Customize detection priority and health algorithms using Detection Studio in Splunk Enterprise Security

Use the Configure to customize the priority and health algorithms for detections to better suit the specific requirements of your security environment.
  1. In Splunk Enterprise Security, access Detection Studio.
  2. Select Configure and go to Priority algorithm to configure how the priority of the detection is calculated by adjusting the weight of each factor such as Impact, Confidence, Compatibility, and Performance.
  3. Select the values such as None, Low, Medium, High, and Extreme for each of the factors.
  4. Select Configure and go to Health algorithm to configure how the health of the detection is calculated by adjusting the weight of each factor such as Confidence, Compatibility, and Performance.
  5. Select the values such as None, Low, Medium, High, and Extreme for each of the factors.
  6. Select Save or Rest to default.