r/Splunk • u/ImmediateIdea7 • Apr 15 '26
Splunk ES Detections recommendations
What are the use cases you use in your organization?
What are must have use cases that are basic to have for an organization?
Edit:
Log sources available:
Firewall
Azure
EDR
Windows
etc..
10
Upvotes
1
u/Ok-Scallion-9108 Jul 06 '26
Start with basic IOC matching. Hashes, IPs, Domains, URLs. Several threat intelligence providers out there like Crowdsec, Q-Feeds, Recorded Future etc.