Splunk Enterprise Security

How Can I adjust Splunk Enterprise security ?

pacifikn
Communicator

Greetings!!!

  1. I am new user of splunk , and I would like to ask about splunk enterprise security, if there's any way to adjust splunk Enterprise security ?

  2. Splunk Enterprise security showing me total count of attacks in intrusion center , i would like to ask if there is a way to customize the existing Splunk Enterprise security ?if yes it requires administrator or a user can also do it?

  3. is there any documents or video link where i can read and know exactly what is summariesonly? and how to use it?

Kindly ,I need your help!
Thank you in advance!!

0 Karma

woodcock
Esteemed Legend

The documentation is excellent so start and end there. The summariesonly=t/f has to do with whether your CIM datamodels are accelerated or not. In ES, if you are using content that accesses a CIM datamodel, then that datamodel should first be accelerated. As far as adjusting content, a single person or very small team should be designated content owners who do this. Anybody can create content, but only these people should be scheduling it. In general, when modifying ES correlation searches, you should always clone the original and come up with your own naming convention standard so that it is obvious what is live and officially supported and what is not. Everything in Splunk and ES is a search and you can easily look at the search (even the ones that drive the threat intel stuff) and create custom content as you see fit. There are also consultants that are very good at this (we provide such services) because it can be somewhat complicated.

0 Karma

starcher
Influencer
0 Karma

richgalloway
SplunkTrust
SplunkTrust
  1. Yes, there are many ways to adjust Enterprise Security. What specifically do you want to adjust?
  2. Yes, it is possible, but you must be an admin to do so.
  3. "summariesonly" is a macro that expands to "summariesonly=true", which tells tstats to only look at data in completed data model accelerations.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...