Splunk Security Essentials - data available


Hi all,


I have the Splunk Security Essentials app installed and configured.

I am trying to understand how the app determine if a rule has data or not, because there are rules that do have logs but their status is "needs data".


There is the commend sseanalytics, but I am not sure how it works.


Thanks ! 

Labels (1)
0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.