Hybrid: DASUG 2nd-Tuesday Apr 11 presents: Optimizing your SIEM: Best Practices from the CrazyVerse!

Dallas Area Splunk User Group

April 11, 2023, 11:00 PM UTC – April 12, 2023, 2:00 AM UTC

15
RSVPs

Do you think your Splunk-based SIEM as as good as it can be? Are you periodically reviewing the initial setup underpinnings to be sure they are still valid? Could it be that you don't know what you don't know? Whether you are using ES, Alert Manager or your own home-brew thing, this DASUG will help! This will be BOTH a virtual event AND a live event @ NEW VENUE: Set Solutions in Frisco!

About this event

Do you use DataModels?  Do you use the Common Information Model?  Do you use drilldowns?  Do you use Macros? Do you think your Splunk-based SIEM as as good as it can be? Are you periodically reviewing the initial setup underpinnings to be sure they are still valid? Could it be that you don't know what you don't know? Whether you are using ES, Alert Manager or your own home-brew thing, this DASUG will help! 

You will walk away with:
1: A search to validate your CIM index macros.
2: A search to validate your SIEM Search curation.
3: Macros to make your searches/drilldowns more accurate, flexible, and easy to read.

This will be BOTH a virtual event AND a live event @ NEW VENUE: Set Solutions in Frisco:
25N Coworking Frisco
9355 John W. Elliott Dr #25
Frisco, TX 75033

Located in the first floor of the Waterford Market apartments.

See map for the main entrance and parking information:
https://drive.google.com/file/d/1BOQD6k4ou-FZiBg3bim-Avh9j_RAC1eo

Feel free to start the conversation early in the #dallas channel of splunk-usergroups.slack.com (sign up with http://splk.it/slack).

Agenda

11:00 PMSoft Start
11:30 PMHard Start
12:30 AMQandA
1:00 AMFree Time