Am looking for top 5-10 Splunk Apps / TAs to help with daily security checks & Watching for UBA behaviors, Ransomware monitoring etc. Thank u in advance
This may be subjective 🤣, anyways can be a good discussion
- Splunk Enterprise Security
- InfoSec App for Splunk
- Splunk ES Content Update
- Splunk Security Essentials for Ransomware
Thank u for this list. We have ES (Enterprise Security). Is Ent. security update a different app? Let me know if you think of more apps / TAs. Thank u again
Yes, Splunk ES content update is different app
https://splunkbase.splunk.com/app/3449/
+1
SA-Investigator for Enterprise Security : https://splunkbase.splunk.com/app/3749/