Hi everyone,
We are currently deploying our internal SIEM using Splunk, and we began to write a list of use cases to trigger.
Does any one of you know an app that has already the most common use cases already deployed? We thought about Windows, Firewall, Linux and Checkpoint.
I would like avoid to write manually every SPL, would be a never ending work : (
Thank you!
Then you will end up with Splunk Enterprice Security... but that will cost you...
see:
https://splunkbase.splunk.com/app/263/
http://www.splunk.com/en_us/solutions/solution-areas/security-and-fraud/splunk-app-for-enterprise-se...
edit: Typo