Knowledge Management

What is best practice when utilizing a search from the below apps?

TheBravoSierra
Path Finder

What is best practice when utilizing a search from the below apps? What pros/cons should I consider from each? I appreciate any guidance here. 

1) Enable the search stored in the app?
2) Clone the search and store in a custom company-specific app, and enable there? 

DA-ESS-MitreContent
DA-ESS-ContentUpdate
Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @TheBravoSierra,

When I have to use the searches as they are, is I prefer to leave them in their own original app.

If I have to modify them (any update!) I clone them in one my own app.

This is an approch hinted to me by a Splunk Professional Service.

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...