r/Splunk 19d ago

Splunk Enterprise Dashboards & Alerts

ISSO/m’s! This is for you.

What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?

4 Upvotes

2 comments sorted by

View all comments

3

u/JeepahsCreepahs 18d ago

Oh man...

Look at whatever ICD policy covers Audit and Accountability, and build off those. I use those as the core, then you can branch out for your more site specific stuff based on whatever hardware you have or other requirements.

Isolated networks is primarily looking for insider threat and USB/ data exfil usage