Splunk Cloud Platform

SOC analyst wants single pane of glass into multi-instance Splunk Enterprise Security

splunkkrishdee
Explorer

Hello Splunkers

we have two instances of Splunk with ES (On Prem + Cloud)

how to pull all the notables from both the instances in to a single place?

i am going through the mothership and es mothership app in splunkbase

few clarification:

1. how ES mothership is depends on MOthership app. do we need to do the set up in mothership app which will communicates/send details to ES mothership app?

2. Where we need to install this app? seperate SH or in on prem sh or cloud?

 

3. what are the other alternative we hvae> can we try federated search for this. will it pull ES notable details?

 

Thanks

D

Labels (1)
0 Karma

splunkkrishdee
Explorer

Any update on this query?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...