BigHugger
sk Skill · mukul975

triaging-security-alerts-in-splunk

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
incident-reviewcorrelation-searchPythonnotable-eventssplsiemalert-triagesplunksoc
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python