Hi splunkers
Right now I'm getting data from FortiWeb Onpremise and I need to know if there are any security use cases I can apply to my Enterprise Security or which Splunk ES "Security Intelligent" and "Security Domains" dashboards I could associate this data with.
I hope to be clear with my doubt
This is not a Splunk question. This is a security or Fortiweb question. But in general, map the events to the "Network Traffic" datamodel and then leverage the usecases from there (think "Splunk Security Essentials").