Splunk Enterprise Security

DLP endpoint logs vs. Enterprise Security

ikulcsar
Communicator

Hi there,

We are receiving logs from a Data Loss Prevention (DLP) system about what users access, etc and we want to analyze it with Enterprise Security. (Semi) Out-of-the-box solutions preferred.
I found a DLP Data model, but couldn't find any dashboard, etc. which uses it for any correlations. Also, ES Content Updates App doesn't provide use cases for DLP Data model.

So does anybody have an experience on this topic, what should I do with this logs?

Regards,
István

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...