- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just curious if there is any documentation to help understand the best practices to use Splunk Enterprise as a SIEM for Security Professionals / SOC analysts.
Or if anyone has any input, that would be appreciated as well.
I have been evaluating Splunk Security Essentials, which I've been using to create dashboards.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Enrich your data with asset & user information where possible (Enterprise Security has this built in)
- Build alerts with a specific use case in mind - mmerza mentioned MITRE ATT&CK and rightfully so, but it doesn't contain all uses cases you may want to look for
- Use the CIM & datamodel acceleration
- Link alerts to playbooks/response plans
- It's only as good as the data you feed it but don't just put data in without an idea of how it will be used
I guess the overall theme is whatever you do, do it with a plan.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Enrich your data with asset & user information where possible (Enterprise Security has this built in)
- Build alerts with a specific use case in mind - mmerza mentioned MITRE ATT&CK and rightfully so, but it doesn't contain all uses cases you may want to look for
- Use the CIM & datamodel acceleration
- Link alerts to playbooks/response plans
- It's only as good as the data you feed it but don't just put data in without an idea of how it will be used
I guess the overall theme is whatever you do, do it with a plan.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Lots of splunk searches, explanations, and mappings to MITRE ATT&CK here: https://splunkbase.splunk.com/app/3449/
the app is updated regularly by splunk's security research team.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Keep in mind that Splunk Enterprise Security and Splunk Security Essentials are two different things.
- Splunk Enterprise Security - Splunk Enterprise Security is the nerve center of the security ecosystem, giving teams the insight to quickly detect and respond to internal and external attacks, simplify threat management minimizing risk.
- Splunk Security Essentials - Showcase of many security examples possible with Splunk
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


You might find some relevant information about best practices and use cases in the recordings of previous Splunk user conference sessions: https://conf.splunk.com/watch/conf-online.html?search=siem#/ .
