Splunk Enterprise Security

Does ES have all the features available in Splunk Security Essentials App?

damode
Motivator

Does ES also comes with SSE app features like Analytics Advisor, Content Recommendations, Data inventory, CIM compliance check etc ?

I found these features really useful for data source assessment.

Labels (2)
0 Karma

samin
Engager

In ES I can see use cases from other apps like SA-Threatintelligence, SA-Accessprotection etc. Aren't SSE contents  visible in ES?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES and SSE are complimentary products.  If you buy ES you may still need SSE.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

Rich, / Any one who have used Security Essentials. Do you by any chance have any leads on how to configure the security Essentials? I have spent hours, not able to make it go. When you click on Configure pull down in Sec essentials & try to add an add-on that it asks of integrate it with ES. You just watch the spinning wheel turn & turn. Also the use case are not able to be accessed. Please advise

Tags (1)
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...