<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking to adopt splunk as SIEM tool for my company in Feedback</title>
    <link>https://community.splunk.com/t5/Feedback/Looking-to-adopt-splunk-as-SIEM-tool-for-my-company/m-p/686544#M321</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This is very high level, I would suggest you really need a workshop with Splunk/Sales/Architect/pre-sales for this, but here's some Splunk food for thought &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;I am looking to use splunk as a SIEM tool for my company. Let me brief about our IT infra.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Splunk ES (SIEM) is most likely what you’re looking for, note, this a premium application, so additional licence. ES is mainly for SOC's use, it has many of the functions they need, and provides visibility for your security events, intelligence, and stats and then some!&lt;/P&gt;&lt;P&gt;&amp;nbsp;The other alternative is Splunk's free InfoSec App(this not a SIEM in the sense, but it can also provide some good visibility into security aspects)&lt;/P&gt;&lt;P&gt;&amp;nbsp;These links will help you find out more information.&lt;/P&gt;&lt;P&gt;Splunk ES&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/products/enterprise-security.html" target="_blank"&gt;https://www.splunk.com/en_us/products/enterprise-security.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Splunk ES SIEM App&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/263" target="_blank"&gt;https://splunkbase.splunk.com/app/263&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Splunk Info Sec App&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4240" target="_blank"&gt;https://splunkbase.splunk.com/app/4240&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Splunk Use Case Library&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3435" target="_blank"&gt;https://splunkbase.splunk.com/app/3435&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;1) We use Azure , AWS &amp;amp; some on premise servers. Most of our resources like VMs and services are on Azure&lt;/U&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk supports many common data sources, so the ones you have listed will be fine, the data will need to be onboarded correctly for ES SIEM to search the data. Use Splunk base to find the various data source add-ons that Splunk supports &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunkbase.splunk.com/" target="_blank"&gt;https://splunkbase.splunk.com/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;2) Want a security kind of dashboard where SOC team can view and report on threats of network, web, servers etc.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This will show you various dashboards ES provides &lt;A href="https://docs.splunk.com/Documentation/ES/7.3.1/User/Domaindashboards" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.3.1/User/Domaindashboards&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;3) I am not sure on the products that offers by splunk which is most relevant to me.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;What products are most relevant to you? well this depends on your use cases, and how your SOC operates, I would suggest you contact Splunk and run perhaps a workshop to discovery your business requirements. There are many apps, Splunk ES, Mission Control, UBA, Soar. For you it sounds like ES, due to complexity ,integrations business requirements, a workshop would be better for you to thrash out all the details and have a strategy. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;4) I am definitely want to go with cloud based solution instead of setting up splunk on virtual machine.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk cloud removes admin overheads for the management of Splunk local instances, you just manage the data forwarding tier and feed that into Splunk cloud, so depends on for business strategy On premise -Vs Cloud. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;I am not sure if splunk has cloud based colsole or not.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Splunk cloud, login is known as a search head, this provides you with various apps like ES and various other Splunk features. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;5) Please help me with some best industry practices to deploy splunk. Also, share the way steps, guide, video to deploy the same.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Start here &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk basic concepts &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.splunk.com/en_us/blog/learn/splunk-tutorials.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/learn/splunk-tutorials.html&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;When deploying Splunk, it's important to follow best practices to ensure a successful implementation. Some key steps include:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Define your use cases and objectives for using Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Plan your data collection strategy, including identifying sources of data to ingest into Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Design your Splunk environment, considering factors such as data volume, retention requirements, and performance needs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Install and configure Splunk components according to your design, ensuring proper integration with your IT infrastructure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Test your deployment to verify functionality and performance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Train your users and administrators on how to use Splunk effectively for monitoring, analysis, and reporting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Continuously monitor and optimize your Splunk deployment to meet evolving business needs and security requirements.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;For detailed guidance on deploying Splunk, you can refer to Splunk documentation, online resources, and training courses available from Splunk. Additionally, Splunk's professional services team can provide expert assistance with deployment planning, implementation, and optimization.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 09:57:16 GMT</pubDate>
    <dc:creator>deepakc</dc:creator>
    <dc:date>2024-05-06T09:57:16Z</dc:date>
    <item>
      <title>Looking to adopt splunk as SIEM tool for my company</title>
      <link>https://community.splunk.com/t5/Feedback/Looking-to-adopt-splunk-as-SIEM-tool-for-my-company/m-p/686453#M320</link>
