All Apps and Add-ons

Security Essentials Merge Snapshots

BenjaminAbben
SplunkTrust
SplunkTrust

Hi all,

my question is regarding towards the addon of security Essentials.

 

i have different instances of Splunk running and all have there own Searches. I ingested these into Security Essentials (SE).

now i want to gather all of content of these different SE instances into one.

 

now what i dit was use the export function to JSON:

BenjaminAbben_0-1628669517410.png

From there i got to the manege snapshots page and pressed the export button, here i got a JSON output encoded base64 code. this works!

BenjaminAbben_1-1628669676400.jpeg

But now!.. if i am searching on my bookmarks i need to restore each snapshot to see that content..

what i want is 1 snapshot with all my content in one (merge all snapshots together).

 

i tried to merge de contents of the sse_bookmarks_backup but then the restore button does not work.

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...