{"id":12771,"date":"2019-04-08T15:08:20","date_gmt":"2019-04-08T19:08:20","guid":{"rendered":"http:\/\/www.iri.com\/blog\/?p=12771"},"modified":"2019-07-23T18:58:08","modified_gmt":"2019-07-23T22:58:08","slug":"darkshield-alerts-from-splunk","status":"publish","type":"post","link":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/","title":{"rendered":"Getting DarkShield Alerts from Splunk Adaptive Response"},"content":{"rendered":"<p class=\"c0\"><span class=\"c9\">The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data. This is done by creating an alert that triggers when a certain search result condition is received in the Splunk ES Search and Reporting app.<\/span><\/p>\n<p class=\"c0\"><span class=\"c10\"><a class=\"c12\" href=\"https:\/\/www.iri.com\/products\/darkshield\">IRI DarkShield<\/a><\/span><span class=\"c16\">\u00a0<\/span><span class=\"c3\">is a machine-learning-enabled data discovery and masking package for finding and securing personally identifiable information (PII) in dark data (unstructured) files \u2014 like email repositories, .pdf and Microsoft documents, and many image formats. DarkShield produces a high volume and quality of log file results from its PII search and mask operations.<\/span><\/p>\n<p class=\"c0\"><span class=\"c3\">By virtue of these logs, DarkShield can identify files which files it protected, versus ones that still have unmasked PII within them. You can <a href=\"https:\/\/www.iri.com\/blog\/business-intelligence\/forward-voracity-data-into-splunk\/\">automatically forward<\/a> the logs to Splunk ES, where you can highlight key information in <a href=\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-splunk-es\/\">dashboards,<\/a>\u00a0and configure alerts based on\u00a0 specific conditions; when, for example, DarkShield found more than 3 unprotected files.<\/span><\/p>\n<p class=\"c0\"><span class=\"c3\">This image shows some of the alert actions that can be triggered to respond to certain conditions. These include creating Splunk messages, sending email, logging the event, and running a script.<\/span><\/p>\n<p class=\"c0\"><a href=\"http:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/Splunk-Alert-Actions.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-12779 aligncenter\" src=\"\/blog\/wp-content\/uploads\/2019\/04\/Splunk-Alert-Actions-1024x518.png\" alt=\"\" width=\"904\" height=\"457\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/Splunk-Alert-Actions-1024x518.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/Splunk-Alert-Actions-300x152.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/Splunk-Alert-Actions-768x389.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/Splunk-Alert-Actions.png 1600w\" sizes=\"(max-width: 904px) 100vw, 904px\" \/><\/a><\/p>\n<p class=\"c0\"><span class=\"c3\">To set up an alert, first go to \u201csearch\u201d from the Splunk ES menu. Set the source you want to have alerts triggered from, then select the search button.<\/span><\/p>\n<p class=\"c0\"><span class=\"c3\">Once the search is complete, an alert condition can be generated by clicking on \u201cAlert\u201d from the \u201cSave As\u201d menu. In the picture below, my source is log.txt.<\/span><\/p>\n<p><a href=\"http:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/log.png\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-12780 aligncenter\" src=\"\/blog\/wp-content\/uploads\/2019\/04\/log-1024x555.png\" alt=\"\" width=\"903\" height=\"490\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/log-1024x555.png 1024w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/log-300x163.png 300w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/log-768x416.png 768w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/log.png 1600w\" sizes=\"(max-width: 903px) 100vw, 903px\" \/><\/a><\/p>\n<p>Once clicking on \u201cAlert\u201d a screen should appear like this that allows you to configure the conditions that trigger the alert, and what actions the alert takes.<\/p>\n<p><a href=\"\/blog\/wp-content\/uploads\/2019\/04\/save-as-1-V2.png\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-12782 aligncenter\" src=\"\/blog\/wp-content\/uploads\/2019\/04\/save-as-1-V2.png\" alt=\"\" width=\"569\" height=\"612\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-1-V2.png 678w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-1-V2-279x300.png 279w\" sizes=\"(max-width: 569px) 100vw, 569px\" \/><\/a><\/p>\n<p class=\"c0\"><span class=\"c3\">In this case, I have the configuration set up to check every 30 minutes (based on a Cron Schedule) if there are more than 3 unmasked files from DarkShield data. The alert then triggers each time there is a file type with more than 3 unmasked files. For example, if there are 5 unmasked PDF files, 6 unmasked .doc files, and 2 unmasked XML files, the alert will be triggered twice.