Skip to content

Welcome to The RBA Community GitHub repo! 👋

The RBA Community is a group of professionals dedicated to advancing the field of risk-based alerting (RBA) and Splunk Enterprise Security (ES). Our mission is to provide a forum for sharing knowledge, best practices, and the latest developments in RBA and ES, and to help professionals enhance their understanding and skills in these areas.

Pinned Loading

  1. threat_object_fun threat_object_fun Public

    An illustrative app for working with Threat Objects.

    1

  2. SA-PaloAltoIoTDevices SA-PaloAltoIoTDevices Public

    This supporting add-on comes with prebuilt content for Palo Alto IoT data to be easily used with Splunk Enterprise Security's Asset database.

  3. SA-CortexXDRDevices SA-CortexXDRDevices Public

    This supporting add-on comes with prebuilt content for Palo Alto Networks Cortex XDR data to be easily used with Splunk Enterprise Security's Asset database.

  4. SA-CrowdstrikeIntelIndicators SA-CrowdstrikeIntelIndicators Public

    This supporting add-on Adds CrowdStrike's intelligence indicators to Splunk Enterprise Security's threat framework.

    1

Repositories

Showing 9 of 9 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…