Splunk Enterprise Security

Does ES have all the features available in Splunk Security Essentials App?

damode
Motivator

Does ES also comes with SSE app features like Analytics Advisor, Content Recommendations, Data inventory, CIM compliance check etc ?

I found these features really useful for data source assessment.

Labels (2)
0 Karma

samin
Engager

In ES I can see use cases from other apps like SA-Threatintelligence, SA-Accessprotection etc. Aren't SSE contents  visible in ES?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES and SSE are complimentary products.  If you buy ES you may still need SSE.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

Rich, / Any one who have used Security Essentials. Do you by any chance have any leads on how to configure the security Essentials? I have spent hours, not able to make it go. When you click on Configure pull down in Sec essentials & try to add an add-on that it asks of integrate it with ES. You just watch the spinning wheel turn & turn. Also the use case are not able to be accessed. Please advise

Tags (1)
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...