Security

Splunk Security Essentials onboard data/use case creation

vinothn
Path Finder

Hi Team,

We are trying to get data on boarded to splunk security essentials.

We do not have a clear visibility to the functioning of the app, I have now onboarded DNS data onto my Splunk Indexer using the Splunk Stream app, Its in the index=netdns as per splunk docs specification.

Now how do I turn on all the use cases related to DNS in splunk security essentials.

 

Followed the onboarding guide which provided in the app.(https://docs.splunksecurityessentials.com/data-onboarding-guides/stream-dns/)

 

 

niroy_splunk
Splunk Employee
Splunk Employee

There's a walkthrough here for how you can track content and data in your Splunk environment and how to operationalize it using different features in the Analytics Advisor section: https://docs.splunksecurityessentials.com/user/productionalize/operationalize_mitre_attack/

0 Karma

johnsasikumar
Path Finder

Hi All,

I too have the same issue, The documents are not clear enough as how we have to activate the use cases in the splunk security essentials app. Please could someone shed some light on this.

 

Thanks

John

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...