RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
-
Updated
Dec 9, 2024
RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
Add a description, image, and links to the splunk-rba topic page so that developers can more easily learn about it.
To associate your repository with the splunk-rba topic, visit your repo's landing page and select "manage topics."