      <description>&lt;P&gt;Hello&amp;nbsp; community members,&lt;/P&gt;&lt;P&gt;I am looking to use splunk as a SIEM tool for my company. Let me brief about our IT infra.&lt;/P&gt;&lt;P&gt;1) We use Azure , AWS &amp;amp; some onpremise servers. Most of our resources like VMs and services are on Azure.&lt;/P&gt;&lt;P&gt;2) Want a security kind of dashboard where SOC team can view and report on threats of network, web, servers etc.&lt;/P&gt;&lt;P&gt;3) I am not sure on the products that offers by splunk which is most relevant to me.&lt;/P&gt;&lt;P&gt;4) I am definitely want to go with cloud based solution instead of setting up splunk on virtual machine.&lt;/P&gt;&lt;P&gt;I am not sure if splunk has cloud based colsole or not.&lt;/P&gt;&lt;P&gt;5) Please help me with some best industry practices to deploy splunk. Also, share the way steps, guide, video to deploy the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6) Is there any way I can setup a zoom(online) meeting call with splunk to understand product. On support page of splunk page I did not find any option to request for product understanding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;looking to get community support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2024 21:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Looking-to-adopt-splunk-as-SIEM-tool-for-my-company/m-p/686453#M320</guid>
      <dc:creator>cloudinfra</dc:creator>
      <dc:date>2024-05-05T21:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Looking to adopt splunk as SIEM tool for my company</title>
      <link>https://community.splunk.com/t5/Feedback/Looking-to-adopt-splunk-as-SIEM-tool-for-my-company/m-p/686544#M321</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This is very high level, I would suggest you really need a workshop with Splunk/Sales/Architect/pre-sales for this, but here's some Splunk food for thought &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;I am looking to use splunk as a SIEM tool for my company. Let me brief about our IT infra.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Splunk ES (SIEM) is most likely what you’re looking for, note, this a premium application, so additional licence. ES is mainly for SOC's use, it has many of the functions they need, and provides visibility for your security events, intelligence, and stats and then some!&lt;/P&gt;&lt;P&gt;&amp;nbsp;The other alternative is Splunk's free InfoSec App(this not a SIEM in the sense, but it can also provide some good visibility into security aspects)&lt;/P&gt;&lt;P&gt;&amp;nbsp;These links will help you find out more information.&lt;/P&gt;&lt;P&gt;Splunk ES&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/products/enterprise-security.html" target="_blank"&gt;https://www.splunk.com/en_us/products/enterprise-security.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Splunk ES SIEM App&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/263" target="_blank"&gt;https://splunkbase.splunk.com/app/263&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Splunk Info Sec App&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4240" target="_blank"&gt;https://splunkbase.splunk.com/app/4240&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Splunk Use Case Library&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3435" target="_blank"&gt;https://splunkbase.splunk.com/app/3435&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;1) We use Azure , AWS &amp;amp; some on premise servers. Most of our resources like VMs and services are on Azure&lt;/U&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk supports many common data sources, so the ones you have listed will be fine, the data will need to be onboarded correctly for ES SIEM to search the data. Use Splunk base to find the various data source add-ons that Splunk supports &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunkbase.splunk.com/" target="_blank"&gt;https://splunkbase.splunk.com/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;2) Want a security kind of dashboard where SOC team can view and report on threats of network, web, servers etc.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This will show you various dashboards ES provides &lt;A href="https://docs.splunk.com/Documentation/ES/7.3.1/User/Domaindashboards" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.3.1/User/Domaindashboards&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;3) I am not sure on the products that offers by splunk which is most relevant to me.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;What products are most relevant to you? well this depends on your use cases, and how your SOC operates, I would suggest you contact Splunk and run perhaps a workshop to discovery your business requirements. There are many apps, Splunk ES, Mission Control, UBA, Soar. For you it sounds like ES, due to complexity ,integrations business requirements, a workshop would be better for you to thrash out all the details and have a strategy. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;4) I am definitely want to go with cloud based solution instead of setting up splunk on virtual machine.&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk cloud removes admin overheads for the management of Splunk local instances, you just manage the data forwarding tier and feed that into Splunk cloud, so depends on for business strategy On premise -Vs Cloud. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;I am not sure if splunk has cloud based colsole or not.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Splunk cloud, login is known as a search head, this provides you with various apps like ES and various other Splunk features. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;5) Please help me with some best industry practices to deploy splunk. Also, share the way steps, guide, video to deploy the same.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Start here &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk basic concepts &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.splunk.com/en_us/blog/learn/splunk-tutorials.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/learn/splunk-tutorials.html&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;When deploying Splunk, it's important to follow best practices to ensure a successful implementation. Some key steps include:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Define your use cases and objectives for using Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Plan your data collection strategy, including identifying sources of data to ingest into Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Design your Splunk environment, considering factors such as data volume, retention requirements, and performance needs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Install and configure Splunk components according to your design, ensuring proper integration with your IT infrastructure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Test your deployment to verify functionality and performance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Train your users and administrators on how to use Splunk effectively for monitoring, analysis, and reporting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Continuously monitor and optimize your Splunk deployment to meet evolving business needs and security requirements.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;For detailed guidance on deploying Splunk, you can refer to Splunk documentation, online resources, and training courses available from Splunk. Additionally, Splunk's professional services team can provide expert assistance with deployment planning, implementation, and optimization.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 09:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Looking-to-adopt-splunk-as-SIEM-tool-for-my-company/m-p/686544#M321</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-05-06T09:57:16Z</dc:date>
    </item>
  </channel>
</rss>

