Splunk Detection Engineering

Use when building, tuning, or reviewing Splunk security detections — correlation searches, scheduled alerts, Enterprise Security notable events, risk-based alerting (RBA), or mapping detections to MITRE ATT&CK. Also when a detection is too noisy, misses true positives, or you need to reduce false positives. Covers detection logic, thresholds, throttling, and the detection lifecycle.

zap-coding-agent Updated

File contents

zap-coding-agent/awesome-skills/tree/main/splunk-detection-engineering commit 30f28d411b

Frequently asked questions

npx skillmds@latest add zap-coding-agent/splunk-detection-engineering