Splunk Enterprise Security

Custom App integrated in ES

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I would to use a custom App to contain all the custom Correlation Searches I'm creating on ES.

I need that the Correlation Searches contained in this custom App are visible in Enterprise Security.

I knew that to be visible in ES the Custom App must have a name starting with "SA-" but it isn't sufficient and doesn't work.

Does anyone know what I forget?

Thank you in advance.

Ciao.

Giuseppe

Labels (1)
0 Karma
1 Solution

starcher
Influencer

I would recommend DA-ESS-ABC for specific detection content.  SA is more utility objects n my opinion.

Next make sure your app permissions is global export (sharing). This is most typical cause of not seeing an app.

View solution in original post

starcher
Influencer

I would recommend DA-ESS-ABC for specific detection content.  SA is more utility objects n my opinion.

Next make sure your app permissions is global export (sharing). This is most typical cause of not seeing an app.

richgalloway
SplunkTrust
SplunkTrust

I believe the "SA-" naming convention is no longer necessary (as of ES 6, IIRC).  Be sure the custom CSs in your app are shared globally.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Hi @richgalloway,

the problem was easier: I forgot to Globally share the App so I didn't see it in ES!

Thank you for your assistance!

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...