Splunk Enterprise Security

Do we have sample data for Splunk Enterprise security app ?

vikas_gopal
Builder

Hi Experts,

I have Splunk ES app, do we have any sample data which I can feed and present it using ES app. Please suggest any other alternative if we do not have sample data .Right now all the dashboards and panels are empty . I am aware that this app uses data models to show data , I am afraid i am not aware that how i can insert data using these models.

Thanks
Vikas

0 Karma

mcronkrite_splu
Splunk Employee
Splunk Employee

You can also use the ES Sandbox to check out what data populates ES. It's quick free and easy.
http://blogs.splunk.com/tag/es-sandbox/ ,Also you can sign up for a Sandbox instance that has data flowing. It's great because you don't have to wait for data or configure eventgen. http://blogs.splunk.com/tag/es-sandbox/

vikas_gopal
Builder

Thanks for the quick response , so once I generate sample logs can I directly feed them to ES app or still they need some configuration ?

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

If the data has an TA that is CIM compliant, it will feed directly in ES (you can see in Splunk base if an app is CIM compliant or not). Otherwise, you will have to normalize the data by yourself.

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Hello,

As said before, the datagen, with some apps that contains samples will automatically generate data that will feed the datamodel.

Otherwise, you can also try the demo sandbox here: https://www.splunk.com/getsplunk/es_sandbox .

0 Karma

Splunker
Communicator

Hi Vikas,

Sure, the Splunk EventGen (Event Generator) app https://splunkbase.splunk.com/app/1924/ can generate logs to light up ES dashboards.

Not sure if it'll work with Splunk Cloud (not sure if you have ES on-prem or in Splunk Cloud), but EventGen is the app to generate dummy logs to allow you to explore ES.

Hope it helps!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...