<\/span><\/p>\n<p class=\"c0\"><span class=\"c6\">I set the alert to send an email with information about the alert, a link to the alert, the alert trigger condition and time, search condition. I also specified that both a\u00a0<\/span><span class=\"c6\">PDF and CSV file<\/span><span class=\"c3\">\u00a0containing a table of the particular data that triggered the alert would attach. Below you can see I also set the alert to be added to the list of high severity alerts:<\/span><\/p>\n<p><a href=\"\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12784\" src=\"\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\" alt=\"\" width=\"563\" height=\"610\" srcset=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png 677w, https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2-277x300.png 277w\" sizes=\"(max-width: 563px) 100vw, 563px\" \/><\/a><\/p>\n<p class=\"c0\"><span class=\"c3\">Once the DarkShield user receives the email, they can respond to it by configuring, modifying, or re-running an existing DarkShield masking operation.<\/span><\/p>\n<p class=\"c0\"><span class=\"c3\">Splunk can also launch custom scripts when an alert is fired. IRI is developing deeper integration points for DarkShield and its other masking tools in order to support automatic remediation through this and similar mechanisms.<\/span><\/p>\n<p><span class=\"c6\">Meanwhile, marrying the log data from IRI Data Protector\u00a0<\/span><span class=\"c10 c15\"><a class=\"c12\" href=\"https:\/\/www.iri.com\/products\/iri-data-protector\">suite tools<\/a><\/span><span class=\"c3\">\u00a0with the alert and response actions available in SIEM tools like Splunk ES can still improve the security of your data by shortening response times to those incidents you specify as needing remediation.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data. This is done by creating an alert that triggers when a certain search result condition is received in the Splunk ES Search and Reporting app. IRI DarkShield\u00a0is a machine-learning-enabled data discovery and masking package<\/p>\n<div><a class=\"btn-filled btn\" href=\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\" title=\"Getting DarkShield Alerts from Splunk Adaptive Response\">Read More<\/a><\/div>\n","protected":false},"author":119,"featured_media":12784,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[8],"tags":[1386,1405,14,1388,149,1404,574,1385],"class_list":["post-12771","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection","tag-darkshield","tag-data-alert","tag-data-masking","tag-iri-darkshield","tag-pii","tag-security-alert","tag-splunk","tag-splunk-es"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.4 (Yoast SEO v23.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Getting DarkShield Alerts from Splunk Adaptive Response - IRI<\/title>\n<meta name=\"description\" content=\"The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Getting DarkShield Alerts from Splunk Adaptive Response\" \/>\n<meta property=\"og:description\" content=\"The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\" \/>\n<meta property=\"og:site_name\" content=\"IRI\" \/>\n<meta property=\"article:published_time\" content=\"2019-04-08T19:08:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-23T22:58:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"677\" \/>\n\t<meta property=\"og:image:height\" content=\"734\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Devon Kozenieski\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Devon Kozenieski\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\"},\"author\":{\"name\":\"Devon Kozenieski\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/person\/de972c035aaeecfc40a3ae2ea5ff7ba1\"},\"headline\":\"Getting DarkShield Alerts from Splunk Adaptive Response\",\"datePublished\":\"2019-04-08T19:08:20+00:00\",\"dateModified\":\"2019-07-23T22:58:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\"},\"wordCount\":510,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\",\"keywords\":[\"DarkShield\",\"data alert\",\"data masking\",\"IRI DarkShield\",\"PII\",\"security alert\",\"Splunk\",\"Splunk ES\"],\"articleSection\":[\"Data Masking\/Protection\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\",\"url\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\",\"name\":\"Getting DarkShield Alerts from Splunk Adaptive Response - IRI\",\"isPartOf\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\",\"datePublished\":\"2019-04-08T19:08:20+00:00\",\"dateModified\":\"2019-07-23T22:58:08+00:00\",\"description\":\"The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage\",\"url\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\",\"contentUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png\",\"width\":677,\"height\":734,\"caption\":\"More save as options\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.iri.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Getting DarkShield Alerts from Splunk Adaptive Response\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.iri.com\/blog\/#website\",\"url\":\"https:\/\/www.iri.com\/blog\/\",\"name\":\"IRI\",\"description\":\"Total Data Management Blog\",\"publisher\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.iri.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.iri.com\/blog\/#organization\",\"name\":\"IRI\",\"url\":\"https:\/\/www.iri.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png\",\"contentUrl\":\"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png\",\"width\":750,\"height\":206,\"caption\":\"IRI\"},\"image\":{\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/person\/de972c035aaeecfc40a3ae2ea5ff7ba1\",\"name\":\"Devon Kozenieski\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iri.