6 -
https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_n
tdsutil.yml
Conf19 Talk: Enterprise Security Biology III: Dissecting the Incident Management Framework -
https://conf.splunk.com/files/2019/slides/SEC1544.pdf
MITRE ATT&CK
Sources of Content
Additional Resources
© 2020 Splunk 3
Incident Management/Notable Event Framework - http://dev.splunk.com/view/enterprise-
security/SP-CAAAFA9
Optional Exercises
© 2020 Splunk 4