Cisco Leverages Splunk Detection Editor to Enhance Risk-Based Security
Cisco's Splunk Detection Editor (Alpha) is being used to build a risk-based secure network analytics detection. The goal was to take active Cisco Secure Network Analytics (SNA) alarms and associate them with source systems, adding this information to the Splunk Enterprise Security risk index. This process aims to improve security by treating every observation as an incident and generating risk events associated with entities like systems or users.
The detection editor brings together several tasks that were previously separate in Splunk, including developing a detection, testing its logic, normalizing fields, configuring risk, and providing a path for further investigation. This streamlined process allowed the development of a more comprehensive detection, which acts as one source of risk evidence by adding an observation to the source system's risk history.
The editor also includes features like syntax highlighting, field completion, and integrated results, making it easier to test and refine the detection without leaving the workspace. The detection was designed to handle multiple SNA alarms referring to a single target or multiple targets, ensuring that only relevant information is presented to analysts.