Security

Splunk Security Essentials - data available

astatrial
Contributor

Hi all,

 

I have the Splunk Security Essentials app installed and configured.

I am trying to understand how the app determine if a rule has data or not, because there are rules that do have logs but their status is "needs data".

 

There is the commend sseanalytics, but I am not sure how it works.

 

Thanks ! 

Labels (1)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!