Monitoring Splunk

'System health and performance' and 'UEBA' in Splunk

KKuser
Path Finder

How can I leverage Splunk Cloud to:

  1. Monitor System Health & Performance – Track uptime, downtime, and resource utilization (CPU/memory) of essential infrastructure.
  2. Enhance Endpoint & Network Security – Analyze firewall activity, VPN connections, and endpoint protection status.
  3. Utilize UEBA – Identify unusual user behavior that may signal insider threats or compromised accounts.
  4. Visualize Threat Response Metrics – Build dashboards to track the time taken for threat detection, investigation, and resolution.
  5. Analyze Cyberattack Patterns – Create dashboards to identify attack sources, detect trends, and refine mitigation strategies.

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

These are so general questions...

It all depends on what data you have, what service you purchased (bare Splunk Cloud, ES, ITSI...).

It's something that would be best discussed with your local friendly Splunk Partner who will sit with you, go through your needs (and budget constraints) and will suggest what can be done, how it can be done and how much it will cost.

0 Karma

livehybrid
Influencer

Hi @KKuser 

Do you have either IT Service Intelligence or Enterprise Security premium apps on Splunk Cloud? If you do this might significantly change how you approach this task. 

These sound like a deliverable work item list but actually each should be broken down for some further analysis and collaboration with the stakeholder to determine exactly what they need, otherwise you may end up building something which is different to what they need (Been there, done that).

A lot of these also depend on various other factors such as architecture, hosts, hosts type, infrastructure hosting provider (On Prem? VMware? AWS? Azure?) Do you already have all the data in Splunk for these data sources? If so, are the appropriate Technical Addons installed? 

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...