Splunk Enterprise Security
Highlighted

How do enable Extreme Search command in ES App?

Explorer

After updating to ES App version 5.3.1, the extreme search commands no longer exist.

An error message is shown that the command is not found.

e.g.

Search: Access - Authentication Failures By Source - Context Gen

Unknown search command 'xsupdateddcontext'.

Labels (1)
0 Karma
Highlighted

Re: How do enable Extreme Search command in ES App?

SplunkTrust
SplunkTrust

Extreme Search is not replaced until ES 6.0.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How do enable Extreme Search command in ES App?

Splunk Employee
Splunk Employee

The Splunk Machine Learning Toolkit (MLTK) replaced Extreme Search:
https://docs.splunk.com/Documentation/ES/6.1.1/Admin/MLTKoverview

0 Karma