Is Splunk Enterprise or Splunk Ent. Security (ES) able to detect attacks by rogue systems or Artificially Intelligent enabled Server? Are AI enabled servers able to create user accounts in my Splunk environment?
Hi @SamHTexas
Splunk Core/Ent* and ES are no exception for an attack. Having said that similar to any other systems Splunk stack shall be protected as well, if someone managed to create a user they would be having full access from outside, and as far as i know there are no prebuilt reports for user creations and malicious activities identification.
these are some of the tips there could be many detections that needs to be enabled to monitor Splunk security posture it depends on how it has implemented and tools in place. Splunk ES can be used to monitor whole Splunk itself however custom notable searches shall be created.
----
An upvote would be appreciated and Accept solution if it helps!