From the course: SIEM: Event Management with Splunk Security

Unlock the full course today

Join today to access over 24,900 courses taught by industry experts.

Incident response, disaster recovery, and executing case management strategies

Incident response, disaster recovery, and executing case management strategies - Splunk Tutorial

From the course: SIEM: Event Management with Splunk Security

Incident response, disaster recovery, and executing case management strategies

- When disaster strike it's important to have an incident response plan in place. Splunk offers amazing resources for improving and expanding our company's incident response, disaster recovery, and case management strategies. The most important thing to understand here is the power of developing strong workflows. One example of a workflow that benefits every company is backups. Everyone needs backups to protect our data and disaster recovery use cases are a great starting place for prioritizing our best practices. Let's walk through an example of how we might produce an event management focused workflow for incident response using samples from Splunk. We'll focus on a single use case at a time. It's important to prioritize use cases one at a time rather than attempting to multitask to get SIM to work most effectively for us. We've chosen to start with this incident response rule, since all companies need secure backups…

Contents