When using Splunk Phantom to process notable events from Splunk ES, a best practice is to validate that the playbook the analyst is running is the right one for that notable event and they are running it on the correct artifact. Here are two tips for doing just that: Decision Block At the beginning of …
Continue reading “Splunk Phantom Tips: ES Notable Playbook Validation”