2 Comments
User's avatar
Haylee's avatar

This is incredible. I've done some meta-scoring style stuff before:

https://splunk.github.io/rba/searches/risk_incident_rule_ideas/#events-from-multiple-sourcetypes

but I *love* the idea of giving labels to other things to dc() on for more dimensionality. Definitely going to build on this! Thank you. โœจ

Certis Foster's avatar

Your welcome Haylee (RBA Queen) ping me if you want to flush out any extra ideas. ๐Ÿ˜Ž