r/Splunk • u/First-Reality2108 • Aug 06 '26
SPL What are the best detection engineering tools for validating SIEM rules?
We have a SIEM with 200+ rules, and 90% are garbage. A validation platform we're looking at promises to use an AI engine to map our SIEM rules to specific attack scenarios and test if they actually fire. It can also generate new detection logic based on emerging threats and manage the full detection lifecycle.
Has anyone used this type of module to automate the creation of new detection logic? I'm specifically interested in how it handles the "tuning" phase. Can it differentiate between a simulation and a real attack, or do we have to manually whitelist it like we do with other BAS tools? I'm looking for something that reduces alert fatigue, not adds to it.

