<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk enterprise security input data in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350211#M3340</link>
    <description>&lt;P&gt;You would create your dashboards, reports, correlation searches, inputs, alerts etc on the ES Search Head (SH.) But since you are using a Search Head Cluster (SHC), you do need to be aware that there are some configurations that you have to do in a dev environment, and then push via a deployer. (This is mainly modular inputs and threatlists..)&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2017 07:34:52 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2017-04-26T07:34:52Z</dc:date>
    <item>
      <title>Splunk enterprise security input data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350210#M3339</link>
      <description>&lt;P&gt;I have installed Splunk ES in SH cluster and search head as mentioned in docs. i have also installed add-on in which index-operation is true in indexers. However i am not clear what to do next. for example, when i am checking in SH &amp;gt; ES &amp;gt; Asset center or Identify master it is showing data which is in sample csv look up. there look up are in SH.&lt;/P&gt;

&lt;P&gt;now suppose i need to create a dash board in ES &amp;gt; SH for monitoring authentication activity of admin user on all splunk servers. from where i need to specify thing/data. in forwarder or in SH&amp;gt;ES ?  how flow of data work in this case. &lt;/P&gt;

&lt;P&gt;i could not find any doc with such detail. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2017 07:16:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350210#M3339</guid>
      <dc:creator>Prakhar_shukla</dc:creator>
      <dc:date>2017-04-26T07:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise security input data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350211#M3340</link>
      <description>&lt;P&gt;You would create your dashboards, reports, correlation searches, inputs, alerts etc on the ES Search Head (SH.) But since you are using a Search Head Cluster (SHC), you do need to be aware that there are some configurations that you have to do in a dev environment, and then push via a deployer. (This is mainly modular inputs and threatlists..)&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2017 07:34:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350211#M3340</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-04-26T07:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise security input data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350212#M3341</link>
      <description>&lt;P&gt;thanks for quick response. &lt;/P&gt;

&lt;P&gt;but how about data input. from where exactly it comes. Like core splunk we use Forwarder to indexer &amp;gt; then search head.  or directly to splunk instance where ES is installed? &lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2017 07:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-enterprise-security-input-data/m-p/350212#M3341</guid>
      <dc:creator>Prakhar_shukla</dc:creator>
      <dc:date>2017-04-26T07:39:29Z</dc:date>
    </item>
  </channel>
</rss>

