Splunk Enterprise Security

How do I put my DLP events into the Alerts data model in Splunk Enterprise Security?

matthew_jochym
Engager

Hey Everyone,

I'm working on putting some of my DLP events into the Alerts data model. However, I'm struggling to find out where they actually populate in Splunk Enterprise Security. Is there a spot for these alerts in ES? I was hoping they would populate in the identity or asset investigator.

Thanks!

mcronkrite
Splunk Employee
Splunk Employee

A DLP alert is more akin to an intrusion detection alert. Except the opposite direction.

I would clone the Intrusion Detection data model, and call it DLP.
Then map the fields to CIM model. CIM_IntrusionDetection

0 Karma

matthew_jochym
Engager

Thanks MCronkrite!

I'm not sure if Splunk totally changed my topic, but my question direction was changed.

I reviewed the other DLP add-ons that Splunk has created and supported, more in particular the RSA DLP application (https://splunkbase.splunk.com/app/2956/) and they all look to be using the alerts data model for DLP. They state in the description that it's good for use in Splunk applications, including ES.

So I mocked up my DLP machine data to comply with that data model and I'm wondering where should it populate in ES? Is there a swimlane that it should go to?

Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...