soc30 / lms
connected
splunk>enterprise
Administrator ▾Settings ▾
ES
Enterprise Security
Splunk App for Enterprise Security · v7.3.0
DAY 20 LAB · LAB 20 — DESIGN AN RBA PIPELINE· week 3
Design an RBA pipeline — sum small risks into one notable.
  • Security Intelligence → Risk Analysis.
  • Identify top 5 risk objects.
  • Build a search: sum(risk_score) > 100 → fire Notable.
  • Tune scores.
Hint: RBA cuts alert fatigue 10× — escalate only when accumulated risk crosses threshold.

Security Intelligence · Risk Analysis

Highest Risk Objects (computed)
risk_objecttypesum(risk)
admin_svcuser256
10.4.12.91system168
10.4.12.50system88
MITRE ATT&CK Techniques (live)
techniquecount
T14861
T1021.0021
T1136.0021
Drill-down
Risk scores aggregate live from current notables. Run adaptive responses in the modal to see scores update.