All Apps and Add-ons

Why am I not able to access the use cases that are available out of the box in Splunk Security Essentials App?

hcqismiddleware
Engager

HIi

We explored the Splunk Security Essentials app and the use cases that are available out of the box. Our Team is trying to access the below but not able to even though they have access. Could you please have a look.

Following are the use cases that we need to configure and allow to view:

Network:

1) Source IPs Communicating with Far More Hosts Than Normal
2) Sources Sending Many DNS Requests
3) Sources Sending a High Volume of DNS Traffic

Access:

1) Significant Increase in Interactively Logged on Users
2) New Local Admin Account
3) Short Lived Admin Accounts

Endpoints:

1) Hosts with Varied and Future timestamps

David
Splunk Employee
Splunk Employee

FWIW -- if anyone is still having this issue, please comment here so that I can follow up directly. (Apologies for the delay -- I was not getting notified about new questions for a long time.)

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...