<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk SIEM license in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556129#M12336</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235516"&gt;@Nikolozts&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I use Windows only on my pc for test, never for production systems.&lt;/P&gt;&lt;P&gt;About requirements, you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/6.5.1/Install/DeploymentPlanning" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.5.1/Install/DeploymentPlanning&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But Anyway, I continue to hint to call a Splunk Partner for the Demo, otherwise you risk to not correctly evaluate ES, if you don't know anyone, contact me with a private message.&lt;/P&gt;&lt;P&gt;In addition, using a demo environment, you already have many log sources to see how ES works, in your lab, you have to ingest logs before to start to install ES and, if you haven't experience on Splunk, it could be a long job.&lt;/P&gt;&lt;P&gt;You have to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;prepare Server,&lt;/LI&gt;&lt;LI&gt;install Splunk Enterprise,&lt;/LI&gt;&lt;LI&gt;install Universal Forwarder (Splunk Agent) on servers,&lt;/LI&gt;&lt;LI&gt;open firewall routes,&lt;/LI&gt;&lt;LI&gt;configure them,&lt;/LI&gt;&lt;LI&gt;configure syslogs from appliances,&lt;/LI&gt;&lt;LI&gt;install and configure Technical Add-Ons on Splunk Enterprise,&lt;/LI&gt;&lt;LI&gt;install Splunk ES and its modules,&lt;/LI&gt;&lt;LI&gt;configure it,&lt;/LI&gt;&lt;LI&gt;activate Data Models and Correlation Searches.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;An expert could do the work in few days (except firewall routes, agents and syslogs), if you aren't an expert it surely will be a longer work.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 07:32:38 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-06-17T07:32:38Z</dc:date>
    <item>
      <title>Splunk SIEM license</title>
      <link>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556100#M12330</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have PoC.&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;I wonder where I could find the documentation and videos about installation, administration, system requirements and licensing of Splunk SIEM. I have no experience in installing or configuration it. I interesing in how to work splunk siem? How collect logs and events? How it is licensed? I searched some information and see 30gb/day I confused this is all events and log size daily?&amp;nbsp;I am ready to receive all information and recommendations about splunk SIEM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 06:04:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556100#M12330</guid>
      <dc:creator>Nikolozts</dc:creator>
      <dc:date>2021-06-17T06:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SIEM license</title>
      <link>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556104#M12331</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235516"&gt;@Nikolozts&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I can confirm, from my experience, that Splunk Enterprise Security (the Splunk SIEM) is one of the best SIEM on the market, and Gartner confirm my idea.&lt;/P&gt;&lt;P&gt;Installation isn't so immediate, because you have to install Splunk Enterprise (easy!) and then Splunk ES with all its modules, then you have to configure it .&lt;/P&gt;&lt;P&gt;I hint to ask to a Splunk partner (if you are in Italy or near I can propose myself) to make a demo ti you and then open a demo environment on Splunk Cloud.&lt;/P&gt;&lt;P&gt;Anyway, on youtube you can find some videos about this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=KoIY-_2ItSc&amp;amp;pp=ugMICgJpdBABGAE%3D" target="_blank"&gt;https://www.youtube.com/watch?v=KoIY-_2ItSc&amp;amp;pp=ugMICgJpdBABGAE%3D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=IA2QwdpCm74&amp;amp;pp=ugMICgJpdBABGAE%3D" target="_blank"&gt;https://www.youtube.com/watch?v=IA2QwdpCm74&amp;amp;pp=ugMICgJpdBABGAE%3D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=9D00ysP5Hbg&amp;amp;t=646s" target="_blank"&gt;https://www.youtube.com/watch?v=9D00ysP5Hbg&amp;amp;t=646s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=HN4zGIyi3PI" target="_blank"&gt;https://www.youtube.com/watch?v=HN4zGIyi3PI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=h2_MiD9OC_8&amp;amp;list=PLxkFdMSHYh3Qx3Ct9ZzeL7accYO2rE_ZB" target="_blank"&gt;https://www.youtube.com/watch?v=h2_MiD9OC_8&amp;amp;list=PLxkFdMSHYh3Qx3Ct9ZzeL7accYO2rE_ZB&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=M1JXeQTiQBQ&amp;amp;pp=ugMICgJpdBABGAE%3D" target="_blank"&gt;https://www.youtube.com/watch?v=M1JXeQTiQBQ&amp;amp;pp=ugMICgJpdBABGAE%3D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;About your questions:&lt;/P&gt;&lt;P&gt;Splunk Enterprise collect every kind of logs,&lt;/P&gt;&lt;P&gt;using some own modules (called Technical Add-Ons) parse these logs and normalize them in CIM format,&lt;/P&gt;&lt;P&gt;Splunk ES takes these logs, correlate and use them into some Use Cases,&lt;/P&gt;&lt;P&gt;there are around 300 Use Cases already ready, then you can create your own Use Cases.