<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Simulation data for ESCU in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438814#M5842</link>
    <description>&lt;P&gt;Is it possible to get some simulation data for ESCU? Right now all searches just return nothing for our instance. &lt;/P&gt;

&lt;P&gt;Or how can we use makeresults to generate some simulation data for ESCU?&lt;/P&gt;

&lt;P&gt;Thank you very much for your help!&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2018 20:31:28 GMT</pubDate>
    <dc:creator>ibmresilient</dc:creator>
    <dc:date>2018-12-17T20:31:28Z</dc:date>
    <item>
      <title>Simulation data for ESCU</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438814#M5842</link>
      <description>&lt;P&gt;Is it possible to get some simulation data for ESCU? Right now all searches just return nothing for our instance. &lt;/P&gt;

&lt;P&gt;Or how can we use makeresults to generate some simulation data for ESCU?&lt;/P&gt;

&lt;P&gt;Thank you very much for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 20:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438814#M5842</guid>
      <dc:creator>ibmresilient</dc:creator>
      <dc:date>2018-12-17T20:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Simulation data for ESCU</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438815#M5843</link>
      <description>&lt;P&gt;if you use the ESCU 2.0 onwards, you can navigate to the 'Analytic Story Detail' menu, select a story and submit 'Configure in ES'. This will create/enable required correlation search. You would need to ensure the sourcetype used etc..is matching with your implementation (or adjust/update it as per your env).&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 16:00:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438815#M5843</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-09T16:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Simulation data for ESCU</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438816#M5844</link>
      <description>&lt;P&gt;Sorry, could you pls tell me what is ESCU?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 23:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438816#M5844</guid>
      <dc:creator>cyber_castle</dc:creator>
      <dc:date>2019-01-09T23:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Simulation data for ESCU</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438817#M5845</link>
      <description>&lt;P&gt;That is the Splunk Enterprise Security Content Update or ESCU, meow details here &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/ESSOC/latest/user/About"&gt;https://docs.splunk.com/Documentation/ESSOC/latest/user/About&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 00:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Simulation-data-for-ESCU/m-p/438817#M5845</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-01-10T00:15:53Z</dc:date>
    </item>
  </channel>
</rss>

