Splunk Enterprise Security

Complete list and descriptions of pre-configured correlation searches in ES 4.0

javiergn
Super Champion

Hi all,

On a similar note to this question, I would also like to know the complete list of pre-configured correlation searches available in ES 4.0

We don't have ES installed and therefore I can't run the rest query suggested there, but I need this information in order to discuss the list internally before we can proceed with the POC and evaluation.

Thanks,
Javier

0 Karma
1 Solution

javiergn
Super Champion

Actually I'm going to answer myself as I just discovered I can have my own ES instance online and it's free for the next 15 days.

View solution in original post

saurabh_tek
Communicator

Hello Javiergn,
Although you have figured out yourself about the Enterprise security sandbox (link : http://blogs.splunk.com/2015/09/24/try-splunk-enterprise-security-for-free/). Now you can see the searches and queries running to power them. - Saurabh

0 Karma

javiergn
Super Champion

Actually I'm going to answer myself as I just discovered I can have my own ES instance online and it's free for the next 15 days.

Get Updates on the Splunk Community!

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...

Enterprise Security Content Update (ESCU) | New Releases

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...