{"id":166,"date":"2020-09-24T20:32:31","date_gmt":"2020-09-24T20:32:31","guid":{"rendered":"https:\/\/arter-demo.bslthemes.com\/?page_id=166"},"modified":"2020-09-24T20:32:31","modified_gmt":"2020-09-24T20:32:31","slug":"blog","status":"publish","type":"page","link":"https:\/\/logsmith.io\/index.php\/blog\/","title":{"rendered":"Blog"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"166\" class=\"elementor elementor-166\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-66cb952 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"66cb952\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-no\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-edca18a\" data-id=\"edca18a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-681945f elementor-widget elementor-widget-arter-blog-grid\" data-id=\"681945f\" data-element_type=\"widget\" data-widget_type=\"arter-blog-grid.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\n\t\t<!-- container -->\n\t\t<div class=\"container-fluid\">\n\n\t\t<!-- row -->\n\t\t<div class=\"row\">\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-12\">\n\t\t    <!-- section title -->\n\t\t    <div class=\"art-section-title\">\n\t\t      <!-- title frame -->\n\t\t      <div class=\"art-title-frame\">\n\t\t        <!-- title -->\n\t\t        <h4 class=\"art-title-h\">\n\t\t    \t<span >\n\t\t          \tBlog\t\t         <\/span>\n\t\t    \t<\/h4>\n\t\t      <\/div>\n\t\t      <!-- title frame end -->\n\t\t    <\/div>\n\t\t    <!-- section title end -->\n\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \n\t\t  \t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-369\" class=\"post-369 post type-post status-publish format-standard hentry category-masterclass tag-detection-engineering tag-detection-as-code tag-gitlab tag-masterclass tag-splunk-es\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/28\/detection-as-code\/\">\n\t\t\t\t<span class=\"art-el-date\">October 28, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Masterclass<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/28\/detection-as-code\/\">\n\t      <h5 class=\"mb-15\">\ud83d\udd27 Detection-as-Code: What It Really Means<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>Masterclass Series \u2013 Part 2 \ud83e\udded TL;DR: It\u2019s Not Just \u201cPut Your Rules in Git\u201d \u201cDetection-as-Code\u201d sounds like a trendy&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/28\/detection-as-code\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-367\" class=\"post-367 post type-post status-publish format-standard hentry category-insights tag-alert-fatigue tag-detection-engineering tag-insight tag-splunk-es\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/23\/the-cost-of-crying-wolf\/\">\n\t\t\t\t<span class=\"art-el-date\">October 23, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Insights<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/23\/the-cost-of-crying-wolf\/\">\n\t      <h5 class=\"mb-15\">The Cost of Crying Wolf: Why False Positives Are Killing Your SOC<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>Introduction It\u2019s not the alerts you miss that break a SOC \u2014 it\u2019s the thousands you never should have seen&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/23\/the-cost-of-crying-wolf\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-363\" class=\"post-363 post type-post status-publish format-standard hentry category-case-study tag-case-study tag-detection-engineering tag-log-normalisation\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/16\/when-cim-mapping-goes-sideways\/\">\n\t\t\t\t<span class=\"art-el-date\">October 16, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Case Study<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/16\/when-cim-mapping-goes-sideways\/\">\n\t      <h5 class=\"mb-15\">When CIM Mapping Goes Sideways: Lessons from a Broken Detection<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>\ud83d\udd0e Introduction Everything looked good on paper:\u2705 The detection rule was written.\u2705 The sourcetype was CIM-mapped.\u2705 The data model was&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/16\/when-cim-mapping-goes-sideways\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-356\" class=\"post-356 post type-post status-publish format-standard hentry category-masterclass tag-detection-engineering tag-masterclass tag-playbook tag-splunk\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/14\/macro-driven-rule-logic\/\">\n\t\t\t\t<span class=\"art-el-date\">October 14, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Masterclass<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/14\/macro-driven-rule-logic\/\">\n\t      <h5 class=\"mb-15\">\ud83e\udde0 Macro-Driven Rule Logic &#8211; Splunk Masterclass 1\/5<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>\ud83d\udc4b Welcome to the LogSmith Splunk Masterclass This series is for detection engineers, Splunk admins, and SOC architects who want&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/14\/macro-driven-rule-logic\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-351\" class=\"post-351 post type-post status-publish format-standard hentry category-insights tag-free-resource tag-insight\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/07\/5-signs-your-siem-is-too-noisy\/\">\n\t\t\t\t<span class=\"art-el-date\">October 7, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Insights<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/07\/5-signs-your-siem-is-too-noisy\/\">\n\t      <h5 class=\"mb-15\">5 Signs Your SIEM Is Too Noisy<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>And what to do about it before your SOC burns out Your SIEM might look functional. It might be alerting&#8230;. <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/07\/5-signs-your-siem-is-too-noisy\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-344\" class=\"post-344 post type-post status-publish format-standard has-post-thumbnail hentry category-case-study tag-alert-fatigue tag-case-study tag-detection-engineering tag-log-normalisation tag-splunk-es\">\n\t  <!-- post cover -->\n\t  \t\t\t\t<a class=\"art-port-cover post-thumbnail\" href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\">\n\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/logsmith.io\/wp-content\/uploads\/2025\/10\/data_pipe-1024x768.png\" class=\"attachment-arter_1280x768 size-arter_1280x768 wp-post-image\" alt=\"Case Study : Taming the 21,000-Alert-a-Day SIEM\" \/>\t\t<\/a>\n\t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\">\n\t\t\t\t<span class=\"art-el-date\">October 6, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Case Study<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\">\n\t      <h5 class=\"mb-15\">Case Study : Taming the 21,000-Alert-a-Day SIEM<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>How I helped restore clarity and control to a chaotic Splunk ES environment<\/p>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  \t\t<\/div>\n\t\t<!-- row end -->\n\n\t\t<\/div>\n\t\t<!-- container end -->\n\n\t\t\t\t<!-- container -->\n\t\t<div class=\"container-fluid\">\n\n\t\t<!-- row -->\n\t\t<div class=\"row\">\n\n\t\t  <!-- col -->\n\t\t  <div class=\"col-lg-12\">\n\n\t\t  \t\t\t    <!-- pagination -->\n\t\t    <div class=\"art-a art-pagination\">\n\t\t      \t<span aria-current=\"page\" class=\"page-numbers current\">1<\/span>\n<a class=\"page-numbers\" href=\"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166\/page\/2\/\">2<\/a>\n<a class=\"next page-numbers\" href=\"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166\/page\/2\/\">Next<\/a>\t\t    <\/div>\n\t\t    <!-- pagination end -->\n\t\t    \n\t\t    \t\t  <\/div>\n\t\t  <!-- col end -->\n\n\t\t<\/div>\n\t\t<!-- row end -->\n\n\t\t<\/div>\n\t\t<!-- container end -->\n\t\t\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Blog September 24, 2020 \/ Design, Events, Technology Follow your own design process. My job is simple and sophisticated, so&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-layout-builder.php","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"iawp_total_views":1,"footnotes":""},"class_list":["post-166","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/comments?post=166"}],"version-history":[{"count":0,"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166\/revisions"}],"wp:attachment":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/media?parent=166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}