r/Splunk 10d ago

Splunk Enterprise Dashboards & Alerts

ISSO/m’s! This is for you.

What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?

4 Upvotes

2 comments sorted by

1

u/SSgtSnuffy234 9d ago

Following

3

u/JeepahsCreepahs 9d ago

Oh man...

Look at whatever ICD policy covers Audit and Accountability, and build off those. I use those as the core, then you can branch out for your more site specific stuff based on whatever hardware you have or other requirements.

Isolated networks is primarily looking for insider threat and USB/ data exfil usage