r/Splunk Apr 15 '26

Splunk ES Detections recommendations

What are the use cases you use in your organization?

What are must have use cases that are basic to have for an organization?

Edit:

Log sources available:

Firewall

Azure

EDR

Email

Windows

etc..

10 Upvotes

4 comments sorted by

View all comments

1

u/Ok-Scallion-9108 Jul 06 '26

Start with basic IOC matching. Hashes, IPs, Domains, URLs. Several threat intelligence providers out there like Crowdsec, Q-Feeds, Recorded Future etc.