Resources / Security Field Guides

Security field guides. Tested end to end.

Each guide takes one pair of security tools and answers the question people actually ask about it: does the data really get from one to the other, what silently goes missing, and how long before you can trust it.

Guide 01

CrowdStrike Falcon to Splunk

What the CrowdStrike Falcon Event Streams add-on for Splunk actually does, what it will not do, and the two configuration facts that cause most silent data loss.

Time to trust
A weekFrom purchase to a feed you actually trust.
Read the guide
Guide 02

Okta to Jira Cloud

Whether deactivating someone in Okta really removes their Jira access, what SCIM provisioning to an Atlassian organization covers, and the license you have to buy first.

Time to trust
Two daysSCIM provisioning into the Atlassian organization, working.
Read the guide
Guide 03

Okta to Splunk

Two documented ways to get the Okta System Log into Splunk, what each one silently fails to deliver, and why most people end up running both.

Time to trust
An hourStanding up the push path on Splunk Cloud.
Read the guide
Guide 04

Splunk to Jira Cloud

Why a Splunk alert cannot create a Jira ticket on its own, what it actually takes, and the three rate limits waiting on the other end.

Time to trust
A quarterHow long until ticket volume is something an analyst can live with.
Read the guide

The guides are published on ingleby.com, where each one carries the date it was last verified and the evidence behind its verdict. Every link above opens the live guide.