Splunk Enterprise Security

How do I configure MC to show me the Alerts & warnings I get on the Enterprise Security (ES)? Thanks a million.


I have Monitoring Console in distributed mode on my Cluster Master. Need to learn how do I configure it to show Alerts & warnings I receive on my ES. I see small issues & warnings about the ES but like to see more. Thanks in advance. 

Labels (2)
Tags (1)
0 Karma

If I recall right you must add separate alert action to “register/send to” those alerts to MC also. Couldn’t remember the name now, but you probably found it from manual?
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!