- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Security Essentials - data available
astatrial
Contributor
05-10-2021
04:08 AM
Hi all,
I have the Splunk Security Essentials app installed and configured.
I am trying to understand how the app determine if a rule has data or not, because there are rules that do have logs but their status is "needs data".
There is the commend sseanalytics, but I am not sure how it works.
Thanks !
