- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
nilbak1
Communicator
10-16-2018
10:41 AM
I have to install Splunk Security Essentials app in my distributed environment.
I gone through its documentation but I am still having a few queries
- To activate this, do we need to give access of all index data to a user?
- Will be there any performance issue since it checks all data ?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kmorris_splunk

Splunk Employee
10-16-2018
07:36 PM
- In order to utilize the searches, your user will need to have access to the indexes that contain the relevant data. Also, if you want to run the data source check, your user will need access to the data sources it is checking for.
- Any resource usage will only happen when you run the data source check. It is not a continuously running thing.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kmorris_splunk

Splunk Employee
10-16-2018
07:36 PM
- In order to utilize the searches, your user will need to have access to the indexes that contain the relevant data. Also, if you want to run the data source check, your user will need access to the data sources it is checking for.
- Any resource usage will only happen when you run the data source check. It is not a continuously running thing.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
nilbak1
Communicator
10-16-2018
10:45 PM
thanks @kmorris for your inputs
