Security

Can Splunk be used for Security Event Management ?

Hi All,

I would like to know is Splunk right tool for Security Event Management ?

Regards,

Somnath Shilmkar

0 Karma

Ultra Champion

Yes. Splunk, with the Enterprise Security app is a SIEM. The ES app is an additional package that is place on top of the core splunk installation. You can read more about it here;

http://www.splunk.com/view/enterprise-security-app/SP-CAAAE8Z
http://apps.splunk.com/app/263
http://docs.splunk.com/Documentation/ES

Hope this helps,

K