splunk / rba

RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
49Updated last month

Alternatives and similar repositories for rba:

Users that are interested in rba are comparing it to the libraries listed below