splunk / rba

RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.

Home Page:https://splunk.github.io/rba/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

splunk/rba Issues