<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the difference? (between Splunk Enterprise, ITSI, SOAR, UBA, and Enterprise Security) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-difference-between-Splunk-Enterprise-ITSI-SOAR-UBA/m-p/608317#M13537</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm just having a bit of difficulty differentiating between&amp;nbsp;Splunk Enterprise, ITSI, SOAR, UBA, and Enterprise Security. It seems like they all do similar things.&amp;nbsp; Do they all work together? or would it be redundant to have all of these at the same time?&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 17:25:53 GMT</pubDate>
    <dc:creator>thos13</dc:creator>
    <dc:date>2022-08-04T17:25:53Z</dc:date>
    <item>
      <title>What is the difference? (between Splunk Enterprise, ITSI, SOAR, UBA, and Enterprise Security)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-difference-between-Splunk-Enterprise-ITSI-SOAR-UBA/m-p/608317#M13537</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm just having a bit of difficulty differentiating between&amp;nbsp;Splunk Enterprise, ITSI, SOAR, UBA, and Enterprise Security. It seems like they all do similar things.&amp;nbsp; Do they all work together? or would it be redundant to have all of these at the same time?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 17:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-difference-between-Splunk-Enterprise-ITSI-SOAR-UBA/m-p/608317#M13537</guid>
      <dc:creator>thos13</dc:creator>
      <dc:date>2022-08-04T17:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference? (between Splunk Enterprise, ITSI, SOAR, UBA, and Enterprise Security)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-difference-between-Splunk-Enterprise-ITSI-SOAR-UBA/m-p/608332#M13538</link>
      <description>&lt;P&gt;It's a lot to digest and those are just a few of the products Splunk offers!&lt;/P&gt;&lt;P&gt;Splunk Enterprise is the core product most of us use when we use "Splunk".&amp;nbsp; It's the tool that indexes your machine data and helps you search it and draw value from it.&lt;/P&gt;&lt;P&gt;ITSI (IT Service Intelligence) is an app that plugs into Splunk Enterprise.&amp;nbsp; It helps companies monitor the services they offer and know when problems are about to occur.&amp;nbsp; Since it's a plug-in, you must first have Splunk Enterprise before you can install and run ITSI.&lt;/P&gt;&lt;P&gt;Splunk Enterprise Security (ES) is like ITSI in that it's an add-on to Splunk Enterprise.&amp;nbsp; This add-on is intended for a company's SOC (Security Operations Center) team and is often billed as a SIEM (Security Information and Event Management) tool.&amp;nbsp; It identifies security incidents as they happen so the SOC and take action to correct them.&amp;nbsp; ES includes features that allow SOC members to track the incidents they investigate and record their findings.&amp;nbsp; Because it's an add-on like ITSI, ES works very closely with Splunk Enterprise.&lt;/P&gt;&lt;P&gt;SOAR (Security Orchestration, Automation and Response; originally called Phantom) is an independent product.&amp;nbsp; SOAR allows a company to respond to events.&amp;nbsp; For example, if ES detects an authorized access, SOAR might be configured to tell the network to block that access.&amp;nbsp; Since SOAR is a separate product it does not require Splunk Enterprise, but the two can work together.&lt;/P&gt;&lt;P&gt;UBA (User Behavior Analytics) is another independent product.&amp;nbsp; It monitors activity on a network and alerts when it notices "unusual" activity.&amp;nbsp; An activity is considered "unusual" if it breaks the pattern UBA has noticed in the past (using machine learning).&amp;nbsp; It, too, can work with Splunk Enterprise, but does not require it.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 19:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-difference-between-Splunk-Enterprise-ITSI-SOAR-UBA/m-p/608332#M13538</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-04T19:06:02Z</dc:date>
    </item>
  </channel>
</rss>

