All Apps and Add-ons

Any Detailed Document for Splunk Security Essentials app?

kpavan
Path Finder

Hi,

Any detailed document available how UEBA app works?

Thanks!
Pavan

0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

Detailed Docs now published! https://splunkbase.splunk.com/app/3435/#/details


Original Answer:

Hi Pavan,

Per aaraneta's comment, I'm assuming that you're just referring to the Splunk Security Essentials app (which delivers many use cases found in UEBA products). Let us know if you mean Splunk UBA instead.

Today there isn't separate detailed documentation available, but that's something I'm working on building right now. You can look to see it in a few weeks.

That said, the goal is for the app to be self-describing to a decent degree. Each use case has a Description, Help, Security Relevance, etc. The app is littered with tooltips to provide contextual information as well.

My primary goal with the separate detailed documentation is to describe installation requirements, to help organizations that require documentation before installation to get around that issue. Does that sound like what you're looking for? Is there anything else that you need?

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

Detailed Docs now published! https://splunkbase.splunk.com/app/3435/#/details


Original Answer:

Hi Pavan,

Per aaraneta's comment, I'm assuming that you're just referring to the Splunk Security Essentials app (which delivers many use cases found in UEBA products). Let us know if you mean Splunk UBA instead.

Today there isn't separate detailed documentation available, but that's something I'm working on building right now. You can look to see it in a few weeks.

That said, the goal is for the app to be self-describing to a decent degree. Each use case has a Description, Help, Security Relevance, etc. The app is littered with tooltips to provide contextual information as well.

My primary goal with the separate detailed documentation is to describe installation requirements, to help organizations that require documentation before installation to get around that issue. Does that sound like what you're looking for? Is there anything else that you need?

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@kpavan - You mention Splunk Security Essentials in your title but then mention the "UEBA" app in your actual post (I assume you are talking about Splunk User Behavior Analytics (Splunk UBA), correct?). Are you using two different apps?

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...