Hi all,
I have the Splunk Security Essentials app installed and configured.
I am trying to understand how the app determine if a rule has data or not, because there are rules that do have logs but their status is "needs data".
There is the commend sseanalytics, but I am not sure how it works.
Thanks !