Splunk Enterprise Security

Custom App integrated in ES

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I would to use a custom App to contain all the custom Correlation Searches I'm creating on ES.

I need that the Correlation Searches contained in this custom App are visible in Enterprise Security.

I knew that to be visible in ES the Custom App must have a name starting with "SA-" but it isn't sufficient and doesn't work.

Does anyone know what I forget?

Thank you in advance.

Ciao.

Giuseppe

Labels (1)
0 Karma
1 Solution

starcher
Influencer

I would recommend DA-ESS-ABC for specific detection content.  SA is more utility objects n my opinion.

Next make sure your app permissions is global export (sharing). This is most typical cause of not seeing an app.

View solution in original post

starcher
Influencer

I would recommend DA-ESS-ABC for specific detection content.  SA is more utility objects n my opinion.

Next make sure your app permissions is global export (sharing). This is most typical cause of not seeing an app.

richgalloway
SplunkTrust
SplunkTrust

I believe the "SA-" naming convention is no longer necessary (as of ES 6, IIRC).  Be sure the custom CSs in your app are shared globally.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Hi @richgalloway,

the problem was easier: I forgot to Globally share the App so I didn't see it in ES!

Thank you for your assistance!

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...