Splunk Enterprise Security

Does anyone see potential issues with only pulling asset data into Splunk Enterprise Security?

adnankhan5133
Communicator

The reason here being that the organization we're setting up Splunk ES for is in the process of centralizing 4 different Active Directories into a single centralized one (Azure AD). We're planning to wrap up our implementation of Splunk ES in a month, while the central AD implementation will be done in December. Does anyone see any concerns or issues with bringing in only asset data for now, and then waiting until December to introduce the identity data? I understand that we'll just miss out on contexts associated with users performing actions that result in notable events, but wondering if there will be any actual concerns that we need to take into account.

Labels (2)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...