Monitoring Splunk

'System health and performance' and 'UEBA' in Splunk

KKuser
Path Finder

How can I leverage Splunk Cloud to:

  1. Monitor System Health & Performance – Track uptime, downtime, and resource utilization (CPU/memory) of essential infrastructure.
  2. Enhance Endpoint & Network Security – Analyze firewall activity, VPN connections, and endpoint protection status.
  3. Utilize UEBA – Identify unusual user behavior that may signal insider threats or compromised accounts.
  4. Visualize Threat Response Metrics – Build dashboards to track the time taken for threat detection, investigation, and resolution.
  5. Analyze Cyberattack Patterns – Create dashboards to identify attack sources, detect trends, and refine mitigation strategies.

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

These are so general questions...

It all depends on what data you have, what service you purchased (bare Splunk Cloud, ES, ITSI...).

It's something that would be best discussed with your local friendly Splunk Partner who will sit with you, go through your needs (and budget constraints) and will suggest what can be done, how it can be done and how much it will cost.

0 Karma

livehybrid
Champion

Hi @KKuser 

Do you have either IT Service Intelligence or Enterprise Security premium apps on Splunk Cloud? If you do this might significantly change how you approach this task. 

These sound like a deliverable work item list but actually each should be broken down for some further analysis and collaboration with the stakeholder to determine exactly what they need, otherwise you may end up building something which is different to what they need (Been there, done that).

A lot of these also depend on various other factors such as architecture, hosts, hosts type, infrastructure hosting provider (On Prem? VMware? AWS? Azure?) Do you already have all the data in Splunk for these data sources? If so, are the appropriate Technical Addons installed? 

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...