Urgent.News

What's breaking now, across thousands of outlets.

AI

I let a local 27B LLM audit and fix my Splunk + Sysmon stack

I let a local 27B LLM audit and fix my Splunk + Sysmon stack The question was not "can an LLM do SOC work". The question I actually wanted answered was narrower and harder: can a 27B model running on my own GPU, with zero bytes leaving the machine, audit my Splunk install, find what is broken and fix it — without me telling it how? After an afternoon of back and forth, the answer is yes, with…

A security analyst without prior SOC experience tested a 27B Local Language Model (LLM) to audit and fix their Splunk + Sysmon stack. The LLM, running on a single 16GB GPU, was tasked with reviewing the Splunk configuration, data pipeline, logging hardening, 24-hour log analysis, and IoC detection without any external data or infrastructure.

After five audited tests, the model demonstrated an ability to reason like a senior analyst, correcting wrong assumptions, debugging issues, and confirming findings rather than inventing answers. However, the model's thoroughness sometimes led to failure modes, such as getting stuck on irrelevant information or encountering context limitations.

Key findings included double ingestion, missing data inputs, language-specific configuration errors, and incorrect Sysmon event-ID mappings. The LLM also caught its own false positives during the audit process. To make the model deterministic, the analyst adjusted temperature settings and provided a new system prompt for remediation tasks.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

Global Workspace Theory The J-Space of Claude

What a 40-year-old theory of human consciousness has to do with catching an AI model lying. Okay, so here's the thing that made me stop scrolling Before Claude Sonnet 4.5 wrote a single word of its…

  • Anthropic discovered Claude's internal "J-space" aligning with consciousness theory.
  • J-space reveals potential AI output concepts, aiding ethical AI monitoring.

More from Thursday 17 September →