awesome-es icon indicating copy to clipboard operation
awesome-es copied to clipboard

A collection of awesome resources for Splunk Enterprise Security

Awesome ESAwesome

A curated list of awesome resources for Splunk Enterprise Security.

Contents

  • Basics
  • Education and Training
  • Professional Services
  • SOAR Integration
  • Threat Intelligence
  • .Conf Presentations

Basics

Resources for getting started with Splunk Enterprise Security.

Education and Training

Professional Services

Need to get the experts involved in an Enterprise Security implementation, or seeing guidance.

Risk Based Alerting

  • RBA All Day - Reduce noise by using a Risk Based approach to notable event generation.
    • SA-RBA - Solution AddOn for ES, adds custom visualisations and correlation searches for RBA.
    • Phantom RBA - Phantom functions for RBA investigations and enrichment.

SOAR Integration

Threat Intelligence

.Conf Presentations

Selected .conf presentations related to various aspects of Splunk Enterprise Security.

Contribute

Contributions welcome! Read the contribution guidelines first.

License

CC0

To the extent possible under law, Simon Duff has waived all copyright and related or neighbouring rights to this work.