★ 0 · Updated 2026-09-20
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.
Browse skills that share this tag.
★ 0 · Updated 2026-09-20
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.
★ 0 · Updated 2026-09-20
Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate response procedures.
★ 0 · Updated 2026-09-19
Reduces SIEM false positives through rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
★ 0 · Updated 2026-09-19
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
★ 0 · Updated 2026-09-19
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
★ 70 · Updated 2026-09-19
Reduces SIEM false positives through rule tuning, threshold adjustment, correlation refinement, allowlisting, and threat intelligence enrichment.
★ 64 · Updated 2026-06-30
Correlates security events in IBM QRadar SIEM using AQL and custom rules to detect multi-stage attacks
★ 4 · Updated 2026-05-09
Classifies severity, investigates notable events, correlates telemetry, and makes triage decisions in Splunk Enterprise Security
★ 327 · Updated 2026-05-09
Classify severity, investigate notable events, correlate telemetry in Splunk Enterprise Security
★ 3,613 · Updated 2026-05-09
Triage security alerts in Splunk ES by classifying severity, investigating events, and making disposition decisions