From the course: SIEM: Event Management with Splunk Security
Unlock the full course today
Join today to access over 24,900 courses taught by industry experts.
Managing critical events - Splunk Tutorial
From the course: SIEM: Event Management with Splunk Security
Managing critical events
- When working in cybersecurity, every now and then we experience attacks that are particularly aggressive or imminent. Splunk helps us identify whether or not something might be actionable. When something is so threatening that we must immediately take action, we call these critical events. One confusing thing about security information and event management is figuring out what to monitor and what matters. Splunk's labels and prebuilt templates help us understand what sorts of attacks we should take action on immediately. Using Security Essentials, head over to search through Splunk's demo data to identify what sort of event that we might need to drop everything for. Let's take a look at this remote desktop event. If something is marked as a critical event, this means that a criminal attacker is actively impacting our company and action needs to be taken right away to resolve this incident. Since we don't have…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.