Splunk Security Essentials - data available


Hi all,


I have the Splunk Security Essentials app installed and configured.

I am trying to understand how the app determine if a rule has data or not, because there are rules that do have logs but their status is "needs data".


There is the commend sseanalytics, but I am not sure how it works.


Thanks ! 

Labels (1)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!