<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where is the documentation on how to use the Verizon Data Breach Investigations Report (DBIR) app for Splunk? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234524#M26362</link>
    <description>&lt;P&gt;Ok I installed the app, now what? I have some pretty pull down menus... what do you do next?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2015 13:07:46 GMT</pubDate>
    <dc:creator>mendesjo</dc:creator>
    <dc:date>2015-11-13T13:07:46Z</dc:date>
    <item>
      <title>Where is the documentation on how to use the Verizon Data Breach Investigations Report (DBIR) app for Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234524#M26362</link>
      <description>&lt;P&gt;Ok I installed the app, now what? I have some pretty pull down menus... what do you do next?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 13:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234524#M26362</guid>
      <dc:creator>mendesjo</dc:creator>
      <dc:date>2015-11-13T13:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation on how to use the Verizon Data Breach Investigations Report (DBIR) app for Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234525#M26363</link>
      <description>&lt;P&gt;Per &lt;A href="https://answers.splunk.com/users/138264/jkat54.html?utm_source=answers&amp;amp;utm_medium=email&amp;amp;utm_term=jkat54&amp;amp;utm_content=&amp;amp;utm_campaign=mention"&gt;jkat54&lt;/A&gt; on question &lt;A href="https://answers.splunk.com/answers/257867/"&gt;257867&lt;/A&gt;, please have a look at:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/apps/DBIR_splunk_app/appserver/static/html/dbir_help_basic.html&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Also, similar to Enterprise Security, the PCI app for Splunk, and ITSI, your data will need to be normalized to conform to the Common Information Model (CIM) to integrate with DBIR. More information on CIM can be found here: &lt;A href="http://docs.splunk.com/Documentation/CIM/4.3.1/User/Overview"&gt;Common Information Model Add-on Manual&lt;/A&gt;. &lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;CIM app&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 19:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234525#M26363</guid>
      <dc:creator>nnmiller</dc:creator>
      <dc:date>2015-11-13T19:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation on how to use the Verizon Data Breach Investigations Report (DBIR) app for Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234526#M26364</link>
      <description>&lt;P&gt;Thanks for the reply.  So,  does this app somehow coorelate existing data in my splunk environment with Verizon's data? How will it obtain the Verizon information, does it down load it somehow? &lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 20:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234526#M26364</guid>
      <dc:creator>mendesjo</dc:creator>
      <dc:date>2015-11-13T20:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation on how to use the Verizon Data Breach Investigations Report (DBIR) app for Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234527#M26365</link>
      <description>&lt;P&gt;Based on this &lt;A href="http://news.verizonenterprise.com/2015/09/verizon-splunk-dbir-app-security/"&gt;press release&lt;/A&gt;, and looking at the app, it appears using the DBIR historical data which is contained within the application itself.&lt;/P&gt;

&lt;P&gt;There are more HTML help files in that html directory I mentioned in my answer.&lt;/P&gt;

&lt;P&gt;If you are not familiar with CIM, then I strongly suggest you read the CIM documentation before going further with this app, since understanding how to normalize data (source typing, event types, tags), is essential.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 21:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-is-the-documentation-on-how-to-use-the-Verizon-Data-Breach/m-p/234527#M26365</guid>
      <dc:creator>nnmiller</dc:creator>
      <dc:date>2015-11-13T21:44:46Z</dc:date>
    </item>
  </channel>
</rss>

