Splunk Enterprise Security

How do I Synchronizes Reports on the Splunk Enterprise with ES (Ent. security). Thx a million

SamHTexas
Builder

I have a ton or reports on the Ent. & like to synch them with ES to save time recreating them. Which is better synching or cloning? I 'd like to Synch them. Please advise. Thx & Happy 2022.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Put the reports into an app and install the app on both search heads.

Do yourself a favor, however, and avoid copying reports to ES.  The ES SH should only run searches that satisfy ES use cases.  To do more just adds load to an already loaded system.  Since both SHs access the same data, you should be able to run the reports from the ad-hoc SH.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thank u bro. & Happy 2022 to you & yours.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks!  Same to you!

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...