&lt;/P&gt;&lt;P&gt;Both Splunk Enterprise and Splunk ES are licensed based on the logs daily indexed, you have to buy both a license for Splunk Enterprise and Splunk ES,&lt;/P&gt;&lt;P&gt;The volume of daily indexed logs depends on the perimeter to monitor: how many servers, firewalls, proxies, is there packet capure, are there application logs, etc...?&lt;/P&gt;&lt;P&gt;Here you can find all the information about ES:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/6.5.1/User/Overview" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.5.1/User/Overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 06:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556104#M12331</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-17T06:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SIEM license</title>
      <link>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556105#M12332</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;If you have limited time and resources for this PoC, I propose that contact to your nearest Splunk Partner and ask that they could help you with it. I suppose that this will be the most cost efficient way to do it.&lt;/P&gt;&lt;P&gt;&lt;A href="https://partners.splunk.com/locator/" target="_blank"&gt;https://partners.splunk.com/locator/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 06:25:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556105#M12332</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-17T06:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SIEM license</title>
      <link>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556125#M12335</link>
      <description>&lt;P&gt;Thank you very much for the quick reply. I will look carefully at the links provided by you. What are the minimum&amp;nbsp;system recommended requirements and your experience which one is the best operating system for Splunk SIEM? Of course I think about installing it on Linux but which is the fully supported system?&amp;nbsp;Are there any restrictions on Windows system?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 07:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556125#M12335</guid>
      <dc:creator>Nikolozts</dc:creator>
      <dc:date>2021-06-17T07:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SIEM license</title>
      <link>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556129#M12336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235516"&gt;@Nikolozts&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I use Windows only on my pc for test, never for production systems.&lt;/P&gt;&lt;P&gt;About requirements, you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/6.5.1/Install/DeploymentPlanning" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.5.1/Install/DeploymentPlanning&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But Anyway, I continue to hint to call a Splunk Partner for the Demo, otherwise you risk to not correctly evaluate ES, if you don't know anyone, contact me with a private message.&lt;/P&gt;&lt;P&gt;In addition, using a demo environment, you already have many log sources to see how ES works, in your lab, you have to ingest logs before to start to install ES and, if you haven't experience on Splunk, it could be a long job.&lt;/P&gt;&lt;P&gt;You have to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;prepare Server,&lt;/LI&gt;&lt;LI&gt;install Splunk Enterprise,&lt;/LI&gt;&lt;LI&gt;install Universal Forwarder (Splunk Agent) on servers,&lt;/LI&gt;&lt;LI&gt;open firewall routes,&lt;/LI&gt;&lt;LI&gt;configure them,&lt;/LI&gt;&lt;LI&gt;configure syslogs from appliances,&lt;/LI&gt;&lt;LI&gt;install and configure Technical Add-Ons on Splunk Enterprise,&lt;/LI&gt;&lt;LI&gt;install Splunk ES and its modules,&lt;/LI&gt;&lt;LI&gt;configure it,&lt;/LI&gt;&lt;LI&gt;activate Data Models and Correlation Searches.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;An expert could do the work in few days (except firewall routes, agents and syslogs), if you aren't an expert it surely will be a longer work.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 07:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-SIEM-license/m-p/556129#M12336</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-17T07:32:38Z</dc:date>
    </item>
  </channel>
</rss>

