Splunk Enterprise Security

How do I calculate the Enterprise security App license usage ?

vsskishore
Explorer

How do I calculate the Enterprise security App license usage ? Is it different from the Spunk Enterprise license ? Does the ES app use the base indexes of Splunk Enterprise or does it contain separate indexes ?

inventsekar
SplunkTrust
SplunkTrust

Question - How to calculate the Enterprise security App license usage ?
As per my understanding - Splunk ES is an app that sits on top of base Splunk. so, you need license for Base Splunk, that is enough.
As per below link also, Splunk Enterprise Security is a Splunk Premium Solution, which requires a Splunk Enterprise license or Splunk Cloud subscription.
Splunk Enterprise Security software is priced by how much data you send into your Splunk installation in a day.
https://www.splunk.com/en_us/software/pricing/faqs/cyber-security.html#Splunk-ES

Question - Is it different from spunk enterprise license ?
no. as explained above, no.. Splunk ES license is not different from splunk license.

Question - Is ES app use the base indexes of Splunk enterprise or does it contain separate indexes ?
Splunk ES uses base splunk's indexes.
and it uses some more indexes for its custom calculations.
more info here -
https://docs.splunk.com/Documentation/ES/5.2.0/Install/Indexes

As you are a new user to Splunk Answers, you can upvote the answers/comments,
if this answer resolved your query, you can select this answer and "accept" it as the answer, so that this question will be moved to answered queue. Happy Splunking!

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...