<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs required for Splunk ES Content Update? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753918#M12693</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a breakdown of logs required for Splunk ES Content updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created my own list already but hoping there is some resource where it is updated regularly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Oct 2025 10:44:58 GMT</pubDate>
    <dc:creator>david_monaghan</dc:creator>
    <dc:date>2025-10-03T10:44:58Z</dc:date>
    <item>
      <title>Logs required for Splunk ES Content Update?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753918#M12693</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a breakdown of logs required for Splunk ES Content updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created my own list already but hoping there is some resource where it is updated regularly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 10:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753918#M12693</guid>
      <dc:creator>david_monaghan</dc:creator>
      <dc:date>2025-10-03T10:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Logs required for Splunk ES Content Update?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753934#M12694</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Not sure I understand your questions correctly...&lt;/P&gt;&lt;P&gt;If you are looking for the location where the updates are stored this page can help&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/security-content-update/how-to-use-splunk-security-content/5.15/use-splunk-security-content/escu-components" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise-security-8/security-content-update/how-to-use-splunk-security-content/5.15/use-splunk-security-content/escu-components&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are looking for what kind of logs you need to feed a correlation search check the search itself, see which &amp;nbsp;data model, tags , and or eventtypes it uses and normalise the data/logs using the CIM&amp;nbsp;&lt;A href="https://help.splunk.com/en/data-management/common-information-model/6.1/using-the-common-information-model/use-the-cim-to-normalize-data-at-search-time" target="_blank"&gt;https://help.splunk.com/en/data-management/common-information-model/6.1/using-the-common-information-model/use-the-cim-to-normalize-data-at-search-time&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps ...&lt;/P&gt;&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 20:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753934#M12694</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2025-10-03T20:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logs required for Splunk ES Content Update?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753956#M12695</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/87535"&gt;@david_monaghan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a wide range of detections/analytic stories in the ESCU app - it really depends on what your use-cases and requirements are as to which datasources you will need to onboard.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out&amp;nbsp;&lt;A href="https://research.splunk.com/sources/" target="_blank"&gt;https://research.splunk.com/sources/&lt;/A&gt;&amp;nbsp;for a full list of datasources used by the ESCU app as well as Analytic Stories (&lt;A href="https://research.splunk.com/stories/" target="_blank"&gt;https://research.splunk.com/stories/&lt;/A&gt;) and Detections (&lt;A href="https://research.splunk.com/detections/" target="_blank"&gt;https://research.splunk.com/detections/&lt;/A&gt;) which both show which sources are required for them.&lt;/P&gt;&lt;P&gt;This will then help your onboarding process. I would also recommend checking out&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2025/recordings/SEC1638.mp4" target="_self"&gt;&lt;SPAN&gt;SEC1638 - From Request to Response: Mastering Security Data Onboarding&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 10:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Logs-required-for-Splunk-ES-Content-Update/m-p/753956#M12695</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-10-05T10:26:16Z</dc:date>
    </item>
  </channel>
</rss>

