<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk enterprise security in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532408#M10040</link>
    <description>&lt;P&gt;Check out the Splunk Security Essentials and ES Content Update apps for some example use cases that are best (or only) implemented using ES.&lt;/P&gt;&lt;P&gt;Also, ES has built-in features that enrich the assets and identities in your data.&lt;/P&gt;&lt;P&gt;That's not to mention the support for investigations and other SIEM features.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 22:35:48 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-12-08T22:35:48Z</dc:date>
    <item>
      <title>splunk enterprise security</title>
      <link>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532283#M10023</link>
      <description>&lt;P&gt;Hi Splunk Experts,&lt;/P&gt;&lt;P&gt;Suppose I only have splunk cloud.&amp;nbsp; Is it NOT possible to set an alert based on a search that correlates events from multiple systems? Such as correlating an event across endpoint and network activity.&amp;nbsp; Is this where Enterprise Security is needed?&amp;nbsp;Or is the answer that one can technically do it without Enterprise security but it would be tougher?&lt;/P&gt;&lt;P&gt;Would splunk enterprise have more out of the box correlations than just splunk cloud?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 14:12:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532283#M10023</guid>
      <dc:creator>trojan_81</dc:creator>
      <dc:date>2020-12-08T14:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise security</title>
      <link>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532339#M10036</link>
      <description>&lt;P&gt;You do not need Enterprise Security to correlate events from multiple systems or sources.&amp;nbsp; Using ES would not necessarily make it easier.&lt;/P&gt;&lt;P&gt;Splunk Cloud and Splunk Enterprise have the same set of OOTB correlations.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 14:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532339#M10036</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-08T14:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise security</title>
      <link>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532349#M10037</link>
      <description>&lt;P&gt;That helps greatly thank you.&amp;nbsp; With that in mind, what are a few reasons why you would want to implement ES&amp;nbsp; (assume you had the funds)?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 15:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532349#M10037</guid>
      <dc:creator>trojan_81</dc:creator>
      <dc:date>2020-12-08T15:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise security</title>
      <link>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532408#M10040</link>
      <description>&lt;P&gt;Check out the Splunk Security Essentials and ES Content Update apps for some example use cases that are best (or only) implemented using ES.&lt;/P&gt;&lt;P&gt;Also, ES has built-in features that enrich the assets and identities in your data.&lt;/P&gt;&lt;P&gt;That's not to mention the support for investigations and other SIEM features.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 22:35:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/splunk-enterprise-security/m-p/532408#M10040</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-08T22:35:48Z</dc:date>
    </item>
  </channel>
</rss>

