<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Security Essentials onboard data/use case creation in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/524029#M11877</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are trying to get data on boarded to splunk security essentials. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We do not have a clear visibility to the functioning of the app, I have now onboarded DNS data onto my Splunk Indexer using the Splunk Stream app, Its in the index=netdns as per splunk docs specification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now how do I turn on all the use cases related to DNS in splunk security essentials.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Followed the onboarding guide which provided in the app.(&lt;A href="https://docs.splunksecurityessentials.com/data-onboarding-guides/stream-dns/)" target="_blank" rel="noopener"&gt;https://docs.splunksecurityessentials.com/data-onboarding-guides/stream-dns/)&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 10 Oct 2020 15:08:31 GMT</pubDate>
    <dc:creator>vinothn</dc:creator>
    <dc:date>2020-10-10T15:08:31Z</dc:date>
    <item>
      <title>Splunk Security Essentials onboard data/use case creation</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/524029#M11877</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are trying to get data on boarded to splunk security essentials. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We do not have a clear visibility to the functioning of the app, I have now onboarded DNS data onto my Splunk Indexer using the Splunk Stream app, Its in the index=netdns as per splunk docs specification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now how do I turn on all the use cases related to DNS in splunk security essentials.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Followed the onboarding guide which provided in the app.(&lt;A href="https://docs.splunksecurityessentials.com/data-onboarding-guides/stream-dns/)" target="_blank" rel="noopener"&gt;https://docs.splunksecurityessentials.com/data-onboarding-guides/stream-dns/)&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 15:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/524029#M11877</guid>
      <dc:creator>vinothn</dc:creator>
      <dc:date>2020-10-10T15:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Security Essentials onboard data/use case creation</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/524030#M11878</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I too have the same issue, The documents are not clear enough as how we have to activate the use cases in the splunk security essentials app. Please could someone shed some light on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 15:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/524030#M11878</guid>
      <dc:creator>johnsasikumar</dc:creator>
      <dc:date>2020-10-10T15:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Security Essentials onboard data/use case creation</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/525398#M11893</link>
      <description>&lt;P&gt;There's a walkthrough here for how you can track content and data in your Splunk environment and how to operationalize it using different features in the Analytics Advisor section: &lt;A href="https://docs.splunksecurityessentials.com/user/productionalize/operationalize_mitre_attack/" target="_blank"&gt;https://docs.splunksecurityessentials.com/user/productionalize/operationalize_mitre_attack/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 15:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Security-Essentials-onboard-data-use-case-creation/m-p/525398#M11893</guid>
      <dc:creator>niroy_splunk</dc:creator>
      <dc:date>2020-10-19T15:36:28Z</dc:date>
    </item>
  </channel>
</rss>

