<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I put my DLP events into the Alerts data model in Splunk Enterprise Security? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272793#M2141</link>
    <description>&lt;P&gt;Hey Everyone,&lt;/P&gt;

&lt;P&gt;I'm working on putting some of my DLP events into the Alerts data model. However, I'm struggling to find out where they actually populate in Splunk Enterprise Security. Is there a spot for these alerts in ES? I was hoping they would populate in the identity or asset investigator.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2015 19:23:08 GMT</pubDate>
    <dc:creator>matthew_jochym</dc:creator>
    <dc:date>2015-12-15T19:23:08Z</dc:date>
    <item>
      <title>How do I put my DLP events into the Alerts data model in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272793#M2141</link>
      <description>&lt;P&gt;Hey Everyone,&lt;/P&gt;

&lt;P&gt;I'm working on putting some of my DLP events into the Alerts data model. However, I'm struggling to find out where they actually populate in Splunk Enterprise Security. Is there a spot for these alerts in ES? I was hoping they would populate in the identity or asset investigator.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 19:23:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272793#M2141</guid>
      <dc:creator>matthew_jochym</dc:creator>
      <dc:date>2015-12-15T19:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I put my DLP events into the Alerts data model in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272794#M2142</link>
      <description>&lt;P&gt;A DLP alert is more akin to an intrusion detection alert. Except the opposite direction. &lt;/P&gt;

&lt;P&gt;I would clone the Intrusion Detection data model, and call it DLP.&lt;BR /&gt;
Then map the fields to CIM model. &lt;A href="http://docs.splunk.com/Documentation/CIM/4.3.1/User/IntrusionDetection"&gt;CIM_IntrusionDetection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 19:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272794#M2142</guid>
      <dc:creator>mcronkrite</dc:creator>
      <dc:date>2015-12-15T19:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do I put my DLP events into the Alerts data model in Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272795#M2143</link>
      <description>&lt;P&gt;Thanks MCronkrite!&lt;/P&gt;

&lt;P&gt;I'm not sure if Splunk totally changed my topic, but my question direction was changed. &lt;/P&gt;

&lt;P&gt;I reviewed the other DLP add-ons that Splunk has created and supported, more in particular the RSA DLP application (&lt;A href="https://splunkbase.splunk.com/app/2956/"&gt;https://splunkbase.splunk.com/app/2956/&lt;/A&gt;) and they all look to be using the alerts data model for DLP. They state in the description that it's good for use in Splunk applications, including ES. &lt;/P&gt;

&lt;P&gt;So I mocked up my DLP machine data to comply with that data model and I'm wondering where should it populate in ES? Is there a swimlane that it should go to?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 19:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-put-my-DLP-events-into-the-Alerts-data-model-in-Splunk/m-p/272795#M2143</guid>
      <dc:creator>matthew_jochym</dc:creator>
      <dc:date>2015-12-15T19:56:38Z</dc:date>
    </item>
  </channel>
</rss>

