
Organization Struggles with High Volume of Splunk Alerts and Vulnerability Management
AlertManagementVulnerabilityManagementSecurityOperationsThreatDetection
The poster describes working at an organization where Splunk generates 10,000 alerts daily, including critical, high, and medium severity, but many are noise (e.g., VPN logins or routine script failures). They struggle to triage effectively, leading to real threats being overlooked. The team has 5,000 open vulnerabilities across 200 servers with no clear prioritization method, and attempts like baselining had minimal impact. Leadership demands daily vulnerability reports, while the CFO pressures the team after a low-priority issue caused a problem.