Operations | Monitoring | ITSM | DevOps | Cloud

Threat Hunting with Cribl Search

Imagine you’re the protector of a castle. Your walls are tall, the gates are strong, and the guards are well-trained. But what if an intruder was still able to slip past your defenses? Even with the best security tools, not every threat will be caught. Threat hunting is the proactive approach to finding attackers that might have bypassed your defenses.

Accelerate Visibility and Analysis With New Cribl Search Packs

Our new Cribl Search Packs give you a framework for packaging, sharing, and installing config bundles that align with a given data source or use case. Similar in concept to our original Cribl Stream Packs framework, Cribl Search Packs help users find value in their datasets more quickly across common use cases. In fact, Stream Pack users were a powerful driver in the development of Search Packs.

Top Tips for Querying OpenSearch

OpenSearch allows you to store a sizeable amount of data, commonly logs, metrics, and documents. You access useful data within OpenSearch by querying to get specific information, deep analysis, and insights for decision-making. With OpenSearch, you can perform complex searches by using natural language, Boolean operators, and filters to pinpoint relevant information efficiently.

Introducing Charmed OpenSearch

Introducing Charmed OpenSearch – an enterprise solution for OpenSearch with advanced automation features, multi-cloud capabilities, and comprehensive support. OpenSearch is an open source search and analytics suite that developers use to build solutions for search, observability, security analytics, generative AI projects, and more. Charmed OpenSearch builds on this foundation with additional enterprise-grade capabilities that can help you spend less time on operational tasks and more time on high-value data and analytics projects.

Mastering Null Semantics: Translating SQL Expressions to OpenSearch DSL

Working at Coralogix, a leading full-stack observability platform, I recently faced an interesting challenge. The team I am part of is building the DataPrime query language and query engine, used to easily query logs and other observability data on the platform, usually in the form of Parquet files on AWS S3. Inside the engine, our DataPrime queries are transformed into query plans with SQL-like expressions, for example in filters.

New GenAI Search Revamps Customer Experience

Splunk has launched a GenAI summary feature in splunk.com and docs.splunk.com search platforms designed to give users a quick and accurate glance of the most pertinent information they are looking for. This GenAI feature serves up a contextual high-level summary pulled from various relevant search results on topics ranging from Splunk product and feature usage to general Splunk terminology.

The Best Elasticsearch Alternatives

Elasticsearch is a distributed search and analytics engine that provides real-time operations and scales Horizontally. This assists users in making quick and effective searches, as well as analyzing, and visualizing huge data volumes. Users commonly commend Elasticsearch for its data indexing and storage capabilities. They highlight its efficiency in indexing text data and its proficiency in managing large data sets for persistence and retrieval.

Elastic Search 8.15: Accessible semantic search with semantic text and reranking

In 8.15, great search results are even more accessible for our customers. Our latest release brings semantic reranking, additional vector search tools, and more third-party model providers and promotes our native Learning to Rank (LTR) to generally available. And now search is more performant than ever with additional speed and efficiency improvements.