<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Security Essentials integration with Forcepoint app. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Security-Essentials-integration-with-Forcepoint-app/m-p/580458#M102406</link>
    <description>&lt;P&gt;Any time you find a Splunk document to be lacking, submit feedback on that docs page.&amp;nbsp; The Documentation team is great about updating docs in response to user feedback.&lt;/P&gt;&lt;P&gt;The message in the first screenshot indicates you do not have Splunk Enterprise Security installed.&amp;nbsp; To resolve it, buy and install ES.&lt;/P&gt;&lt;P&gt;The use cases in SSE are built using somewhat generic SPL, but should always be examined and updated before deploying it in a real environment.&amp;nbsp; For example, many use cases use "index=*", which should never be allowed in a Production system.&amp;nbsp; Also, some examples use products you may not have so you'll need to modify those examples to use data from your products.&lt;/P&gt;&lt;P&gt;The tags shown in the last screenshot come with the Splunk Common Information Model (CIM) app, IIRC.&lt;/P&gt;&lt;P&gt;IMO, the Splunk Security Essentials app should not be used as a SOC tool, but as a way to learn what you can do with Splunk to solve SOC use cases.&amp;nbsp; Use SSE to see what is possible using your data and what data you need to solve other use cases, but take those examples and implement them in your own app.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jan 2022 14:09:19 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-01-10T14:09:19Z</dc:date>
    <item>
      <title>Splunk Security Essentials integration with Forcepoint app.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Security-Essentials-integration-with-Forcepoint-app/m-p/580434#M102399</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been trying to get data in SSE, but somehow I can't. The setup is the following - Installed Splunk Enterprise, Universal Forwarder, Forecpoint app, Syslog-ng(for receiving the logs, which i monitor with the UF) and Splunk Security Essentials.&lt;/P&gt;&lt;P&gt;I've tried different things with the demo data but when I'm trying to do anything with the live data i hit the wall.&amp;nbsp; I've tried to follow &lt;A href="https://docs.splunk.com/Documentation/SSE/3.4.0/Install/ConfigureSSE" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SSE/3.4.0/Install/ConfigureSSE&lt;/A&gt; these instructions, but they seem unclear and somehow inaccurate(For example in the chapter for getting data in - &lt;STRONG&gt;Configure the products you have in your environment with the Data Inventory dashboard.&lt;/STRONG&gt; When I browse in the web interface there is no option to "2.b.Click &lt;STRONG&gt;Manually Configure&lt;/STRONG&gt; to manually enter your data.") .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first thing I've noticed was that this error for the ES Integration was thrown, for which i didn't find any information.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17481i65CDD6E8C4C9FACA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I open any use cases and for example "Basic Scanning", the sourcetype and index for forcepoint (index="forcepoint", sourcetype="next-generation-firewall") are missing by default. Are there any ways to add it automatically for all the use cases?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test123.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17486i50BD278765E219DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="test123.png" alt="test123.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've already have logs monitored by the indexer forwarded by the Forcepoint which are displayed in the Splunk Search and Reporting and Forcepoint App.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test124.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17484iFAD2B568FAEDA0DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="test124.png" alt="test124.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even if i change the index and sourcetype in the enter a search field I still get these results. Can you give me any info on the tags, like what are they and what are they used for?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17488iD98CD5ACFDBFF8A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guides or tips will be highly appreciated, thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 10:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Security-Essentials-integration-with-Forcepoint-app/m-p/580434#M102399</guid>
      <dc:creator>vaveryanov</dc:creator>
      <dc:date>2022-01-10T10:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Security Essentials integration with Forcepoint app.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Security-Essentials-integration-with-Forcepoint-app/m-p/580458#M102406</link>
      <description>&lt;P&gt;Any time you find a Splunk document to be lacking, submit feedback on that docs page.&amp;nbsp; The Documentation team is great about updating docs in response to user feedback.&lt;/P&gt;&lt;P&gt;The message in the first screenshot indicates you do not have Splunk Enterprise Security installed.&amp;nbsp; To resolve it, buy and install ES.&lt;/P&gt;&lt;P&gt;The use cases in SSE are built using somewhat generic SPL, but should always be examined and updated before deploying it in a real environment.&amp;nbsp; For example, many use cases use "index=*", which should never be allowed in a Production system.&amp;nbsp; Also, some examples use products you may not have so you'll need to modify those examples to use data from your products.&lt;/P&gt;&lt;P&gt;The tags shown in the last screenshot come with the Splunk Common Information Model (CIM) app, IIRC.&lt;/P&gt;&lt;P&gt;IMO, the Splunk Security Essentials app should not be used as a SOC tool, but as a way to learn what you can do with Splunk to solve SOC use cases.&amp;nbsp; Use SSE to see what is possible using your data and what data you need to solve other use cases, but take those examples and implement them in your own app.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 14:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Security-Essentials-integration-with-Forcepoint-app/m-p/580458#M102406</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-10T14:09:19Z</dc:date>
    </item>
  </channel>
</rss>

