Access Detection Studio to identify optimal detections

Install Splunk Enterprise Security (Cloud) on AWS to access Detection studio.
Note: Detection Studio is automatically provisioned if you are on Splunk Enterprise Security (Cloud version) and is available on AWS Cloud for both Essentials and Premier editions.
  1. In Splunk Enterprise Security, go to Security content and select Detection Studio.
  2. Go to Launchpad dashboard to view the available detections and deployed detections.
  3. Go to MITRE ATT&CK coverage dashboard to view and drill-down into the individual techniques that are used in detections.
  4. Go to Detection library dashboard to deploy only those detections that are most actionable and relevant to reduce alert noise.
  5. Go to Configure to customize the detection priority and health algorithms for your specific security environment.