Splunk Enterprise Security

How do enable Extreme Search command in ES App?

Explorer

After updating to ES App version 5.3.1, the extreme search commands no longer exist.

An error message is shown that the command is not found.

e.g.

Search: Access - Authentication Failures By Source - Context Gen

Unknown search command 'xsupdateddcontext'.

Labels (1)
0 Karma

Splunk Employee
Splunk Employee

The Splunk Machine Learning Toolkit (MLTK) replaced Extreme Search:
https://docs.splunk.com/Documentation/ES/6.1.1/Admin/MLTKoverview

0 Karma

SplunkTrust
SplunkTrust

Extreme Search is not replaced until ES 6.0.

---
If this reply helps you, an upvote would be appreciated.
0 Karma