2 Comments
User's avatar
Haylee's avatar

This is incredible. I've done some meta-scoring style stuff before:

https://splunk.github.io/rba/searches/risk_incident_rule_ideas/#events-from-multiple-sourcetypes

but I *love* the idea of giving labels to other things to dc() on for more dimensionality. Definitely going to build on this! Thank you. ✨

Expand full comment
Certis Foster's avatar

Your welcome Haylee (RBA Queen) ping me if you want to flush out any extra ideas. 😎

Expand full comment