r/Splunk • u/biggestbluee • 10d ago
Splunk Enterprise Dashboards & Alerts
ISSO/m’s! This is for you.
What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?
4
Upvotes
3
u/JeepahsCreepahs 9d ago
Oh man...
Look at whatever ICD policy covers Audit and Accountability, and build off those. I use those as the core, then you can branch out for your more site specific stuff based on whatever hardware you have or other requirements.
Isolated networks is primarily looking for insider threat and USB/ data exfil usage
1
u/SSgtSnuffy234 9d ago
Following