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e4c421588c1a85dd9a76146fe15528f7?s=96&d=blank&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e4c421588c1a85dd9a76146fe15528f7?s=96&d=blank&r=g\",\"caption\":\"Devon Kozenieski\"},\"url\":\"https:\/\/www.iri.com\/blog\/author\/devonk\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Getting DarkShield Alerts from Splunk Adaptive Response - IRI","description":"The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/","og_locale":"en_US","og_type":"article","og_title":"Getting DarkShield Alerts from Splunk Adaptive Response","og_description":"The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data.","og_url":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/","og_site_name":"IRI","article_published_time":"2019-04-08T19:08:20+00:00","article_modified_time":"2019-07-23T22:58:08+00:00","og_image":[{"width":677,"height":734,"url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png","type":"image\/png"}],"author":"Devon Kozenieski","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Devon Kozenieski","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#article","isPartOf":{"@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/"},"author":{"name":"Devon Kozenieski","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/person\/de972c035aaeecfc40a3ae2ea5ff7ba1"},"headline":"Getting DarkShield Alerts from Splunk Adaptive Response","datePublished":"2019-04-08T19:08:20+00:00","dateModified":"2019-07-23T22:58:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/"},"wordCount":510,"commentCount":1,"publisher":{"@id":"https:\/\/www.iri.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png","keywords":["DarkShield","data alert","data masking","IRI DarkShield","PII","security alert","Splunk","Splunk ES"],"articleSection":["Data Masking\/Protection"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/","url":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/","name":"Getting DarkShield Alerts from Splunk Adaptive Response - IRI","isPartOf":{"@id":"https:\/\/www.iri.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage"},"image":{"@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png","datePublished":"2019-04-08T19:08:20+00:00","dateModified":"2019-07-23T22:58:08+00:00","description":"The Splunk Adaptive Response Framework (ARF) included with Splunk Enterprise Security (ES) allows actions to be taken in response to data.","breadcrumb":{"@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#primaryimage","url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png","contentUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png","width":677,"height":734,"caption":"More save as options"},{"@type":"BreadcrumbList","@id":"https:\/\/www.iri.com\/blog\/data-protection\/darkshield-alerts-from-splunk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.iri.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Getting DarkShield Alerts from Splunk Adaptive Response"}]},{"@type":"WebSite","@id":"https:\/\/www.iri.com\/blog\/#website","url":"https:\/\/www.iri.com\/blog\/","name":"IRI","description":"Total Data Management Blog","publisher":{"@id":"https:\/\/www.iri.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.iri.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.iri.com\/blog\/#organization","name":"IRI","url":"https:\/\/www.iri.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png","contentUrl":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/02\/iri-logo-total-data-management-small-1.png","width":750,"height":206,"caption":"IRI"},"image":{"@id":"https:\/\/www.iri.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/person\/de972c035aaeecfc40a3ae2ea5ff7ba1","name":"Devon Kozenieski","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iri.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e4c421588c1a85dd9a76146fe15528f7?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e4c421588c1a85dd9a76146fe15528f7?s=96&d=blank&r=g","caption":"Devon Kozenieski"},"url":"https:\/\/www.iri.com\/blog\/author\/devonk\/"}]}},"jetpack_featured_media_url":"https:\/\/www.iri.com\/blog\/wp-content\/uploads\/2019\/04\/save-as-2-V2.png","_links":{"self":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts\/12771"}],"collection":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/users\/119"}],"replies":[{"embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/comments?post=12771"}],"version-history":[{"count":7,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts\/12771\/revisions"}],"predecessor-version":[{"id":13019,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/posts\/12771\/revisions\/13019"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/media\/12784"}],"wp:attachment":[{"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/media?parent=12771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/categories?post=12771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.iri.com\/blog\/wp-json\/wp\/v2\/tags?post=12771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}